A converter that's wrong is worse than no converter: you trust its output precisely because you couldn't do the conversion in your head. This page is the standing answer to “why should I believe these tools?”
Every tool keeps its logic in a plain ES module with no DOM access. The
page is a thin layer that wires inputs to that module; the module is what
gets tested, with Node's built-in node:test. As of this
writing: 24 tools, 330 tests. The deploy script runs every suite,
then loads every page of the site in a real headless Chromium — no
console errors, no failed requests, every example button must produce
visible output — and refuses to publish if anything is red. There is no
path to the server that skips the tests.
Ordinary example-based tests are the floor, not the method. Wherever possible each suite leans on one or more of these stronger checks:
| subnet | IPv4: hand-verified vectors for the edge prefixes (/0, /31 per RFC 3021, /32), rejection of non-contiguous masks, RFC 1918 classification; the JS 32-bit signed-shift traps are pinned in tests. IPv6: differential against Python's ipaddress module — 600 values through RFC 5952 formatting and RFC 4291 parsing (both compact and exploded spellings), 300 random CIDRs through network/last/netmask math — plus pinned RFC 5952 canonicalization vectors. |
|---|---|
| cron | Pinned plain-English descriptions, Vixie's dom/dow either-matches rule, leap days, short months, year rollover. Next-run computation is checked against hand-computed schedules. |
| jwt | HMAC-SHA-256/384/512 verification vectors cross-checked against node:crypto; tampered-payload rejection; a documenting test for the 2 discarded trailing bits in a base64url-encoded 256-bit MAC. |
| diff | Differential against git apply: generated unified diffs must patch A into B byte-exactly (60 random pairs plus trailing-newline edge cases). Reconstruction property over 500 seeded-random pairs; minimality proven against an independent LCS dynamic program. |
| epoch | Own strict ISO 8601 parser with round-trip rejection of impossible dates (Feb 30), leap-second messaging, and all time context passed explicitly so timezone behavior is pinned in tests (+02:00, −05:00) rather than inherited from the machine. |
| chmod | Differential against the real GNU chmod binary: 336 expression × mode × file-type combinations applied to actual files and directories, plus an all-4096-modes round-trip. The oracle corrected two misread man-page semantics before ship. |
| color | Differential against culori: 2000 random colors through OKLab both ways, worst disagreement 3.7×10⁻⁸; parser agreement on sampled CSS strings; verified vectors pinned. WCAG contrast from the spec formula. |
| url | Differential against Node's domainToUnicode for the hand-written RFC 3492 punycode decoder; strict percent-decoding with error positions; form-semantics vectors. |
| uuid | Differential against Python's uuid module (300 random UUIDs: variant, version, v1 timestamp/clock-sequence/node); ULID decode cross-checked against the reference ulid npm package; RFC 9562 Appendix A vectors pinned; 1000-value Crockford base32 round-trip; crypto.randomUUID() outputs must decode as v4/RFC. |
| base | Differential against Python: int(s, base) on 300 random value×base pairs, format() for hex/oct/bin/dec, struct.pack for every two's-complement width (boundary values pinned: −2ʷ⁻¹, −1, 0, 2ʷ⁻¹−1), and bit_length()/bit_count(). Round-trip property across all 35 bases; prefix-vs-digit ambiguities ("0b1" in hex, "0o…" in base ≥ 25) pinned. |
| cert | Differential against openssl x509: certificates generated with varied key types (RSA 2048/4096, EC P-256/P-384, Ed25519), unicode and escaping-heavy distinguished names, SANs (DNS, IPv4/IPv6, email, URI), key-usage combinations, and 2051 expiry dates — subject/issuer in RFC 2253 form, serial, validity instants, SHA-256 fingerprint, key size, and signature algorithm must all agree with openssl's reading. The site's own 4-certificate production chain is pinned as a fixture. Hand-built DER vectors for the UTCTime 1950/2049 pivot, multi-byte OID components, negative INTEGERs, and BER-indefinite-length rejection. |
| csr | Differential against openssl req: requests generated with RSA/EC/Ed25519 keys, unicode DNs, SANs, key-usage/EKU/CA:TRUE extension requests, and challengePassword attributes — subject in RFC 2253 form, key size, signature algorithm, and SAN sets must agree with openssl's reading. Self-signature verification (WebCrypto) is tested positively on every generated request and negatively on a bit-flipped one, which openssl req -verify must also reject. Hand vector for DER→raw ECDSA signature conversion. |
