A phone reported "IPv6 is configured but not working" while loading an IPv6-only site over TCP perfectly well. The finding fired on one signal - ICMPv6 echo getting no reply - at HIGH confidence. ICMPv6 echo is widely filtered on networks where IPv6 works, so the two cases are indistinguishable from where the app stands, and it was picking one. Same class of error as the multi-homed downstream-loss bug: a confident measurement of something that was not happening. Now v6.no_icmp_reply, low severity, medium confidence, naming both explanations. Still reported, because filtered ICMPv6 breaks Path MTU Discovery - large packets vanish instead of being reported as too big - which is a fault in its own right. Corroborating with a real IPv6 connection would separate the two properly, but needs a target, which runs into the hardcoded-deployment issue already open. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Echolot app
The production Android client (spec). Native Kotlin + Jetpack Compose. Multi-module; built bottom-up from a verifiable protocol spine.
Modules
| Module | Type | Status |
|---|---|---|
core-protocol |
pure Kotlin/JVM | done — client half of probe-protocol.md, verified live against the server |
core-measurement |
pure Kotlin/JVM | planned — measurement-schema.md types |
core-probe |
Android lib | planned — app-tier probes, ported from echolot-prober |
core-shizuku |
Android lib | planned — dual-path executor (UserService + newProcess fallback) |
app |
Android app | planned — Compose UI |
core-protocol is deliberately Android-free so it builds and unit-tests on any JDK (no Android
SDK) and can run integration tests against a live server.
core-protocol
Implements the control plane (SPKI-pinned enrollment/profile/sessions via HttpsURLConnection —
Android-API-1 compatible, hostname verification off because trust is the pin), the HKDF-SHA256
session-key schedule, and the binary ELT1 UDP data plane (HMAC gate, ECHO + observation block,
MTU probe) — byte-compatible with the Go server.
./gradlew :core-protocol:test # unit tests (crypto vectors, wire round-trip)
scripts/test-fmr.sh # live end-to-end test against the deployed server
test-fmr.sh mints an enrollment token over SSH, enrolls via the public control plane, computes
the SPKI pin from the served cert, and runs LiveServerTest — proving the client speaks the wire
protocol to the real server (enroll → profile → session → echo+observation → MTU → observations).
The live test self-skips when ECHOLOT_LIVE_* env vars are absent, so unit runs and CI stay green
offline.