Skip to main content
WeaveBit

Understanding check results

Understand Normal, Blocked, and Indeterminate results, protocol statuses, GFW Full aggregation, timeouts, and node coverage without overstating conclusions.

Updated

A WeaveBit result describes an observation made with a particular method, node, and time. Normal does not mean that every feature of a website works. An abnormal classification does not identify the organization responsible for a failure. Indeterminate does not mean blocked.

Read three layers separately: task progress, protocol status, and the platform's assessment of the observation.

Task completion and network assessment

A successful API v2 creation response means the batch was accepted. pending, running, and completed describe execution progress. A completed batch can still contain timeouts, node errors, or indeterminate items.

The protocol status identifies an observation such as DNS_RESOLVE_OK, HTTP_HOST_RESET, or TLS_HANDSHAKE_TIMEOUT. GFW scenario checks use result_code and overall_result for assessments. Do not turn one raw status string into a conclusion about the entire domain.

What the three classifications mean

Classification Scenario value Meaning
Normal 0 This observation did not meet the method's defined abnormal conditions
Abnormal shown as Blocked 1 The observation met a defined condition, such as DNS pollution or an HTTP or TLS reset
Indeterminate null Evidence was insufficient because of timeout, a failed prerequisite, an untested stage, or another unclassifiable outcome

Blocked is a platform classification that needs the associated method and evidence. It does not establish unavailability on every network in China or identify a particular filtering system.

A successful DNS Resolve check reports resolution, not the dedicated DNS Pollution assessment. TCP success establishes a connection to the IP and port. A missing ICMP reply may reflect a policy to disable Ping rather than an unavailable application.

HTTP_RESPONSE_OK means a valid HTTP response was received. It need not be HTTP 200, and it does not validate page content, redirect chains, or a business transaction. TLS_HANDSHAKE_OK describes a completed handshake, rather than a complete audit of certificate expiry, hostname matching, and trust. Method definitions.

How a GFW Full result is combined

GFW Full combines DNS Pollution, HTTP Host Reset, and TLS SNI observations. It does not run all seven methods. Review the dimensions and overall_result associated with each node.

Any dimension equal to 1 produces 1. All dimensions equal to 0 produce 0. If none is 1 but at least one is null, the overall value is null. The following examples illustrate the rules; they are not live measurements.

DNS HTTP TLS Overall Interpretation
0 0 0 0 All dimensions were classifiable and did not meet abnormal conditions
0 0 null null TLS evidence is insufficient for an all-normal result
0 1 0 1 An explicit abnormal HTTP condition was observed
1 null null 1 Explicit DNS evidence remains abnormal despite missing evidence elsewhere

For HTTP, HTTP_RESPONSE_OK maps to 0 and HTTP_HOST_RESET to 1. Timeout, EOF, untested stages, and read or write errors map to null. TLS uses TLS_HANDSHAKE_OK and TLS_HANDSHAKE_RESET for these two values; alerts, EOF, and other handshake errors are not automatically classified as blocking.

Responding to Indeterminate

Locate the failed stage. A failed DNS prerequisite can leave later checks untested. An untested TLS handshake is different from a reset during negotiation. Check the target, port, node availability, and origin, then repeat on the affected network and add other observations if necessary.

In the GFW scenario alert rules, null does not count as abnormal and cannot establish recovery. An abnormal round followed by an indeterminate round is not evidence that the service recovered. Keep offline nodes separate from target abnormalities.

Reporting observations across nodes

Report the numbers of normal, abnormal, indeterminate, and missing observations together with the carriers, locations, and time. A large indeterminate count means the observation coverage is limited. Removing those items and presenting only a reassuring success percentage can mislead.

A reset can meet a platform classification rule while its cause still needs investigation. Compare origin logs, other networks, and repeated tests before attributing responsibility.

Use the free DNS check for a single pollution question, follow Getting started to configure scheduled Console observations, or use API v2 to save and analyze results in your own system within the retention window.