| qr | Three independent oracles. Full-matrix differential against the segno reference implementation: all 160 version/level combinations with forced parameters must match bit for bit, and on random inputs the automatically chosen version and mask pattern (penalty scoring) must agree too. Every generated symbol is rendered to an image and must decode to the exact input bytes with zbar, and qrencode — a third, unrelated implementation — must produce symbols that decode identically. Reed-Solomon arithmetic checked against an independently written GF(256) division; BCH format/version codes verified to have the minimum Hamming distances the standard guarantees (7 and 8); ISO capacity corner values (7,089 digits / 4,296 alphanumeric / 2,953 bytes at version 40) pinned. |
Differential against Python's email stdlib, an independent widely-deployed implementation of the same RFCs: header splitting/unfolding vs email.parser on 124 generated messages (folded headers, mbox lines, malformed lines, CRLF), date parsing vs parsedate_to_datetime on 200 generated RFC 5322 dates (obsolete zone names, two-digit years, comments — with the RFC-vs-POSIX year-pivot divergence documented and excluded), address lists vs getaddresses (quoted display names, groups, comments), RFC 2047 encoded-words vs decode_header (B and Q, adjacent-word whitespace rules). Received / Authentication-Results / DKIM parsing, which Python does not structure, is pinned against RFC 8601-style vectors and two full realistic fixtures — one that must produce zero warnings and one where every red flag must fire. | |
| unicode | Two oracles at once. The character data (34,823 names plus category and script tables) is generated from the Unicode Character Database 15.0.0 by a committed build script; the committed tests then check ~5,000 sampled codepoints against Python's unicodedata — an independent decoder of the same standard — for names (including algorithmic Hangul-syllable composition and CJK ranges) and categories, and check the script table against Node's own ICU via \p{Script=…} regexes. Normalization forms are differential-tested against unicodedata.normalize. Grapheme/byte counts pinned (ZWJ families, flags, skin tones) and cross-checked against Python's UTF-8 lengths. A found divergence, documented in the tests: Python has no algorithmic names for Tangut ideographs; the tool follows the standard. |
| sshkey | Differential against ssh-keygen itself: keys of every supported type (Ed25519, RSA at several sizes, ECDSA P-256/384/521, DSA) plus user and host certificates are generated fresh at test time, and the decoder's type, bit size, SHA256 and MD5 fingerprints, certificate fields (key ID, serial, principals, validity, extensions, signing-CA fingerprint), and the complete randomart drawing must match ssh-keygen -lf / -Lf / -lv output — the randomart byte for byte. authorized_keys quoting is checked against lines ssh-keygen itself accepts; hashed known_hosts entries come from ssh-keygen -H. Private-key refusal, truncated blobs, and type-mismatch rejection covered. |
| spf | Differential against three independent reference implementations. SPF mechanism grammar against pyspf on ~400 generated mechanisms (qualifiers, macros, dual-CIDR, malformed addresses — validity, mechanism, prefix length, and qualifier result must all agree), and full-record evaluation against pyspf's checker on 150 generated ip4/ip6/all records with probe IPs, which needs no DNS. DMARC tags, RFC 9989 defaults (sp ← p, np ← sp), and validity against checkdmarc on 120 generated records. DKIM tag-list strictness (duplicate tags, empty segments, whitespace) against dkimpy. DKIM key sizes verified against openssl-generated RSA and Ed25519 keys, including the SPKI-wrapped-Ed25519 generator mistake. Where an oracle diverges from the RFC text (pyspf accepts a zero digit transformer and bare exists; checkdmarc's invalid-tag-value handling contradicts RFC 9989 §4.7 relaxation), the divergence is documented in the test and the RFC behavior is pinned. Zone-file/dig quoting with RFC 1035 escapes and multi-string concatenation covered by vectors; clean fixtures must produce zero warnings, nasty ones must fire every flag. |
