mirror of
https://github.com/fluffos/fluffos
synced 2026-08-12 18:26:06 -04:00
* docs: add local full-text search and a contributor README Add @easyops-cn/docusaurus-search-local to the Docusaurus site so the docs get an offline search bar (index built at build time, no external service). English and zh-CN pages are both indexed, and matched terms are highlighted on the target page. Add docs/README.md describing the Docusaurus setup, local dev/build commands, search behavior, directory layout, and gotchas; exclude it from the published site alongside CLAUDE.md. Point the root README's docs/ entry at it. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TSzcESzU9947zkGzQ6SMmE * docs: remove dead framework leftovers, fix index generation, complete the nav Delete the VitePress (.vitepress/) and Jekyll (_layouts/, css/) leftovers, the one-shot migration scripts (fix_md_header.py, fix_seealso.py), and the stale keywords.json snapshot; prune the matching .gitignore entries and docusaurus exclude patterns. Rewrite gen_index.py for Docusaurus: it emitted dead .html links and legacy 'layout: doc' frontmatter, choked on non-markdown entries, and dropped nested categories — regenerating an index would have broken it. It now emits the extension-less links the site actually uses, links nested category indexes (restoring apply/* on the zh-CN index), and refuses to run on the docs root. Fix update_index.sh's copy-paste titles (zh-CN efun/build were titled 'APPLY'), stop it clobbering the hand-written lpc/index.md, and cover cli/. Regenerated indexes pick up the missing driver/ffi-plan entry. add_missing_efuns.py now takes the keywords.json path as an argument instead of requiring a stale copy. Move CNAME and the Google site-verification file into static/ so they actually reach the published build output. Complete the sidebar: link the CLI category to cli/index and add the missing portbind/symbol/generate_keywords pages, and expose the previously orphaned stdlib section under Reference. Promote onBrokenLinks to 'throw' now the build is warning-free, and drop the empty Demo section from the landing page. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TSzcESzU9947zkGzQ6SMmE * docs: strip legacy 'layout: doc' frontmatter from all pages Mechanical sweep removing the Jekyll-era 'layout: doc' line from every doc page's frontmatter (Docusaurus ignores it), and the matching line from the templates in docs/CLAUDE.md so new pages don't reintroduce it. No content changes. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TSzcESzU9947zkGzQ6SMmE --------- Co-authored-by: Claude <noreply@anthropic.com>
67 lines
2.6 KiB
Markdown
67 lines
2.6 KiB
Markdown
---
|
|
title: cli / portbind
|
|
---
|
|
# cli / portbind
|
|
|
|
`portbind` is a privilege-separated port binding utility for FluffOS. It allows the driver to bind to privileged ports (< 1024) and then drop privileges before execution.
|
|
|
|
## Usage
|
|
|
|
```bash
|
|
./portbind -p <port> [-d <driver_path>] [-u <uid>] [-g <gid>] [-i <ip_address>] [driver_args...]
|
|
```
|
|
|
|
## Options
|
|
|
|
| Option | Description | Required |
|
|
|-------------------|--------------------------------------------------------------|----------|
|
|
| `-p <port>` | Port number to bind to | Yes |
|
|
| `-d <driver>` | Path to the driver executable (default: `./driver`) | No |
|
|
| `-u <uid>` | User ID to drop privileges to after binding | No |
|
|
| `-g <gid>` | Group ID to drop privileges to after binding | No |
|
|
| `-i <ip_address>` | IP address to bind to (default: INADDR_ANY) | No |
|
|
| `driver_args...` | Additional arguments passed to the driver | No |
|
|
|
|
## Description
|
|
|
|
`portbind` solves the problem of binding to privileged ports (ports below 1024) which typically require root privileges. The tool:
|
|
|
|
1. Binds a socket to the specified port (requires root if port < 1024)
|
|
2. Passes the bound socket to the driver via file descriptor 6
|
|
3. Drops privileges to the specified UID/GID if provided
|
|
4. Executes the driver with any additional arguments
|
|
|
|
This allows the driver to run as an unprivileged user while still binding to privileged ports like port 23 (telnet) or port 80 (HTTP).
|
|
|
|
## Security Considerations
|
|
|
|
- The `portbind` utility itself must have appropriate permissions (typically setuid root) to bind to privileged ports
|
|
- Always specify `-u` and `-g` to drop privileges after binding
|
|
- The driver will inherit the bound socket on file descriptor 6
|
|
|
|
## Examples
|
|
|
|
**Bind to port 23 (telnet) and run as user 1000:**
|
|
```bash
|
|
sudo ./portbind -p 23 -u 1000 -g 1000 -d ./driver etc/config.prod
|
|
```
|
|
|
|
**Bind to a specific IP and port:**
|
|
```bash
|
|
sudo ./portbind -p 80 -i 192.168.1.100 -u www-data -g www-data ./driver etc/config.web
|
|
```
|
|
|
|
**Bind to port 4000 (non-privileged, for testing):**
|
|
```bash
|
|
./portbind -p 4000 -d ./driver etc/config.test -ftest
|
|
```
|
|
|
|
## See Also
|
|
|
|
- [driver](driver.md) - Main FluffOS driver executable
|
|
|
|
## Notes
|
|
|
|
- The socket is placed on file descriptor 6 before executing the driver
|
|
- The driver configuration should be set up to use the pre-bound socket
|
|
- All arguments after the portbind options are passed to the driver unchanged
|