mrambossekandClaude Fable 5 5d7f59a66a
server-release / image (push) Successful in 15s
server-test / test (push) Successful in 34s
server-release / release (push) Successful in 35s
acme: answer HTTP-01 from the server itself, on port 80
HTTP-01 always arrives on port 80 - the CA chooses the port, not the operator -
so it never collides with an admin UI on 443. The conflict only exists for
TLS-ALPN-01, which is the challenge type that does use 443.

Given that, the server keeps a permanent listener on 80 that answers challenges
from a webroot and redirects everything else to the admin UI. Same arrangement
as the webroot plugins for Apache and nginx, and better than letting the ACME
client bind 80 per renewal: nothing binds and unbinds, so a renewal cannot fail
because the port was briefly busy, and the client needs only write access to a
directory instead of the privilege to bind a low port. Port 80 also gets a use
it would want anyway.

The ACME client stays an external program. lego is also a Go library, but
importing it would put a large dependency tree into a server that deliberately
has none, and the CLI does the same job from a timer.

Tokens are validated by *shape* before any filesystem call, so traversal never
reaches the disk - a stronger guarantee than sanitising a path and trusting the
sanitiser.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-01 18:16:09 +02:00

echolot — measure, don't guess

Echolot

Free software for detecting and debugging local network issues from an Android phone — built for people who actually know what a neighbor table is.

Most "wifi analyzer" apps show you signal bars. Echolot aims at the layer where home and office networks actually break: duplicate DHCP servers, broken IPv6 RAs, MTU black holes, NAT64 weirdness, multicast that dies at the AP, DNS that answers differently than it should. It records what it observed, separates observation from interpretation, and exports the whole run so you can argue with it later.

Status: pre-release. The capability prober runs on real hardware; the production app and the probe server are not built yet.

Repository layout

docs/              design docs — the contract for everything below
echolot-prober/    capability prober: validates the no-root feasibility matrix on real devices

The Go probe server and the production app land here as siblings.

Design docs

The three specs are draft-complete and reviewed; treat them as the contract.

Doc What it defines
docs/feature-catalog-and-feasibility.md Full feature list + the no-root feasibility matrix
docs/measurement-schema.md Archived/exportable measurement JSON (observation vs finding, two-clock rule, anonymization)
docs/probe-protocol.md Client↔server wire protocol (pinned TLS control plane, binary UDP data plane, STUN, canary DNS)
docs/build-status.md Running log of decisions and next steps

Privilege tiers

Every result records which tier produced it:

  • app — no root, no special setup. The bulk of the functionality.
  • shizuku — ADB-shell privileges via wireless pairing, no root. Shipped in v1.
  • root — future optional module.

Licensing

Part License Why
All code (app, prober, server) GPL-3.0-or-later The value here is the platform-API research; copyleft keeps derivative apps free
docs/ (the specs) CC-BY-4.0 A wire protocol and a measurement format should be implementable by anyone, without license anxiety

Full texts: LICENSE (GPLv3) and docs/LICENSE (CC BY 4.0). Sources carry SPDX-License-Identifier headers.

If you want to build a compatible server or client, the protocol and schema docs are deliberately permissive — go ahead.

Building

See echolot-prober/README.md. Short version, from echolot-prober/:

echo "sdk.dir=/path/to/Android/sdk" > local.properties
./gradlew :app:assembleDebug
S
Description
No description provided
Readme GPL-3.0
1.3 MiB
2026-08-02 14:58:41 +02:00
Languages
Kotlin 61.6%
Go 36.2%
HTML 1%
Shell 0.5%
Python 0.4%
Other 0.2%