| bytes | Differential against two Python packages that disagree with each other — humanfriendly for byte units (250 generated sizes; its float pipeline loses exactness above 2⁵³, so pools stay below that and the loss is documented) and bitmath for the strict case-sensitive notation including bit units (200 generated sizes — kb is kilobits, kB kilobytes), which humanfriendly silently misreads as bytes. The exact BigInt rational arithmetic is re-derived independently with Python's fractions.Fraction on 150 mantissa×unit pairs including e-notation. Significant-digit rendering, duration formatting, rate parsing (Mbps vs MB/s vs MBps), the 500-GB-drive = 465.66-GiB gap, and the sloppy-lowercase ambiguity rules are pinned; a 600-case round-trip property bounds display error at 4 significant digits. |
| robots | Differential against protego, Scrapy's RFC 9309 robots.txt parser — 150 generated files (multi-group, shared and repeated user-agent tokens, wildcards, anchors, percent-encoded and non-ASCII patterns, crawl-delays, sitemaps) × 4 paths each, where the allow/block verdict, crawl-delay, and sitemap list must all agree, plus real-world-shaped fixtures (WordPress, AI-crawler policies) across six user-agents. The oracle was calibration-probed before a line of the tool was written, which pinned the details the RFC leaves easy to get wrong: specificity is measured on the percent-normalized pattern, a matching named group fully shadows *, groups sharing a token merge, a Sitemap or unknown line ends a run of user-agent lines (blank lines and comments don't), and %2F never equals a literal slash. One divergence is deliberate and documented: protego does not strip a UTF-8 byte-order mark and silently loses the first line — this tool strips it like Google's parser does, and warns, because that BOM breaks real parsers. |
| cookie | Differential against a real browser's cookie jar. Generated Set-Cookie lines are served to live headless Chromium over raw sockets (so control bytes and oversized headers can be tested) and the resulting jar is read back: acceptance, name, value, domain, path, expiry, Secure/HttpOnly, and SameSite must all match the model's prediction, across 25 seeded batches per run. Calibration probes pinned the rules the RFC leaves to implementations: any control byte (TAB included) rejects the whole cookie, name+value over 4096 bytes rejects while an attribute value over 1024 bytes is dropped silently, expiry is capped at 400 days, fractional Max-Age is ignored, impossible calendar dates (31 Nov) fail rather than roll over, "localhost" is treated as a public suffix, and a nameless cookie whose value contains "=" or spoofs a __Host- prefix is rejected. The RFC 6265 date parser is separately differential-tested against curl's independent C implementation (which applies no expiry cap, exposing the raw parsed epoch); five genuine curl-vs-browser divergences surfaced and are documented in the tests: curl honors timezone offsets, accepts times without seconds, fails on unknown weekday tokens, handles full month names differently, and rolls impossible dates over. |
| csp | Differential against a real browser. The URL-matching engine is tested against live headless Chromium: pages served with generated img-src policies attempt real loads, and a blocked load is detected by its securitypolicyviolation event (CSP runs before DNS, so fake hosts work) — ~250 verdicts per run across host wildcards, ports, scheme upgrades, paths, percent-encoding, 'self', and fallback chains, plus a pinned 66-cell scheme×port matrix measured from Chrome. Calibration probes before writing the tool pinned undocumented behavior: a scheme-upgrade match (http source, https URL) requires the URL port to be 443 even when source and URL ports are equal, IPv6-literal sources can never match, invalid expressions are dropped individually, and query strings in source paths are ignored. Findings are separately differential-tested against Google's csp-evaluator on 400 generated policies (parser must agree exactly; findings compared by category). Two csp-evaluator divergences from real browsers are documented in the tests: it claims IP sources are ignored (Chrome enforces them), and its effective-policy model strips default-src values under 'strict-dynamic' for non-script loads too (browsers only ignore them for scripts). |
