ARTICLE DETAIL

资讯详情

深耕郑州网站建设与运营推广的一线实战洞察。

Portmaster 安装包打包指南:从 Earthly 产物到 Windows NSIS/MSI 安装器

Portmaster 安装包打包指南:从 Earthly 产物到 Windows NSIS/MSI 安装器 网络安全【免费下载链接】portmaster Love Freedom - ❌ Block Mass Surveillance项目地址https://gitcode.com/gh_mirrors/po/portmaster点击查看免费下载本指南以 packaging/README.md 为骨架系统讲解 PortmasterSafing 出品的开源应用防火墙Windows 安装包的完整生成流程先在 Linux 环境用 Earthly 产出dist发布产物再在 Windows 环境通过 PowerShell 脚本或 Tauri CLI 手动打包成 NSIS.exe与 WIX.msi两种安装器并覆盖二进制签名与 MSI 调试方法。读完本文你将掌握 Portmaster 从编译产物到可分发安装包的整条打包链路并能在本地复现官方同款打包流程。一、打包总体流程概览Portmaster 的 Windows 安装包并非在单一环境一键产出而是由两条环境链协作完成Linux 环境通过 Earthly 执行release-prep交叉编译 UITauri/Angular与 CoreGo二进制并从updates.safing.io拉取最新的 KEXT 驱动与情报数据intel统一输出到仓库根目录的dist文件夹。Windows 环境编译 Windows 专属的portmaster-core.dll将dist中的全部二进制与情报文件拷贝到 Tauri 工程目录再调用 Tauri 打包器生成 NSIS / WIX 安装器。整个流程由 generate_windows_installers.ps1 串联成 5 个步骤脚本头注释中完整记录1. 编译 Core 二进制Linux 环境 earthly release-prep # 或 earthly all-artifacts额外构建 Linux 包 2. 编译 Windows 专属二进制Windows 环境 从 windows_core_dll 目录编译 portmaster-core.dll 并复制到 项目根/dist/downloaded/windows_amd64 3. 签名所有二进制Windows 环境 .\packaging\windows\sign_binaries_in_dist.ps1 -certSha1 证书SHA1 4. 创建安装器Windows 环境 .\generate_windows_installers.ps1 安装器输出到 项目根/dist/windows_amd64 5. 签名安装器Windows 环境 .\packaging\windows\sign_binaries_in_dist.ps1 -certSha1 证书SHA1二、前置条件Earthly 预发布步骤根据 packaging/README.md 的说明打包 Windows 安装器前必须先执行 Earthly 的 release prep 步骤并保证仓库根目录存在dist输出文件夹earthly release-prep该步骤很可能需要在单独的 Linux 机器上执行或直接从 CI 下载产物。release-prep目标在 Earthfile 中定义了完整的产物装配逻辑其产物结构如下对应脚本注释中的dist目录布局dist/binary/all/跨平台共享资源即 assets.zip 与 Angular 前端打包出的portmaster.zipdist/binary/windows_amd64/Windows 平台 UI 可执行文件portmaster.exe与WebView2Loader.dll、Go 编译的portmaster-core.exedist/binary/linux_amd64/Linux 平台二进制用于同步产出 Linux 包dist/downloaded/windows_amd64/由updatemgr从https://updates.safing.io/stable.v3.json下载的当前稳定版portmaster-kext.sys与portmaster-core.dll这两个文件无法由 Earthly 交叉编译必须取自已发布的稳定版dist/intel/由updatemgr从https://updates.safing.io/intel.v3.json拉取的情报数据*.dsdl、*.mmdb、*.yaml、index.json等。Earthfile 中还支持packaging/_precompiled目录覆盖机制若该目录存在其中的预编译文件将优先于本次构建产物见 Earthfile便于在不重新编译的情况下复用已有二进制但需注意若覆盖intel目录intel/index.json中的哈希值必须保持正确。三、一键生成安装器generate_windows_installers.ps1在仓库根目录运行以下 PowerShell 脚本即可生成安装器./packaging\windows\generate_windows_installers.ps1脚本会在dist文件夹内同时产出 NSIS.exe与 WIX.msi两种安装器...\Portmaster\dist\windows_amd64\Portmaster_0.1.0_x64-setup.exe ...\Portmaster\dist\windows_amd64\Portmaster_0.1.0_x64_en-US.msi3.1 脚本支持的可选参数脚本定义在 generate_windows_installers.ps1支持三个开关参数参数别名含义-interactive-i交互模式。当文件在主目录中找不到、但在备用目录中找到时会提示用户确认是否使用备用文件-version v-v显式指定安装器文件名中使用的版本号-erase-e仅清除工作目录binary、intel、target后直接退出不执行打包3.2 脚本内部做了哪些事结合 generate_windows_installers.ps1 的实现一键脚本的完整工作流为清理并重建工作目录脚本将工作目录定位到仓库根Set-Location到$PSScriptRoot/../..并清空desktop/tauri/src-tauri下的binary、intel、target三个目录若传了-e则到此为止。