Spikes
Spike code lives in spikes/ and is never imported by DevKit.
Binding ports 80 and 443
Section titled “Binding ports 80 and 443”Question: can devkitd, running as the user, bind 127.0.0.1:80 and :443?
Result: no. On macOS 26 an unprivileged process gets EACCES for loopback ports below 1024; only the wildcard address is allowed, which would expose every site to the network.
Decision: a launchd job with a Sockets key binds both ports as root and hands them to devkitd running as the user (ADR 0003).
Driving php-fpm from Rust
Section titled “Driving php-fpm from Rust”Question: can the proxy talk to a static-php-cli php-fpm over a unix socket, and can that PHP load shared extensions such as Xdebug?
Result: yes. A pool is ready 22 ms after it starts, so pools can start on the first request. Keep-alive requests take about 90 µs each. A shared Xdebug built for the same PHP API loads into the static binary.
Gotcha: macOS limits unix socket paths to 104 bytes, and php-fpm silently listens elsewhere when the path is longer. DevKit keeps its sockets under a short folder and checks the length up front.