TCP: Treason uncloaked DoS ??

From: Tim Kay (
Date: Fri Apr 19 2002 - 10:15:22 EST

[posted here because the message itself apparantly only appears with debug
stuff on.]

Please forgive my igonorance but our cluster of load balanced web servers
suddenly produced a run of:

TCP: Treason uncloaked! Peer XXX.XXX.XXX.XXX:4968/6666 shrinks window
2154146057:2154152518. Repaired.

lines in our error logs. I have tracked this down to timer.c and I can see
sort of what's going on [ please correct me if I'm wrong but I think a
client is saying 'send me something - ah but not at the moment because I'm
not ready to receive - but don't close the connection']. Question is are
multiple instances of this from multiple IPs a DoS possiblility. I assume
that the connections are kept open if the client connecting doesn't actually
go away so surely lots of these ocurring at once would overload a server. I
have googled this and an occasional instance seems normal and could be down
to a broken client, but lots from different IP addr's at once??

I'm a bit concerned that maybe someone is warming up for a hit or something.



To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to
More majordomo info at
Please read the FAQ at

This archive was generated by hypermail 2b29 : Tue Apr 23 2002 - 22:00:24 EST