拷贝二进制文件通过Find-And-Copy-File函数支持主目录缺失时回退到备用目录的查找逻辑将以下文件装配到 Tauri 工程目录dist/downloaded/windows_amd64/portmaster-kext.sys - desktop/tauri/src-tauri/binary/ dist/downloaded/windows_amd64/portmaster-core.dll - desktop/tauri/src-tauri/binary/ dist/binary/windows_amd64/portmaster-core.exe - desktop/tauri/src-tauri/binary/ dist/binary/windows_amd64/WebView2Loader.dll - desktop/tauri/src-tauri/binary/ dist/binary/all/portmaster.zip - desktop/tauri/src-tauri/binary/ dist/binary/all/assets.zip - desktop/tauri/src-tauri/binary/ dist/binary/windows_amd64/portmaster.exe - desktop/tauri/src-tauri/target/release/拷贝时会记录每个文件的路径、大小、SHA256 摘要取前 4 位与后 8 位及文件版本信息。拷贝情报数据将dist/intel/*整体复制到desktop/tauri/src-tauri/intel/。版本探测与一致性校验generate_windows_installers.ps1分别读取 Git 标签版本git tag --points-at无标签时回退git describe --tags --first-parent --abbrev0并去除前缀v、UI 版本portmaster.exe的文件版本、Core 版本执行portmaster-core.exe version解析输出、KEXT 版本portmaster-kext.sys文件版本。若三者不一致会打印警告交互模式下还会询问是否继续。确定打包版本号优先使用-v显式指定的版本否则采用 Core 版本。随后通过Set-CargoVersion临时改写desktop/tauri/src-tauri/Cargo.toml中的[package] version使 Tauri CLI 能据此生成正确的安装器文件名注意仅当tauri.conf.json5中未显式定义版本时该方法才生效打包完成后由Restore-CargoVersion恢复原文件。自动补齐工具链若环境中没有cargo脚本会通过Start-BitsTransfer下载rustup安装 stable 工具链若没有cargo-tauri.exe会下载tauri-cli-v2.2.7的预编译包到本地tauri-cli目录并直接调用。执行打包并搬运产物运行cargo tauri bundle成功后把target\release\bundle\nsis\*复制到仓库根的dist\windows_amd64\.msi文件同样由 WIX 目标生成于bundle\msi脚本注释中保留了对应拷贝语句。3.3 在 DockerWindows 容器中运行脚本头注释给出了容器化运行方式实测基于镜像abrarov/msvc-2022:latest$path Convert-Path . # 获取当前目录的绝对路径 docker run -it --rm -v ${path}:C:/app -w C:/app abrarov/msvc-2022 powershell -NoProfile -File C:/app/packaging/windows/generate_windows_installers.ps1前提是 Docker Desktop 已切换到Windows 容器模式脚本本身也会识别容器环境根据主机名包含container或用户名为ContainerAdministrator并自动配置 Git 的safe.directory避免在容器内报 Git 权限错误见 generate_windows_installers.ps1。四、手动构建Manual build若不想使用一键脚本也可以完全手动完成同样的打包这便于理解 Tauri 打包器本身的工作方式。4.1 前置条件确保已安装 Rust 与 Cargo并安装 Tauri CLI版本限定^2.0.0cargo install tauri-cli --version ^2.0.0 --locked4.2 目录结构在 Tauri 工程文件夹内创建binary与intel两个目录放入全部所需文件最终结构应与下列一致...\Portmaster\desktop\tauri\src-tauri\binary assets.zip index.json portmaster-core.dll portmaster-core.exe portmaster-kext.dll portmaster-kext.sys portmaster.zip WebView2Loader.dll ...\Portmaster\desktop\tauri\src-tauri\intel base.dsdl geoipv4.mmdb geoipv6.mmdb index.dsd index.json intermediate.dsdl main-intel.yaml news.yaml notifications.yaml urgent.dsdlbinary目录中portmaster-kext.dll/portmaster-kext.sys是 Windows 内核扩展驱动文件portmaster-core.dll是注入各进程的核心动态库源码位于 windows_core_dll 与 windows_kextportmaster.zip/assets.zip则是打包好的前端 UI 与静态资源。4.3 执行打包命令进入src-tauri目录cd desktop/tauri/src-tauri然后按需选择打包目标# NSIS 与 WIX 两种安装器都生成 cargo tauri bundle # 仅生成 NSIS.exe cargo tauri bundle --bundles nsis # 仅生成 WIX.msi cargo tauri bundle --bundles wix产物位于target\release\bundle\msi\ target\release\bundle\nsis\需要说明的是当前仓库中 tauri.conf.json5 的bundle.targets默认只启用了deb、rpm、nsismsi被注释掉因此本地默认执行cargo tauri bundle会以 NSIS 为主msi目标需通过--bundles wix或--bundles msi显式触发。