holdmysocks 4554502591 Tailscale for jailbroken PS5
A payload that runs the Tailscale client (tsnet, userspace networking) on a
jailbroken PS5: a C launcher built with ps5-payload-sdk that loads a Go
program in-process, an installer that registers it with the console's
payload autoloader and adds a home screen icon, and the patch that makes Go
1.27.1 speak the PS5's FreeBSD 9 era syscall interface.
2026-10-02 10:29:31 -04:00
2026-10-02 10:29:31 -04:00
2026-10-02 10:29:31 -04:00
2026-10-02 10:29:31 -04:00
2026-10-02 10:29:31 -04:00
2026-10-02 10:29:31 -04:00
2026-10-02 10:29:31 -04:00
2026-10-02 10:29:31 -04:00
2026-10-02 10:29:31 -04:00
2026-10-02 10:29:31 -04:00
2026-10-02 10:29:31 -04:00
2026-10-02 10:29:31 -04:00
2026-10-02 10:29:31 -04:00

Tailscale for jailbroken PS5

Puts a jailbroken PS5 on your Tailscale network.

  • Reach the console from anywhere. FTP, the payload loader, web tools: whatever listens on the console is available at its tailnet address from your other Tailscale devices.
  • Stream games to the console over Tailscale. A Moonlight client on the PS5 (such as ProsperoLight) can connect to a Sunshine host on your tailnet.
  • Starts by itself after each jailbreak if you use a payload autoloader, and adds a home screen icon for its status page.

It runs the real Tailscale client code (v1.104.0) as a single payload.

The status page

Unofficial and experimental. This project is not affiliated with or endorsed by Tailscale Inc. or Sony. It has been tested on one console. It runs homebrew with full privileges on a jailbroken system; use it at your own risk.

What it is not

The PS5 kernel has no tunnel device, so Tailscale cannot become a system-wide VPN here. It runs inside one process:

  • Games and PSN traffic do not go through Tailscale.
  • Other apps on the console cannot open connections to tailnet addresses directly. They can through a local forward (see game streaming and configuration).
  • No exit node, subnet routing, Tailscale SSH, Taildrop or Funnel.

Requirements

  • A jailbroken PS5 with an ELF loader listening on port 9021 (for example elfldr).
  • A Tailscale account.
  • Optional: a payload autoloader, so Tailscale starts after every jailbreak. Payload Manager and ps5_autoloader folders are detected.

Tested on firmware 13.42 with elfldr 0.26 and Payload Manager 0.5.2.

Install

  1. Download tailscale-installer.elf from the latest release.

  2. Send it to the console's ELF loader, once. Any payload sender works:

    # Linux / macOS
    socat -t 60 - TCP:<console-ip>:9021 < tailscale-installer.elf
    
    # Windows (script from this repository)
    .\tools\ps5send.ps1 -File tailscale-installer.elf -PS5Host <console-ip> -Seconds 70
    

    The installer prints what it does. It:

    • stores the daemon payload (tailscale.elf),
    • adds it to the end of your autoloader's load order, if it finds one,
    • adds a Tailscale icon to the home screen (media section),
    • starts Tailscale.
  3. Open http://<console-ip>:8090 on a phone or PC. Scan the QR code or follow the link and log in to Tailscale. If your tailnet uses device approval, approve the console in the admin console.

The console now has a tailnet address, shown on the status page.

Sending the installer again upgrades and restarts Tailscale. The login is kept.

Using it

Reaching the console

Connect to the console's tailnet address or MagicDNS name on the port you want, for example FTP on 2121 or the payload loader on 9021.

  • Every TCP port that something on the console listens on is forwarded. Ports with no listener refuse the connection.
  • UDP is not forwarded in this direction.
  • To keep a port off the tailnet, add it to blockedPorts in the configuration.

The status page

http://<console address>:8090, on the LAN or over the tailnet, or the Tailscale icon on the home screen. It shows the connection state, the login link, and your devices, and has controls for game streaming, logging out, stopping and uninstalling.

It has no password, like the console's other homebrew services. Anyone on your LAN, or on your tailnet if your ACLs allow it, can use it.

Game streaming (Moonlight to Sunshine)

This lets a Moonlight client on the PS5 stream from a PC that is somewhere else, over Tailscale.

On the PC:

  1. Install Sunshine and leave it on its default port (47989).
  2. Install Tailscale and log in to the same tailnet as the console.

On the console:

  1. Open the status page and find Game streaming.
  2. Choose the device that runs Sunshine and press Save. The page shows "Forwarding 127.0.0.1 to your-pc (7 ports)".
  3. In your Moonlight client on the PS5, add a host manually with the address 127.0.0.1. Do not enter the PC's tailnet address: the client cannot reach it.
  4. Pair as usual: the client shows a PIN, which you enter in Sunshine's web interface on the PC.

How it works: the daemon listens on 127.0.0.1 on Sunshine's ports (TCP 47984, 47989, 48010 and UDP 47998, 47999, 48000, 48002) and relays them to the chosen host through Tailscale. To the Moonlight client the Sunshine host appears to be the console itself.

Notes:

  • One Sunshine host at a time. Change it on the status page at any time.
  • A wired connection on the console helps, as with any streaming.
  • Do not change the console's network (Wi-Fi to Ethernet, connection settings) while a stream is running. That froze the test console once; the cause was not established.
  • Tested with ProsperoLight.