| gitignore | Differential against git itself — git check-ignore -v -n -z --no-index --stdin in a throwaway repo with global/system config neutralized, which reports the deciding pattern and line number for every path, so verdict, pattern text, and line are all pinned at once: 120 generated files × 6 paths plus hand-picked nasty structures (the gitignore(5) re-inclusion example, the excluded-parent trap, byte-level wildcards). Calibration probes pinned git's real two-stage algorithm: a directory-exclusion walk from the top (in which an explicitly queried directory's own name is the final step, and dir-only patterns participate) followed by a self-scan of the raw query string (where a trailing-slash query has an empty basename and dir-only patterns are skipped) — details the documentation does not spell out. A randomized 7,200-check sweep then caught one more: a bare ! line is a real pattern in git (a negation with an empty stem) that actually flips verdicts on directory queries; it is pinned in the committed suite. Matching is byte-based like git's, so caf? must not match café. |
| ua | uap-core's own 18,000+ test fixtures, plus an engine-vs-engine differential against the reference Python implementation — identification uses the ua-parser community's regexes.yaml (pinned commit, Apache-2.0), so correctness splits in two: the data is theirs, but the matching engine is reimplemented here and mirrors the reference's subtle replacement semantics (family $1-substitution without trimming, version replacements taken verbatim, OS/device templates substituted then trimmed then nulled, first match wins, case-sensitive unless flagged). Every one of the 18,213 uap-core fixtures must pass, and then uap-python's BasicResolver is loaded with the same regexes.yaml and both engines are run over fixture strings plus seeded random ASCII mutations of them (800+ per seed, multi-seed swept) — the layer that catches Python-re-vs-JS-RegExp semantic drift the fixed corpus misses. One such divergence is real and pinned in its own test: Python's \d matches Unicode digits and JavaScript's does not, so the same uap rules can classify a UA containing e.g. Arabic-Indic digits differently depending on the implementation language (mutations stay ASCII so this known class doesn't drown real bugs). |
| hash | Differential against the coreutils binaries (md5sum, sha1sum, sha256sum, sha512sum) on real files, against node:crypto at every padding-boundary length 0–130 plus multi-block sizes, and against node:zlib for CRC-32 (200 random inputs). All seven RFC 1321 MD5 vectors, FIPS 180 SHA vectors, and RFC 2202 / RFC 4231 HMAC vectors (including the key-longer-than-block cases) pinned. HMAC checked against node:crypto for key lengths 0 through 3× block size. |
Oracles used during development (like culori and
ulid) are installed once in a scratch directory, used to
verify, and never become dependencies — the verified values are pinned
into the committed tests, and the site itself remains dependency-free.
The method only matters if it finds real errors before you do. A sample, kept honestly:
srgbToLinear sent every negative channel down the linear branch (c <= 0.04045 is true for all negatives) while its inverse mirrored through the origin — so out-of-gamut round trips drifted in lightness (0.7 → 0.76). Caught by the culori differential.c − 48 < 10 accepts every character below “0”, since negative numbers are less than ten. Caught by malformed-input tests; ranges are now validated explicitly.8080 → 9090 keeps the two zeros and edits each digit separately. The oracle was right; the intuition wasn't.8 − len % 8 zero bits, injecting a spurious 0x00 codeword when the stream is already aligned. ISO/IEC 18004 §7.4.10 pads only when the stream does not end at a boundary. Decoders ignore padding, so nobody had noticed. This time the differential caught a bug in the oracle; the test patches it back to the ISO behaviour and documents why.x.example:8080 match https://x.example:8080 — ports equal, scheme upgradeable, and the CSP3 spec reads like a match. Chrome blocks it: when a scheme matches only via the http→https upgrade, the URL port must be 443, and the source port must itself be 80, 443, or absent. Port equality does not count under an upgraded scheme. Caught by the pinned scheme×port matrix measured from a real browser before the matcher was written.= with an omitted “who” clears bits the umask masks (the umask limits only what gets set), and = on directories preserves setuid/setgid unless explicitly changed. Both surfaced only because the differential ran the real binary.Honesty requires the other column. The DOM glue in each page — event wiring, rendering — is not unit-tested; it is kept deliberately thin so the tested module does all the thinking, and it is exercised only by the headless-browser smoke test above, which catches breakage but does not judge whether rendered output is right. And a test suite, however adversarial, bounds confidence rather than proving correctness — if you find a wrong answer, the issue tracker is open, and a failing input is the most valuable thing you can send.