tailscale / tailscale/tailscale

Inconsistent behaviour when assigning a new tag.

Open
#20,365 2 comments 0 reactions 0 assignees View on GitHub
bug OS-linux
Dominant language
Go
Stars
36.5k
Forks
3.2k
Avg merge
2d 3h
Merged PRs (30d)
123

Description

### What is the issue?

If I bring a machine up with an authkey carrying `tag:tag1` and that is a tagOwner of `tag:tag2` I would expect to be able to run `tailscale up --advertise-tags="tag:tag2"` and have it retag the device.

This works sometimes, but not consistently.

### Steps to reproduce

Create tag1, tag2. make tag1 the tagOwner of tag2
Log in a device as tag1
run `tailscale up --advertise-tags="tag2"`
Sometimes it works, sometimes it logs the machine out.

### Are there any recent changes that introduced the issue?

_No response_

### OS

Linux

### OS version

Debian 13

### Tailscale version

1.98.4

### Other software

Fresh install

### Bug report

BUG-1f879da71861c1112523b10594c627a45be621b9c49ee38644970ee920926b6e-20260707125809Z-77330c2e0645d81f

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the Debian 13 scenario: create tag1 and tag2, make tag1 the owner of tag2, log in with tag1, and run `tailscale up --advertise-tags="tag2"`. Use the linked bug report to compare runs where retagging succeeds with runs where the machine is logged out. Done means the command consistently retags the device without logging it out.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
authentication, cli
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.