Skip to content

Archive

Networking

79 articles
Tech 23 Sep 2026 5 min read

TCP Keepalive Probes Detect Silent Dead Peers

An established TCP connection can remain quiet for a long time. Silence alone does not mean either endpoint has failed: an application may simply have no data to exchange. That property is useful for long-lived sessions, but it also creates an operational problem when a peer disappears without sending FIN or RST. A machine can lose power, a network path can fail, or state in an intermediate device can vanish. The surviving endpoint may retain a socket that still appears established because no packet has arrived to prove otherwise. TCP keepalive provides an optional mechanism for testing such idle connections.

Tech 23 Sep 2026 7 min read

epoll Readiness Modes Change How Event Loops Drain File Descriptors

Linux epoll lets one thread wait on readiness changes across many file descriptors without scanning every descriptor on each iteration. The interface is common in network servers, proxies, runtimes, and other programs that keep large sets of sockets active. The registration mode matters. Level-triggered operation keeps reporting a descriptor while the relevant condition remains ready. Edge-triggered operation reports transitions in readiness and expects the application to consume available work until the descriptor would block.

Tech 22 Sep 2026 6 min read

TCP TIME_WAIT Keeps Closed Connections Distinct from Delayed Segments

A TCP connection can finish exchanging application data and still leave a socket record behind. The familiar TIME_WAIT state is part of TCP’s close machinery, not evidence that a process forgot to close a descriptor. The endpoint that performs the active close commonly enters TIME_WAIT after the closing handshake. It keeps enough state for a bounded interval so late segments from the old connection cannot be confused with traffic from a later connection using the same endpoint identity.

Tech 22 Sep 2026 6 min read

Linux TCP Receive Autotuning Expands Buffer Capacity with Flow Demand

A TCP receiver can accept data only while it has room to hold bytes that the application has not consumed. On Linux, that capacity does not have to remain fixed at the small amount available when a connection starts. Receive autotuning can enlarge the socket’s receive buffer as the connection develops, subject to system limits and the state of the flow. That behavior matters most when a connection carries sustained traffic across a path with a sizable bandwidth-delay product. A receiver with too little usable window can constrain the sender even when the network and sender could carry more data. Extra receive capacity gives TCP room to keep data in flight while the application drains the socket.

Linux 21 Sep 2026 6 min read

io_uring Multishot Accept Keeps One Accept Request Active

A normal accept request has a one-to-one shape: one submitted operation eventually yields one completion. io_uring multishot accept changes that relationship. A single accept SQE can remain active across multiple incoming connections and emit a separate completion queue entry for each accepted socket. The request is persistent, but not permanent. Each CQE carries enough state for the application to tell whether the original request can produce another completion. That boundary matters because a server that treats every successful CQE as proof that accept is still armed can silently stop accepting after the multishot request terminates.

Tech 19 Sep 2026 5 min read

NIC Interrupt Moderation Trades Wakeup Rate for Packet Latency

A network adapter does not need to interrupt a CPU for every received packet or completed transmission. Many NICs can hold interrupt delivery briefly and report several completion events together. This interrupt moderation reduces interrupt traffic and CPU entry overhead, but it can also delay the moment software notices newly completed work. The mechanism sits between packet DMA and the driver’s receive or transmit processing. It changes notification timing; it does not change the packet’s wire format, Ethernet ordering rules, or the basic requirement that the driver eventually process completed descriptors.

Software Engineering 19 Sep 2026 8 min read

MQTT and QUIC Solve Different Parts of a Chat Transport

MQTT and QUIC Solve Different Parts of a Chat Transport MQTT and QUIC are often placed in the same comparison table when discussing real-time chat. That comparison is convenient, but it collapses two different protocol layers into one choice. MQTT is an application-layer messaging protocol. It defines concepts such as clients, brokers, topics, subscriptions, retained messages, session state, and delivery quality of service. QUIC is a secure transport protocol over UDP. It provides connections, streams, flow control, loss recovery, encryption, and connection migration mechanisms.

Linux 19 Sep 2026 5 min read

io_uring Multishot Requests Persist Across Completion Events

A normal io_uring request has a simple lifetime: userspace submits one SQE and eventually receives one CQE. Multishot operations change that relationship. One submitted request can remain active in the kernel and produce several completion queue entries as matching events occur. That persistence changes completion handling from a one-CQE-per-request assumption into an explicit lifecycle protocol. The decisive state is carried by IORING_CQE_F_MORE: when the flag is present, the originating request can produce another completion; when it is absent, that multishot request has terminated.

