Files
holdmysocks--ps5-tailscale/tools/make-release.ps1
T
holdmysocks 02fc73a04d Receive files with Taildrop; install signed updates from the status page
Taildrop: files sent to the console from the user's other devices are moved
from Tailscale's holding area to /data/tailscale/received (a setting),
announced on screen and listed on the status page with download links.

Updates: the status page can install a newer release when asked to. A
release carries tailscale.elf.sig, an Ed25519 signature over its version
and SHA-256; the daemon installs only what verifies against the public key
built into it, is the version the release claims and is newer than itself.
The payload is handed to the ELF loader, and the copy named by the new
payloadPath setting is replaced as well.

- tsd/relsig, tsd/cmd/signrelease: signing, verifying, and keeping the key
  (keygen, passphrase-protected backup and restore).
- tools/make-release.ps1 builds, signs and checksums a release.
- Files are no longer copied to sockets with sendfile, which the PS5
  kernel refuses.
2026-10-05 08:52:31 -04:00

44 lines
1.8 KiB
PowerShell

# Build the files of a release into out\release-<version>:
# tailscale.elf the payload
# tailscale.elf.sig its signature, which the status page's "Install" checks
# SHA256SUMS.txt
#
# .\tools\make-release.ps1 -Version 1.2.3
#
# Needs the release signing key on this machine (see docs/BUILDING.md).
param(
[Parameter(Mandatory = $true)][string]$Version
)
$ErrorActionPreference = 'Stop'
. (Join-Path $PSScriptRoot 'env.ps1')
if ($Version -notmatch '^\d+\.\d+\.\d+$') { throw "version must look like 1.2.3, not '$Version'" }
& (Join-Path $PSScriptRoot 'build-payload.ps1') -GoDir tsd -Name tailscale -Version $Version -HomeIcon
$rel = Join-Path $DevRoot "out\release-$Version"
New-Item -ItemType Directory -Force $rel | Out-Null
$elf = Join-Path $rel 'tailscale.elf'
Copy-Item (Join-Path $DevRoot 'out\tailscale.elf') $elf -Force
Push-Location (Join-Path $DevRoot 'tsd')
try {
go run ./cmd/signrelease sign -version $Version -file $elf
if ($LASTEXITCODE -ne 0) { throw 'signing failed' }
go run ./cmd/signrelease verify -file $elf
if ($LASTEXITCODE -ne 0) { throw 'the signature does not verify' }
# The payload must carry the public half of the key it was signed with,
# or consoles running it could never install the release after it.
$pub = go run ./cmd/signrelease pubkey
if (-not (Select-String -Path 'selfupdate.go' -SimpleMatch $pub -Quiet)) {
throw "tsd\selfupdate.go does not have this machine's public key ($pub) as updatePublicKey"
}
} finally { Pop-Location }
$hash = (Get-FileHash $elf -Algorithm SHA256).Hash.ToLower()
[IO.File]::WriteAllText((Join-Path $rel 'SHA256SUMS.txt'), "$hash tailscale.elf`n")
Get-ChildItem $rel | Select-Object Name, Length | Format-Table -AutoSize
Write-Host "release files are in $rel"