Repository navigation
Releases: WayneShao/KernelSU-Tailscaled
Release list
KernelSU-Tailscaled v2.0.4
v2.0.4
Finalize fully verified hot updates without an Android reboot. Once the active
runtime, manager view, staged bundle, WebUI, and service health all match, the
module removes only its own KernelSU pending-update marker and staged directory.
Any failed check preserves the normal pending-reboot state.
v2.0.3
Correct the live module summary to report the Tailscale engine version and
query IPv4 through the active runtime socket.
v2.0.2
Show live service health, Tailscale IPv4, WebUI readiness, and pending reboot
updates in the KernelSU module description. Keep runtime, update, and details
controls available as separate actions while an update is staged.
v2.0.1
Fix boot activation after reboot by starting the verified immutable runtime
generation directly instead of validating the manager directory as a runtime
bundle.
v2.0.0
Published 2026-09-08 as the current stable release and GitHub Latest.
https://github.com/WayneShao/KernelSU-Tailscaled/releases/tag/v2.0.0
- Promoted the beta.5 runtime to the current stable module release. Runtime,
installer, and WebUI code are unchanged; versionCode advances to 20000006. - Retired the unused Magisk-Tailscaled v1 release and its update.json channel.
Only kernelsu-tailscaled receives ongoing releases and ordinary updates. - Existing kernelsu-tailscaled installations upgrade normally with retained
identity. Old magisk-tailscaled data uses the documented one-time migration. - Stable releases explicitly become GitHub Latest. Release pages use their
version-specific notes, keeping migration instructions ahead of historical logs.
Full release log: docs/releases/v2.0.0.md
v2.0.0-beta.5 (historical prerelease)
Published 2026-09-07. Immutable Release:
https://github.com/WayneShao/KernelSU-Tailscaled/releases/tag/v2.0.0-beta.5
Full release log: docs/releases/v2.0.0-beta.5.md
- Renamed the source project to KernelSU-Tailscaled and adopted the independent
kernelsu-tailscaled module ID. The legacy v1 update feed is preserved. - Isolated persistent state and complete runtime generations from manager files.
Standard ZIP installation verifies, activates, and publishes its own runtime
and KernelSU panel/action entrypoints without post-install patch scripts. - Added explicit copy-only login migration with stopped-owner checks, validated
configuration, recoverable journals and a separate enable gate. - Added serialized lifecycle commands, bounded probes, process start-time checks,
visible failed/degraded states and same-engine activation rollback. - Retain process records and sockets when a still-live process fails identity
verification; block replacement instead of spawning duplicate TUN owners. - Reject orphaned supervisor passes after they acquire the lifecycle lock,
preventing an old generation from cleaning up a newly installed runtime. - Added truthful native interface/address/route diagnostics, upstream health
warnings, effective preferences and active/staged/previous runtime versions. - Restricted configuration to validated data; bounded and redacted runtime logs.
- Corrected Android mksh descriptor inheritance and BusyBox JSON scalar parsing
using actual shell/applet regressions discovered during device verification. - Prepared universal-only, immutable official-store distribution gates. Store
review and stable publication are separate from candidate builds.
Candidate validation and device results are recorded under docs/verification.
This beta is not a claim of broad compatibility or long-term network stability.
v1.102.3.1
- Added a compact KernelSU WebUI with module enable/disable, refresh, IP copy,
runtime restart, recent logs, component health, and official local-panel
navigation. - Switched the default data plane to native TUN while retaining an explicit
userspace fallback mode. - Added an owned-process supervisor for tailscaled, the optional userspace
tunnel, and the loopback-only Tailscale web service. - Preserved Tailscale identity, preferences, configuration, and logs across
in-place upgrades. - Added one-time Android product-name initialization so new nodes do not first
register as localhost. - Preferred the control-plane DNS name in the dashboard so admin-side node
renames are reflected immediately. - Added an optional loopback CONTROL_PROXY for Android Fake-IP environments;
peer and WireGuard traffic remain on the native Tailscale data plane. - Added fixed-command KernelSU bridge calls and strict JSON/status validation;
no arbitrary shell input is exposed by the WebUI. - Added deterministic full, arm, and arm64 packages with per-payload SHA-256
manifests and package structure verification.
Validation
- Verified Tailscale 1.102.3 arm64 binaries against the recorded SHA-256
values. - Installed and exercised the module on PKX110 and nezha KernelSU devices.
- Confirmed both devices reached BackendState=Running without disabling or
modifying their existing ZeroTier modules. - Verified hostname display using backend DNS names and local hostname
initialization without an Android reboot.