Other apps on the console

forwards in the configuration relays any localhost port to a tailnet host in the same way, TCP or UDP.

The daemon also runs an HTTP proxy on 127.0.0.1:8118 that reaches tailnet hosts, for apps that have their own proxy setting. Do not set it as the PS5's system proxy. The system then sends everything through it, including pages on 127.0.0.1, and it is not running until Tailscale has been loaded. On the test console that stopped Payload Manager's page from opening.

Configuration

/data/tailscale/config.json is created on first start. Every field is optional. Restart Tailscale (send the payload again) to apply edits.

{
  "hostname": "ps5",
  "authKey": "",
  "webAddr": ":8090",
  "httpProxyAddr": "127.0.0.1:8118",
  "controlURL": "",
  "sunshineHost": "",
  "forwards": [
    {"proto": "tcp", "listen": "127.0.0.1:8096", "target": "my-nas:8096"}
  ],
  "blockedPorts": [],
  "verbose": false
}
Field Meaning
hostname The console's name on the tailnet.
authKey A Tailscale auth key, to log in without the browser step.
webAddr Where the status page listens.
httpProxyAddr Where the HTTP proxy listens. Empty turns it off.
controlURL A coordination server other than Tailscale's.
sunshineHost The Sunshine host; set from the status page.
forwards Extra local forwards: proto is tcp or udp, listen a localhost address, target a tailnet host and port.
blockedPorts Local TCP ports that are never exposed to the tailnet.
verbose Put Tailscale's own log in the main log as well.

Files on the console:

Path What
/data/tailscale/config.json Settings.
/data/tailscale/state/ Tailscale's state, including the login.
/data/tailscale/tailscale.log The daemon's log, rotated at 2 MB.
/data/tailscale/tailscale-debug.log Tailscale's detailed log, up to 4 MB plus one older file.
/data/pldmgr/payloads/Tailscale/tailscale.elf The daemon, when Payload Manager is used.
/data/tailscale/tailscale.elf The daemon, when no autoloader was found.
/user/app/TSCL00001/ The home screen icon.

Uninstall

Press Uninstall on the status page. It removes the autoloader entry and the daemon payload and stops Tailscale. It asks whether to also log out and delete the saved login.

Two things are left to do by hand:

  • Delete the home screen icon (Options button, then Delete).
  • Remove the device in the Tailscale admin console.

Troubleshooting

  • The status page does not open on the console, but does from a PC. Check that the PS5's proxy server setting is "Do Not Use".
  • The Moonlight client cannot find the host. The host to add is 127.0.0.1, and a Sunshine host must be selected on the status page. Sunshine must be on its default port.
  • "Not logged in" after logging in. Press Log in again for a fresh link.
  • Something else. http://<console>:8090/api/logs?full=1 is the daemon's log and /api/logs?debug=1 is Tailscale's detailed log. Please attach them to bug reports, after checking them for anything you consider private.

Security

  • The status page and its controls are unauthenticated.
  • All listening TCP ports on the console become reachable from your tailnet, including the payload loader, which runs anything sent to it. Use Tailscale ACLs if other people share your tailnet.
  • The local forwards and the proxy listen on 127.0.0.1 only and are not exposed to the tailnet.

Resource use

About 60 MB of memory and next to no CPU when idle. The daemon runs at the lowest scheduling priority on at most 4 cores, so it gives way to games.

What has and has not been tested

Tested on the one console: install and upgrade, login with device approval, autostart after a reboot through Payload Manager, reaching the console over the tailnet, a ProsperoLight stream from a Sunshine host through the forward, the HTTP proxy, the home screen icon.

Not tested: rest mode, the ps5_autoloader and USB autoloader paths, Uninstall on a console, other firmware versions, coordination servers other than Tailscale's.

Building

See docs/BUILDING.md. The build runs on Windows with PowerShell, clang, ps5-payload-sdk and a patched Go 1.27.1.

How it works

tailscale.elf is a small C program built with ps5-payload-sdk with a Go program embedded in it. The SDK's startup code lifts the PS5's restriction on where system calls may be issued from. The C part drops the process to the lowest scheduling priority, maps the Go program into memory and enters it the way the FreeBSD kernel would. Go's runtime and standard library are patched to speak the PS5's FreeBSD 9 era system call interface. The Go program is a tsnet server that pipes every incoming tailnet TCP connection to the same port on localhost.

docs/TECHNICAL.md has the details, including what was learned about running Go on the PS5.

Credits

License

The project's own code is licensed under the GNU General Public License version 3 or later (see LICENSE); the payloads link the SDK's GPL-licensed startup code. patches/ is a patch to the Go source tree and is under Go's BSD-style license. Tailscale is BSD-3-Clause. The release binaries also contain Tailscale's dependencies under their own licenses; they are listed in tsd/go.mod.

"Tailscale" is a trademark of Tailscale Inc. "PlayStation" and "PS5" are trademarks of Sony Interactive Entertainment Inc.

v0.6.0
Latest
2026-10-05 21:25:14 +02:00
Languages
Go 65.2%
C 19.2%
HTML 12.4%
PowerShell 3.2%