A compact overview of what is listening on which port, on macOS and Linux.
$ ports
PORT PROTO PID PROCESS USER ADDRESS SCOPE
22 tcp - - - 0.0.0.0 network
3002 tcp 96267 node knowone :: network
5173 tcp 79238 node knowone ::1 local
5432 tcp 92912 com.docker.backend knowone 0.0.0.0,:: network
8080 tcp 12044 java knowone 10.0.0.4 network
SCOPE is local when a socket is bound to loopback only, and network when
anything off this machine can reach it. A - means the kernel would not name the
owner: sockets belonging to other users are visible only to root.
ports everything that is listening
ports 3000 what is holding port 3000
ports 8000-8100 a range of ports
ports node listeners owned by a process matching "node"
ports 3000 --all plus the connections to and from that port
kill $(ports 3000 -p) stop whatever is holding the port
| Flag | Effect |
|---|---|
-a, --all |
include established connections, and the sockets listed below |
-p, --pids |
print matching PIDs only, one per line |
-j, --json |
print matching sockets as JSON, addresses unabbreviated |
--color <when> |
auto (default), always, never; --no-color is a shorthand |
Exit status is 0 when something matched, 1 when nothing did and 2 on an
error. Colour turns itself off for pipes and honours NO_COLOR.
A bare ports is a survey, so it leaves out sockets on port 0 and UDP sockets on
ephemeral ports (49152 and up), which are outbound flows rather than services. Any
filter switches that off, and --all switches off the listening-only default too:
a specific question always gets a complete answer.
cargo install --git https://github.com/simon-amadeus/ports
No dependencies, at build time or after. The socket table comes from /proc/net
and /proc/<pid>/fd on Linux and from libproc on macOS, with no call out to
lsof, ss or netstat.
MIT