KernelSU-Tailscaled v2.0.3
v2.0.3
Correct the live module summary to report the Tailscale engine version and
query IPv4 through the active runtime socket.
v2.0.2
Show live service health, Tailscale IPv4, WebUI readiness, and pending reboot
updates in the KernelSU module description. Keep runtime, update, and details
controls available as separate actions while an update is staged.
v2.0.1
Fix boot activation after reboot by starting the verified immutable runtime
generation directly instead of validating the manager directory as a runtime
bundle.
v2.0.0
Published 2026-09-08 as the current stable release and GitHub Latest.
https://github.com/WayneShao/KernelSU-Tailscaled/releases/tag/v2.0.0
- Promoted the beta.5 runtime to the current stable module release. Runtime,
installer, and WebUI code are unchanged; versionCode advances to 20000006. - Retired the unused Magisk-Tailscaled v1 release and its update.json channel.
Only kernelsu-tailscaled receives ongoing releases and ordinary updates. - Existing kernelsu-tailscaled installations upgrade normally with retained
identity. Old magisk-tailscaled data uses the documented one-time migration. - Stable releases explicitly become GitHub Latest. Release pages use their
version-specific notes, keeping migration instructions ahead of historical logs.
Full release log: docs/releases/v2.0.0.md
v2.0.0-beta.5 (historical prerelease)
Published 2026-09-07. Immutable Release:
https://github.com/WayneShao/KernelSU-Tailscaled/releases/tag/v2.0.0-beta.5
Full release log: docs/releases/v2.0.0-beta.5.md
- Renamed the source project to KernelSU-Tailscaled and adopted the independent
kernelsu-tailscaled module ID. The legacy v1 update feed is preserved. - Isolated persistent state and complete runtime generations from manager files.
Standard ZIP installation verifies, activates, and publishes its own runtime
and KernelSU panel/action entrypoints without post-install patch scripts. - Added explicit copy-only login migration with stopped-owner checks, validated
configuration, recoverable journals and a separate enable gate. - Added serialized lifecycle commands, bounded probes, process start-time checks,
visible failed/degraded states and same-engine activation rollback. - Retain process records and sockets when a still-live process fails identity
verification; block replacement instead of spawning duplicate TUN owners. - Reject orphaned supervisor passes after they acquire the lifecycle lock,
preventing an old generation from cleaning up a newly installed runtime. - Added truthful native interface/address/route diagnostics, upstream health
warnings, effective preferences and active/staged/previous runtime versions. - Restricted configuration to validated data; bounded and redacted runtime logs.
- Corrected Android mksh descriptor inheritance and BusyBox JSON scalar parsing
using actual shell/applet regressions discovered during device verification. - Prepared universal-only, immutable official-store distribution gates. Store
review and stable publication are separate from candidate builds.
Candidate validation and device results are recorded under docs/verification.
This beta is not a claim of broad compatibility or long-term network stability.
v1.102.3.1
- Added a compact KernelSU WebUI with module enable/disable, refresh, IP copy,
runtime restart, recent logs, component health, and official local-panel
navigation. - Switched the default data plane to native TUN while retaining an explicit
userspace fallback mode. - Added an owned-process supervisor for tailscaled, the optional userspace
tunnel, and the loopback-only Tailscale web service. - Preserved Tailscale identity, preferences, configuration, and logs across
in-place upgrades. - Added one-time Android product-name initialization so new nodes do not first
register as localhost. - Preferred the control-plane DNS name in the dashboard so admin-side node
renames are reflected immediately. - Added an optional loopback CONTROL_PROXY for Android Fake-IP environments;
peer and WireGuard traffic remain on the native Tailscale data plane. - Added fixed-command KernelSU bridge calls and strict JSON/status validation;
no arbitrary shell input is exposed by the WebUI. - Added deterministic full, arm, and arm64 packages with per-payload SHA-256
manifests and package structure verification.
Validation
- Verified Tailscale 1.102.3 arm64 binaries against the recorded SHA-256
values. - Installed and exercised the module on PKX110 and nezha KernelSU devices.
- Confirmed both devices reached BackendState=Running without disabling or
modifying their existing ZeroTier modules. - Verified hostname display using backend DNS names and local hostname
initialization without an Android reboot.
