Skip to main content

Network 7

Subnets, chmod, HTTP status codes, curl and redirects

Addressing, permissions and HTTP. The details that decide whether a deployment works, and that are easiest to get wrong under time pressure.

// Tools in this category

// Arithmetic you should not do in your head

Subnet boundaries and permission bits are both places where a plausible-looking answer is often wrong. A /26 gives 62 usable hosts rather than 64, because the network and broadcast addresses cannot be assigned. A directory at 644 will refuse to let anyone enter it, because traversing a directory needs the execute bit. Working the value out in a tool that shows the full breakdown takes seconds and removes a class of outage.

// From curl to code, and back

A great deal of API debugging starts as a curl command copied from documentation or from a browser network tab. Turning that into the equivalent fetch, axios, Python requests or Go snippet by hand is tedious and easy to get wrong, particularly around header casing, body encoding and authentication. Converting it mechanically keeps the request identical, which matters when you are trying to work out why the code behaves differently from the command line.

// What to reach for

The Subnet Calculator expands a CIDR block into network address, broadcast address, usable range and host count. The Chmod Calculator turns checkboxes into an octal value, a symbolic string and a ready command. The cURL Converter rewrites a curl command as code in several languages. The HTTP Status Codes reference explains what each code means and what to do about it. The Header Analyzer explains a response and flags weak security settings. The User-Agent Parser identifies browsers and AI crawlers.

// Network: frequently asked questions

Does the subnet calculator handle IPv6?
The current version covers IPv4 CIDR blocks. IPv6 subnetting follows a different set of conventions and is not included.
Why does my converted curl request fail in the browser but work in the terminal?
Almost always CORS. curl ignores it; a browser does not. If the API does not return an Access-Control-Allow-Origin header matching your page, the browser blocks the response even though the request itself is identical. Running the same code in Node.js or on a server avoids the problem.

// Other categories