Ping from the r-no.fr server
serverPart of this tool runs on the r-no.fr server: that part cannot be checked from your browser. Why, and what it does.
Examples:
Pinging your own address shows whether your connection answers when seen from outside, not from inside your network.
Transparency
A browser cannot send a ping. And the point of this tool is to test another network path than yours: so the r-no.fr server sends the ping, not your browser. Your browser sends it the address, and shows the result.
- Why this tool is tagged [server]
- The code that pings runs on the server. Its source, ping.py, is shown below with its fingerprint, and the server is built from that very file, at the same version as this page. But nothing lets you check from here that it is what actually runs: for that part, you have to trust r-no.fr. Everything that runs in your browser can be checked, as on the other tools.
- What the server receives
- The address to ping, in the body of a request, and, like any website, your IP address and browser name.
- What the server keeps
- Your IP address and the address you pinged, in memory only, for the limits below: ten minutes at most, never on disk, and erased when the service restarts. The ping service writes no log line for a request. Like for any page of the site, the server's access logs note the request (IP address, date and time, address requested, browser name), but not its content: the pinged address is not in them.
- What the pinged address sees
- Four ICMP echo requests of 64 bytes, one second apart, coming from the address of the r-no.fr server, never from yours. Their content says where they come from (
r-no.fr/ip/ping), so that the administrator of that machine knows whom to ask. - Guardrails
-
They keep the server from being used against anyone, and its address from ending up on blocklists:
- IPv4 addresses written in digits only, never a name: the server resolves no name for you.
- Never a private, local or reserved address (10.0.0.0/8, 192.168.0.0/16, 127.0.0.0/8…), nor the server's own. They are refused in your browser, and again by the server.
- Always four packets of 64 bytes, one second apart: neither the count, nor the size, nor the pace can be chosen.
- No continuous ping: never more than four packets per request, and a compulsory 30-second pause between two pings from the same visitor, enforced by the server. Even a looping script gets no more.
- At most 10 pings per visitor, 10 per pinged address (all visitors together), 20 per /24 network (against the scanning of a range) and 120 for the whole service, over 10 minutes. One ping at a time per visitor, four at a time in all.
- Only this page's requests are answered (Sec-Fetch-Site and Origin headers, set by your browser). A script can forge them: it is a brake, and the limits above remain the real guardrail.
- An address whose holder asks not to be pinged from here is excluded. The service can also be paused at once.
- Enforced by your browser
- This page's Content Security Policy allows this site itself (
connect-src 'self'), for the ping and for the “My address” button, which asks ip/my-ip. No form submission (form-action 'none'). One more destination is allowed, as on every page of the site:https://stats.r-no.fr, the audience measurement (see below). - Audience measurement
- Like every page of the site, this one counts its visit with Umami, installed on R-no’s own server (
stats.r-no.fr). It receives the address of the page, without parameters or anchor, the site you came from (its domain only), your browser, system, language and screen size, and the country, region and city deduced from your IP address, which is not kept. It never receives what you type, nor the result of the tool. No cookie, nothing stored in your browser; if your browser asks not to be tracked (Do Not Track), nothing is measured. The data is erased after 25 months.- /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
SHA-256225eec74fd12623d82fc05ee7d222be629ce454d081c129e8d1e249ed37ee716 - https://stats.r-no.fr/m.js: Umami’s tracker, open source (MIT), served by the measurement server. Its fingerprint is not shown here: it changes with each version of Umami, and you cannot check from your browser that it is the published code. For that part, you have to trust R-no.
- /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
- What is stored in your browser
- No cookie, and nothing in the address of this page. Your language is given by the address itself (
/en/or/fr/): nothing is stored to remember it. - Code
-
In your browser, checkable
- app.js: checks the address, asks the server, and computes and shows the result (losses, minimum, average…). Written for R-no Toolbox, not minified, no third-party library. 14.3 kB
SHA-256611623500e74d71ecc1f32fa8ae10dca8caa0cd9bed7ac1f8b20187104f7ee7d - textes.js: the French messages of the tool, shown by its script (the rest of the French page is written into its HTML when the site is built). It only defines texts, with no logic. 11.0 kB
SHA-256f23f7a1c84d41450b8f2778fd04fd1bb105e5066bd89463def5add6a2b2196c1 - /commun/langue.js: the language helper, the same on every page of the site. It reads the language of the page and gives the tool its messages in that language. It stores nothing. 1.6 kB
SHA-25680f76f69773ef628d36d09bf8387cfedebda4529210d7120649b6f5603310631
On the server, to be trusted
- ping.py: the ping service: the checks, the limits and the sending of the packets. Python, standard library only, no privilege needed on the server. The service runs this file, built from the same commit. 17.9 kB
SHA-256058c171b34be416bee83fd21163d969355cdba1e5c4d20710192da0c21e4623a
- app.js: checks the address, asks the server, and computes and shows the result (losses, minimum, average…). Written for R-no Toolbox, not minified, no third-party library. 14.3 kB
- Tested
- The checks of addresses, the limits, the packets and the answers of the service are covered by automated tests, run on every deployment, as is the reading and display of results in your browser.
- Check it yourself
- Download a file and compare its fingerprint with the one above:
curl -s https://r-no.fr/ip/ping/app.js | shasum -a 256curl -s https://r-no.fr/ip/ping/ping.py | shasum -a 256 - Limits
-
- No answer does not mean down: many firewalls and routers drop pings. And an answer says nothing about the ports (web, mail…): ping is ICMP, not TCP or UDP.
- The times are those between the r-no.fr server and the address, not between you and it.
- An answer that takes more than one second counts as lost.
- IPv4 only for now: the server has no IPv6 connection.