KernelSU-Tailscaled v2.0.2
v2.0.2
Show live service health, Tailscale IPv4, WebUI readiness, and pending reboot
updates in the KernelSU module description. Keep runtime, update, and details
controls available as separate actions while an update is staged.
v2.0.1
Fix boot activation after reboot by starting the verified immutable runtime
generation directly instead of validating the manager directory as a runtime
bundle.
v2.0.0
Published 2026-09-08 as the current stable release and GitHub Latest.
https://github.com/WayneShao/KernelSU-Tailscaled/releases/tag/v2.0.0
- Promoted the beta.5 runtime to the current stable module release. Runtime,
installer, and WebUI code are unchanged; versionCode advances to 20000006. - Retired the unused Magisk-Tailscaled v1 release and its update.json channel.
Only kernelsu-tailscaled receives ongoing releases and ordinary updates. - Existing kernelsu-tailscaled installations upgrade normally with retained
identity. Old magisk-tailscaled data uses the documented one-time migration. - Stable releases explicitly become GitHub Latest. Release pages use their
version-specific notes, keeping migration instructions ahead of historical logs.
Full release log: docs/releases/v2.0.0.md
v2.0.0-beta.5 (historical prerelease)
Published 2026-09-07. Immutable Release:
https://github.com/WayneShao/KernelSU-Tailscaled/releases/tag/v2.0.0-beta.5
Full release log: docs/releases/v2.0.0-beta.5.md
- Renamed the source project to KernelSU-Tailscaled and adopted the independent
kernelsu-tailscaled module ID. The legacy v1 update feed is preserved. - Isolated persistent state and complete runtime generations from manager files.
Standard ZIP installation verifies, activates, and publishes its own runtime
and KernelSU panel/action entrypoints without post-install patch scripts. - Added explicit copy-only login migration with stopped-owner checks, validated
configuration, recoverable journals and a separate enable gate. - Added serialized lifecycle commands, bounded probes, process start-time checks,
visible failed/degraded states and same-engine activation rollback. - Retain process records and sockets when a still-live process fails identity
verification; block replacement instead of spawning duplicate TUN owners. - Reject orphaned supervisor passes after they acquire the lifecycle lock,
preventing an old generation from cleaning up a newly installed runtime. - Added truthful native interface/address/route diagnostics, upstream health
warnings, effective preferences and active/staged/previous runtime versions. - Restricted configuration to validated data; bounded and redacted runtime logs.
- Corrected Android mksh descriptor inheritance and BusyBox JSON scalar parsing
using actual shell/applet regressions discovered during device verification. - Prepared universal-only, immutable official-store distribution gates. Store
review and stable publication are separate from candidate builds.
Candidate validation and device results are recorded under docs/verification.
This beta is not a claim of broad compatibility or long-term network stability.
v1.102.3.1
- Added a compact KernelSU WebUI with module enable/disable, refresh, IP copy,
runtime restart, recent logs, component health, and official local-panel
navigation. - Switched the default data plane to native TUN while retaining an explicit
userspace fallback mode. - Added an owned-process supervisor for tailscaled, the optional userspace
tunnel, and the loopback-only Tailscale web service. - Preserved Tailscale identity, preferences, configuration, and logs across
in-place upgrades. - Added one-time Android product-name initialization so new nodes do not first
register as localhost. - Preferred the control-plane DNS name in the dashboard so admin-side node
renames are reflected immediately. - Added an optional loopback CONTROL_PROXY for Android Fake-IP environments;
peer and WireGuard traffic remain on the native Tailscale data plane. - Added fixed-command KernelSU bridge calls and strict JSON/status validation;
no arbitrary shell input is exposed by the WebUI. - Added deterministic full, arm, and arm64 packages with per-payload SHA-256
manifests and package structure verification.
Validation
- Verified Tailscale 1.102.3 arm64 binaries against the recorded SHA-256
values. - Installed and exercised the module on PKX110 and nezha KernelSU devices.
- Confirmed both devices reached BackendState=Running without disabling or
modifying their existing ZeroTier modules. - Verified hostname display using backend DNS names and local hostname
initialization without an Android reboot.
KernelSU-Tailscaled v2.0.1
v2.0.1
Fix boot activation after reboot by starting the verified immutable runtime
generation directly instead of validating the manager directory as a runtime
bundle.
v2.0.0
Published 2026-09-08 as the current stable release and GitHub Latest.
https://github.com/WayneShao/KernelSU-Tailscaled/releases/tag/v2.0.0
- Promoted the beta.5 runtime to the current stable module release. Runtime,
installer, and WebUI code are unchanged; versionCode advances to 20000006. - Retired the unused Magisk-Tailscaled v1 release and its update.json channel.
Only kernelsu-tailscaled receives ongoing releases and ordinary updates. - Existing kernelsu-tailscaled installations upgrade normally with retained
identity. Old magisk-tailscaled data uses the documented one-time migration. - Stable releases explicitly become GitHub Latest. Release pages use their
version-specific notes, keeping migration instructions ahead of historical logs.
