FotoVerite/pcheck

★ 0Forks 0GoGitHub ↗Compare

README

pcheck

pcheck shows what is listening on your machine without making you remember lsof flags.

It is a small, pipeable CLI for macOS and Linux. The default view stays conservative and factual; richer process context lives in the per-port detail view.

Install

Release binaries:

  • Download the latest binary from GitHub Releases and place pcheck in your PATH.

Go:

go install github.com/FotoVerite/pcheck@latest

Homebrew tap:

brew install <tap>/pcheck

Version:

pcheck --version

Quick Start

pcheck
pcheck 3000
pcheck --wide
pcheck --raw
pcheck --raw --no-header
pcheck --local
pcheck --public
pcheck --user=$(whoami)
pcheck --group=staff
pcheck --json

Example Output

Default:

$ pcheck
PORT  PROC      PID    STATE      BINDS
3000  node      42872  listening  127.0.0.1,[::1]
5432  postgres  812    listening  0.0.0.0
8080  node      55211  orphaned   127.0.0.1

Wide:

$ pcheck --wide
PORT  PROC   PID    BIND       STATE      CWD
3000  node   42872  127.0.0.1  listening  /Users/you/code/app
3000  node   42872  [::1]      listening  /Users/you/code/app

Raw:

$ pcheck --raw --no-header
3000	node	42872	127.0.0.1	you	staff	listening	/Users/you/code/app
3000	node	42872	::1	you	staff	listening	/Users/you/code/app

Detail:

$ pcheck 3000
Port:           3000
Process:        node
PID:            42872
Proto:          tcp
Bind:           127.0.0.1
State:          listening
CWD:            /Users/you/code/app
Command:        node server.js
Parent PID:     42860
Parent Process: npm

JSON:

[
  {
    "port": 3000,
    "process": "node",
    "pid": 42872,
    "proto": "tcp",
    "bind": "127.0.0.1",
    "state": "listening"
  }
]

States

  • listening: the process is present and listening, with no explicit abnormal condition detected
  • orphaned: the process looks detached and matches a likely runtime
  • zombie: the OS process state indicates zombie
  • unknown: metadata was incomplete or classification was not reliable

Design Principles

  • Facts first in the default view
  • Grouped text for humans, literal --wide and --json for precise inspection
  • --raw is normalized TSV for shell tools
  • JSON is a real interface, not an afterthought
  • Colors help scanning but never carry meaning alone
  • No shell-interpolated command execution
  • No hidden destructive behavior

Why Not Just Use lsof?

lsof is the underlying substrate on macOS, and it is powerful. pcheck exists to make the common case easy to remember:

pcheck
pcheck 3000

Safe Shell Usage

If you want to grep or post-process results, prefer --raw --no-header or --json.

Examples:

# tab-separated rows
pcheck --raw --no-header

# local listeners only
pcheck --raw --no-header --local

# exact port match
pcheck --raw --no-header | awk -F '\t' '$1 == "3000"'

# inspect with jq
pcheck --json | jq '.[] | select(.port == 3000)'

pcheck intentionally does not ship a built-in kill command in v1. If you want to terminate a process, extract the PID explicitly and run kill yourself:

pcheck --raw --no-header | awk -F '\t' '$1 == "3000" { print $3 }'
kill <pid>

That keeps process termination explicit and separate from inspection.

Development

make test
make build
make run

Contributors

FotoVerite

Issues