Hollowport Lab
See what your traffic tool actually shows
A small, controlled set of real network behaviors with a documented, independent record of exactly what the server did. Run one with any traffic observer capturing — Hollowport or anything else — then compare what it showed against the ground truth here.
Semantics & observation
Status codes, response bodies, headers, redirects, compression, timing. These run over ordinary HTTPS to this site.
They establish what an observer did with the meaning of a response. They do not establish anything about the wire: this site sits behind a CDN, so the connection your tool sees is to the edge, not to an origin we control.
Transport & connection
ALPN, HTTP/2 multiplexing, HTTP/3 / QUIC, TLS versions and certificate failures, raw connection behavior.
These need a transport-preserving origin — a host that speaks the real protocol end to end with no HTTP-aware proxy in between. That origin doesn't exist yet, so these groups are listed but not runnable.
Test groups
The shape of the eventual catalog. Only HTTP semantics is runnable today.
HTTP semantics
LiveStatus, headers, bodies, redirects, compression, timing.
HTTP/2
Class 3Multiplexing, stream reset, GOAWAY — needs a transport-preserving origin.
HTTP/3 / QUIC
Class 3QUIC negotiation and behavior — needs a transport-preserving origin.
WebSocket
PlannedUpgrade, text/binary frames, ping/pong, fragmentation, close codes.
TLS / Certificates
Class 3Versions, ciphers, and deliberate certificate failures — needs a dedicated origin.
DNS
PlannedRecord types and resolution failures — not drivable from a web page.
Connection / Failure
PlannedResets, timeouts at different phases, refusal.
Application protocols
PlannedgRPC / protobuf and other real application protocols.
HTTP semantic tests
Each has a stable id and a fully documented server behavior. Open one, run it with your observer capturing, then classify what you saw.
h1-redirect-301
301 Moved Permanently
Responds 301 with a Location header pointing at a sibling path that itself returns 200 with a short known body. Two transactions on the wire: the redirect, then the followed request.
h1-status-404
404 Not Found
Responds 404 with a short known text body and a deliberately duplicated response header (two X-Lab-Note lines with different values, in this order).
h1-status-500
500 Internal Server Error
Responds 500 with a short known text body and a Retry-After header.
h1-gzip
gzip-compressed response
Responds 200 with Content-Encoding: gzip. The compressed bytes decode to a fixed, known plaintext (shown below verbatim). The Content-Length is the compressed byte count, not the plaintext length.
h1-slow-2400ms
Deliberately slow response (~2.4 s)
Holds the response for ~2400 ms after receiving the request, then responds 200 with a short known body. The delay is a fixed server-side wait, not network variance.
The Lab records what the server did. It does not record, collect, or report what your observer captured — that comparison is yours to make. Nothing you select on a test page is sent anywhere.