4.4 两种安装器的打包配置Windows 打包配置集中在 tauri.conf.json5NSISinstallMode设为perMachine机器级安装使用 install_hooks.nsh 作为安装钩子安装器图标为assets/data/icons/pm_light_contrast.icoWIX通过fragmentPaths引入 files.wxs、old_service_check.wxs、migration.wxs 三个片段componentGroupRefs引用BinaryAndIntelFiles组件组即把 binary/intel 文件写入 MSI主模板为 main.wxs。从 WIX 模板的存在可以看出MSI 安装器内置了旧服务检测old_service_check与数据迁移migration逻辑。五、代码签名sign_binaries_in_dist.ps1无论是正式发布还是自行分发都建议先对二进制与安装器进行 Authenticode 签名。仓库提供了 sign_binaries_in_dist.ps1 完成这一工作.\packaging\windows\sign_binaries_in_dist.ps1 -certSha1 证书SHA1 [-timestampServer 时间戳服务器]参数说明参数必填说明-certSha1是代码签名证书的 SHA1 指纹用于定位本地证书存储中的签名证书-timestampServer否RFC 3161 时间戳服务器地址默认http://timestamp.digicert.com该脚本会递归扫描项目根\dist\目录下所有.exe、.dll、.sys、.msi文件见 sign_binaries_in_dist.ps1对每个文件先调用signtool verify检查签名状态已用同一证书签名 → 标记[signed OK]跳过被其他证书签名 → 标记[different]并报告实际签名主体未签名 → 收集进待签名列表最后批量执行signtool sign /tr $timestampServer /td sha256 /fd sha256 /sha1 $certSha1 /v 待签名文件...即使用 SHA256 摘要算法与时间戳进行签名。若环境中找不到signtool.exe脚本会在 PATH 与常见位置Windows SDK 的bin\ver\x64|x86、Visual Studio 的vswhere结果中自动搜索并提示需要安装 Windows SDK 或 Visual Studio 的C 桌面开发工作负载。六、调试 MSI 安装器打包或安装过程中出现问题时可使用以下手段排查6.1 打包阶段打开 verbose 日志构建 MSI 时加上--verbose标志即可看到 bundler 的详细输出cargo tauri bundle --bundles msi --verbose6.2 安装阶段捕获安装日志用msiexec的/lv参数把安装过程完整记录到日志文件msiexec /i target\release\bundle\msi\Portmaster_0.1.0_x64_en-US.msi /lv install.log/i表示安装/lv install.log表示将详细日志写入当前目录的install.log便于分析安装失败的具体步骤如服务注册、文件拷贝、驱动安装等。七、扩展阅读Linux 侧打包脚本顺序packaging目录同时维护着 Linux 打包相关文件其中 linux/readme.md 记录了 DEB 与 RPM 的维护脚本执行顺序差异DEBapt升级时依次执行旧版 remove → 新版 install → 旧版 remove 后置 → 新版 configure而 RPMdnf升级时install 与 remove脚本的先后与计数参数$1不同。相关的安装/卸载脚本实现见 postinst内含从 v1 旧目录/opt/safing/portmaster迁移配置、SELinux 权限修复、服务注册等逻辑与 postrmsystemd 服务单元则定义在 portmaster.service包含cap_net_admin、cap_net_raw等防火墙运行所需的 AmbientCapabilities。这些文件与 Windows 侧共同构成了 Portmaster 的完整分发体系可在 packaging/README.md 基础上按需延伸阅读。总结Portmaster 的 Windows 安装包生产是一条Linux 出料、Windows 组装的双环境流水线earthly release-prep负责把 Go Core、Tauri UI、KEXT 驱动与情报数据统一落盘到distgenerate_windows_installers.ps1负责文件装配、版本一致性校验与 Tauri 打包调用sign_binaries_in_dist.ps1负责对二进制与安装器做 Authenticode 签名。掌握这套流程后无论是复现官方构建、接入 CI 还是本地排查 MSI 问题都有清晰的命令与脚本依据可循。赞分享网络安全【免费下载链接】portmaster Love Freedom - ❌ Block Mass Surveillance项目地址https://gitcode.com/gh_mirrors/po/portmaster点击查看免费下载相关推荐构建 ILSpy Windows 安装程序MSI从发布产物到 WiX 打包全流程指南构建 ILSpy Windows 安装程序MSI从发布产物到 WiX 打包全流程指南 本指南以 ILSpy.Installer/README.md htt逆向工程开发工具桌面应用PowerToys 本地化构建产物如何打包进 MSI 安装包PowerToys 本地化构建产物如何打包进 MSI 安装包 PowerToys 的界面文案通过 resx / resw 资源文件和 lcl 翻译文件管理流桌面应用开发工具Sandboxie Classic NSIS 安装器构建指南从环境搭建到 32/64 位安装包产出Sandboxie Classic NSIS 安装器构建指南从环境搭建到 32/64 位安装包产出 Sandboxie Classic经典版的安装程序并非应用安全虚拟化桌面应用创作声明:本文部分内容由AI辅助生成(AIGC),仅供参考
返回列表