Full release log: docs/releases/v2.0.0.md
v2.0.0-beta.5 (historical prerelease)
Published 2026-09-07. Immutable Release:
https://github.com/WayneShao/KernelSU-Tailscaled/releases/tag/v2.0.0-beta.5
Full release log: docs/releases/v2.0.0-beta.5.md
- Renamed the source project to KernelSU-Tailscaled and adopted the independent
kernelsu-tailscaled module ID. The legacy v1 update feed is preserved. - Isolated persistent state and complete runtime generations from manager files.
Standard ZIP installation verifies, activates, and publishes its own runtime
and KernelSU panel/action entrypoints without post-install patch scripts. - Added explicit copy-only login migration with stopped-owner checks, validated
configuration, recoverable journals and a separate enable gate. - Added serialized lifecycle commands, bounded probes, process start-time checks,
visible failed/degraded states and same-engine activation rollback. - Retain process records and sockets when a still-live process fails identity
verification; block replacement instead of spawning duplicate TUN owners. - Reject orphaned supervisor passes after they acquire the lifecycle lock,
preventing an old generation from cleaning up a newly installed runtime. - Added truthful native interface/address/route diagnostics, upstream health
warnings, effective preferences and active/staged/previous runtime versions. - Restricted configuration to validated data; bounded and redacted runtime logs.
- Corrected Android mksh descriptor inheritance and BusyBox JSON scalar parsing
using actual shell/applet regressions discovered during device verification. - Prepared universal-only, immutable official-store distribution gates. Store
review and stable publication are separate from candidate builds.
Candidate validation and device results are recorded under docs/verification.
This beta is not a claim of broad compatibility or long-term network stability.
v1.102.3.1
- Added a compact KernelSU WebUI with module enable/disable, refresh, IP copy,
runtime restart, recent logs, component health, and official local-panel
navigation. - Switched the default data plane to native TUN while retaining an explicit
userspace fallback mode. - Added an owned-process supervisor for tailscaled, the optional userspace
tunnel, and the loopback-only Tailscale web service. - Preserved Tailscale identity, preferences, configuration, and logs across
in-place upgrades. - Added one-time Android product-name initialization so new nodes do not first
register as localhost. - Preferred the control-plane DNS name in the dashboard so admin-side node
renames are reflected immediately. - Added an optional loopback CONTROL_PROXY for Android Fake-IP environments;
peer and WireGuard traffic remain on the native Tailscale data plane. - Added fixed-command KernelSU bridge calls and strict JSON/status validation;
no arbitrary shell input is exposed by the WebUI. - Added deterministic full, arm, and arm64 packages with per-payload SHA-256
manifests and package structure verification.
Validation
- Verified Tailscale 1.102.3 arm64 binaries against the recorded SHA-256
values. - Installed and exercised the module on PKX110 and nezha KernelSU devices.
- Confirmed both devices reached BackendState=Running without disabling or
modifying their existing ZeroTier modules. - Verified hostname display using backend DNS names and local hostname
initialization without an Android reboot.
KernelSU-Tailscaled v2.0.0
KernelSU-Tailscaled v2.0.0
Published 2026-09-08 as an immutable stable release and GitHub Latest.
This is the current stable release of KernelSU-Tailscaled, with official
Tailscale 1.102.3. It promotes the previously published beta.5 runtime.
Runtime, installer, and WebUI code are unchanged by this promotion.
Installation And Updates
Install the universal ZIP through KernelSU Manager or ksud module install.
The package starts its runtime and installs the panel and Action entrypoints.
ARM and ARM64-specific ZIPs are also available.
Existing kernelsu-tailscaled installations, including beta.5, upgrade normally
and preserve their login and configuration. The module ID stays the same and
versionCode increases from 20000005 to 20000006. No migration is required.
Retired Magisk-Tailscaled v1
Only the kernelsu-tailscaled module line is maintained. The unused v1 Release
and its update.json channel are retired. An old magisk-tailscaled installation
does not receive an automatic update into this different module ID.
For retained legacy data, stop and disable the old module, install the new ZIP,
use its explicit Migrate legacy identity action or control.sh migrate-legacy,
then enable it. Preserve the old login data until the new runtime is confirmed.
The helper requires stopped runtimes and an empty destination; it does not claim
to cover every historical or manually modified layout. Those are one-time manual
data transfers, not a separately maintained compatibility line.
