Skip to content

0003: Ports 80 and 443 through a launchd socket handoff

Status: accepted

macOS refuses unprivileged binds to loopback ports below 1024 (see Spikes). Binding the wildcard address would expose every site to the network, and running DevKit as root is not acceptable.

A launchd daemon plist with a Sockets key binds 127.0.0.1:80 and :443 as root and hands the descriptors to devkitd, which runs as the user (UserName).

No DevKit code runs as root and no signed privileged helper is needed. Setup needs one admin prompt to install the plist; removal needs another.