fluffos/docs/cli/portbind.md
Yucong Sun c914f03d66
Add local search and documentation guide for docs site (#1221)
* docs: add local full-text search and a contributor README

Add @easyops-cn/docusaurus-search-local to the Docusaurus site so the
docs get an offline search bar (index built at build time, no external
service). English and zh-CN pages are both indexed, and matched terms
are highlighted on the target page.

Add docs/README.md describing the Docusaurus setup, local dev/build
commands, search behavior, directory layout, and gotchas; exclude it
from the published site alongside CLAUDE.md. Point the root README's
docs/ entry at it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TSzcESzU9947zkGzQ6SMmE

* docs: remove dead framework leftovers, fix index generation, complete the nav

Delete the VitePress (.vitepress/) and Jekyll (_layouts/, css/) leftovers,
the one-shot migration scripts (fix_md_header.py, fix_seealso.py), and the
stale keywords.json snapshot; prune the matching .gitignore entries and
docusaurus exclude patterns.

Rewrite gen_index.py for Docusaurus: it emitted dead .html links and
legacy 'layout: doc' frontmatter, choked on non-markdown entries, and
dropped nested categories — regenerating an index would have broken it.
It now emits the extension-less links the site actually uses, links
nested category indexes (restoring apply/* on the zh-CN index), and
refuses to run on the docs root. Fix update_index.sh's copy-paste titles
(zh-CN efun/build were titled 'APPLY'), stop it clobbering the
hand-written lpc/index.md, and cover cli/. Regenerated indexes pick up
the missing driver/ffi-plan entry. add_missing_efuns.py now takes the
keywords.json path as an argument instead of requiring a stale copy.

Move CNAME and the Google site-verification file into static/ so they
actually reach the published build output.

Complete the sidebar: link the CLI category to cli/index and add the
missing portbind/symbol/generate_keywords pages, and expose the
previously orphaned stdlib section under Reference.

Promote onBrokenLinks to 'throw' now the build is warning-free, and drop
the empty Demo section from the landing page.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TSzcESzU9947zkGzQ6SMmE

* docs: strip legacy 'layout: doc' frontmatter from all pages

Mechanical sweep removing the Jekyll-era 'layout: doc' line from every
doc page's frontmatter (Docusaurus ignores it), and the matching line
from the templates in docs/CLAUDE.md so new pages don't reintroduce it.
No content changes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TSzcESzU9947zkGzQ6SMmE

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-09 22:09:55 -04:00

2.6 KiB

title
cli / portbind

cli / portbind

portbind is a privilege-separated port binding utility for FluffOS. It allows the driver to bind to privileged ports (< 1024) and then drop privileges before execution.

Usage

./portbind -p <port> [-d <driver_path>] [-u <uid>] [-g <gid>] [-i <ip_address>] [driver_args...]

Options

Option Description Required
-p <port> Port number to bind to Yes
-d <driver> Path to the driver executable (default: ./driver) No
-u <uid> User ID to drop privileges to after binding No
-g <gid> Group ID to drop privileges to after binding No
-i <ip_address> IP address to bind to (default: INADDR_ANY) No
driver_args... Additional arguments passed to the driver No

Description

portbind solves the problem of binding to privileged ports (ports below 1024) which typically require root privileges. The tool:

  1. Binds a socket to the specified port (requires root if port < 1024)
  2. Passes the bound socket to the driver via file descriptor 6
  3. Drops privileges to the specified UID/GID if provided
  4. Executes the driver with any additional arguments

This allows the driver to run as an unprivileged user while still binding to privileged ports like port 23 (telnet) or port 80 (HTTP).

Security Considerations

  • The portbind utility itself must have appropriate permissions (typically setuid root) to bind to privileged ports
  • Always specify -u and -g to drop privileges after binding
  • The driver will inherit the bound socket on file descriptor 6

Examples

Bind to port 23 (telnet) and run as user 1000:

sudo ./portbind -p 23 -u 1000 -g 1000 -d ./driver etc/config.prod

Bind to a specific IP and port:

sudo ./portbind -p 80 -i 192.168.1.100 -u www-data -g www-data ./driver etc/config.web

Bind to port 4000 (non-privileged, for testing):

./portbind -p 4000 -d ./driver etc/config.test -ftest

See Also

  • driver - Main FluffOS driver executable

Notes

  • The socket is placed on file descriptor 6 before executing the driver
  • The driver configuration should be set up to use the pre-bound socket
  • All arguments after the portbind options are passed to the driver unchanged