Included Features
- KernelSU status panel, service enable/disable, and access to the official local
Tailscale panel. - Isolated state, complete runtime bundles, serialized lifecycle control, and
recovery that rejects obsolete supervisor tasks. - Hostname initialization from Android naming and display of administrative
name changes, real runtime health, and upstream diagnostic warnings. - Complete ZIP installation and hot activation without post-install patches.
Verification Scope
The runtime was installed on the maintainer's PKX110 and nezha with both backends
running. This release preserves that code. Release CI verifies metadata, packages,
runtime regressions, the frontend, and reproducible ZIPs before publication.
Existing DNS preferences are retained and Android /etc/resolv.conf warnings
can remain visible. Broad Android/root-manager compatibility and multi-day
stability are not newly asserted by changing the release classification.
See the runtime verification record.
Official KernelSU store review is tracked in
submission #80.
Publication Verification
The build job
passed. Publication verification
also passed after GitHub's newly created release attestation became available.
The pipeline now allows bounded retries for that publication delay.
The public universal ZIP was downloaded and validated. Comparing it with the
published beta.5 ZIP confirmed that every runtime, installer, WebUI, and binary
entry is byte-identical. Only version/update metadata and generated manifests
changed, and the old update.json entry was removed.
abcb71f77a1dbe80a4439657abfaddfb70d30ee01264572cb3cee5190eba6a00 KernelSU-Tailscaled-v2.0.0.zip
6d7c5d9d6e28fd3443d93fc805f149b522ff2cbbcbbaeb0a6570e83a4c6e2bb2 KernelSU-Tailscaled-arm-v2.0.0.zip
1178b388f3d7ca82f32206ac421e7e597498c95795b577801abd948b7b6d5be4 KernelSU-Tailscaled-arm64-v2.0.0.zip
KernelSU-Tailscaled v2.0.0-beta.5
KernelSU-Tailscaled v2.0.0-beta.5
Published 2026-09-07 as a prerelease. Official Tailscale engine: 1.102.3.
Independent module ID: kernelsu-tailscaled.
Changes
- KernelSU-first identity, with upstream history and licensing retained.
- Complete ZIP installation activates the runtime and publishes the WebUI and
Action entrypoints, without post-install patches or an Android reboot. - Isolated persistent login state, checked runtime generations, serialized
lifecycle operations, and bounded recovery. - Status distinguishes actual process, API, native interface, and route health;
it shows upstream warnings instead of reporting an unhealthy runtime as healthy. - Dashboard names follow control-plane names and fresh logins use Android naming.
- Corrected mksh lock descriptor inheritance, BusyBox JSON parsing, and pointer
replacement behavior encountered on Android. - Prevented orphaned supervisor tasks from acting after a runtime replacement.
Inconclusive process identity checks retain records and block duplicate starts. - Release publication verifies draft assets by release ID and supports resuming
verified builds without rebuilding or replacing existing release assets.
Installation
Use the universal ZIP unless an architecture-specific package is preferred.
Install through KernelSU Manager or ksud module install. The ZIP performs
activation itself. Existing v2 login state and preferences are preserved.
The legacy module uses a different ID. An existing legacy login requires the
explicit copy-only migration procedure in the README, not an automatic takeover.
Verification
- Build job:
112 Python tests, 51 frontend tests, 15 browser checks, shell checks, all three
package variants, and duplicate-build byte comparison passed. - Publication workflow:
reused the original successful build, checked commit provenance and asset
digests, then published the immutable release. - PKX110 and nezha installed the same ARM64 ZIP and reported all runtime
components and the Tailscale backend running. The CI ARM64 ZIP has exactly
the same SHA-256 as the package installed on both devices.
Known Limits
This is not a stable compatibility claim. Existing DNS acceptance preferences
are preserved; Android /etc/resolv.conf warnings can remain visible. Final
physical inspection of the KernelSU Details page, ARM execution, broad root
manager compatibility, userspace networking, and multi-day stability are not
established. See the verification record.
The original tag build completed successfully but its first publication attempt
stopped at draft lookup. The linked publication workflow completed that same
release without changing its tag, rebuilding its ZIPs, or replacing assets.
SHA-256
a8b403da99a6739366f8320837ebb43b954a92cd576b6b13679e14d29f49ed60 KernelSU-Tailscaled-v2.0.0-beta.5.zip
49b7b03d8d9f27556fe91f2aa5900c402a0c273df2d879aa9d64899496c284ab KernelSU-Tailscaled-arm-v2.0.0-beta.5.zip
6d851adee28c140d853cc69a31fa5e51659d1ebccd914f666784acc2ab25d043 KernelSU-Tailscaled-arm64-v2.0.0-beta.5.zip