Software Engineering 18 Sep 2026 5 min read

SO_REUSEPORT Moves Listener Distribution into Socket Selection

SO_REUSEPORT permits multiple Linux AF_INET or AF_INET6 sockets to bind the same local address and port when every member satisfies the reuse-port rules. For TCP listeners, this moves incoming connection distribution ahead of accept(): the kernel selects a listener from the reuse-port group, and that listener receives the connection on its accept queue. For UDP, selection determines which socket receives an incoming datagram. This is a different concurrency boundary from several threads sharing one listening file description. Each reuse-port member is a distinct socket, with its own descriptor, queues, polling state, and lifecycle.

Linux 17 Sep 2026 5 min read

TCP_NODELAY Disables Nagle Coalescing on a Socket

A TCP socket can hold a small write instead of transmitting it immediately when earlier data remains unacknowledged. This behavior comes from Nagle coalescing: it limits the stream of small TCP segments by allowing outstanding data to influence transmission of newly queued bytes. On Linux, setting TCP_NODELAY disables that coalescing rule for the socket. Small writes become eligible for prompt transmission, subject to the rest of the TCP stack, congestion control, flow control, queue state, and device scheduling.

Software Engineering 17 Sep 2026 4 min read

SO_REUSEPORT Forms Kernel-Selected Socket Groups

Multiple Linux sockets can bind the same local address when every participating socket enables SO_REUSEPORT before bind(). Incoming traffic is then assigned to a member of the resulting reuseport group rather than delivered to every socket. The shared address is therefore a kernel selection boundary, not a broadcast endpoint. This behavior supports independent receive or accept loops without forcing all work through one listening descriptor. It also creates a distinct operational property: group membership and the selection policy determine which socket receives a packet or connection.

Linux 17 Sep 2026 6 min read

SO_REUSEPORT Distributes Traffic Across Socket Groups

SO_REUSEPORT changes a local endpoint from a single-socket binding into a socket group. On Linux, multiple TCP or UDP sockets can bind the same local address when every participating socket enables the option before bind() and the bind credentials satisfy the kernel’s reuse rules. That behavior is distinct from merely relaxing address-conflict checks. Incoming traffic must also be assigned to one member of the group. The resulting selection boundary affects listener architecture, queue isolation, process restarts, UDP flow placement, and any design that assumes a port maps to exactly one socket.

Linux 17 Sep 2026 4 min read

SO_RCVLOWAT Raises the Readability Threshold for Linux Sockets

A Linux socket with SO_RCVLOWAT set above one byte can have data queued while poll(), select(), or epoll still reports no normal readable readiness. Since Linux 2.6.28, those readiness interfaces respect the configured receive low-water mark. The option changes the threshold associated with normal receive readiness. It does not define message boundaries, reserve receive-buffer space, or guarantee that a later receive operation returns exactly the configured number of bytes. Readability can require more than one queued byte Socket receive readiness is usually observed with the default low-water mark of one byte. In that state, ordinary queued data is enough to satisfy the data-volume part of the readable condition.

Tech 17 Sep 2026 6 min read

NIC Interrupt Coalescing Trades CPU Overhead for Packet Latency

A network interface can receive packets faster than a CPU should service one hardware interrupt per packet. Interrupt coalescing addresses that mismatch by allowing the adapter to group completion notifications and interrupt the CPU less often. The tradeoff is explicit. Fewer interrupts reduce interrupt handling and scheduling pressure, but a packet may wait longer before software is told that receive work is ready. The best setting depends on packet rate, latency targets, CPU capacity, and the adapter’s coalescing controls.

Software Engineering 17 Sep 2026 4 min read

io_uring Multishot Accept Keeps One Request Active Across Connections

A Linux io_uring multishot accept request can produce several completion queue entries from one submission queue entry. The kernel keeps the accept operation active after a successful completion when the CQE carries IORING_CQE_F_MORE, so a server does not need to submit a fresh accept SQE for every connection. This changes the lifetime contract between submission and completion. A normal oneshot request is finished after its CQE. A multishot accept can remain in flight across many accepted connections, and the CQE flags determine whether that request still exists.

Tech 16 Sep 2026 6 min read

TCP Window Scaling Expands the Receive Window for Fast Long Paths

TCP flow control limits how much data a sender may have outstanding according to the receiving endpoint’s available buffer space. The receiver advertises that limit in the TCP Window field so the sender does not deliver data faster than the receiving stack can accept it. The Window field in the TCP header is 16 bits wide. Without an extension, its largest value is 65,535 bytes. That ceiling can be too small on a path that carries data quickly but has a substantial round-trip time.

Tech 16 Sep 2026 6 min read

TCP TIME-WAIT Preserves Closed Connection State

A TCP endpoint can finish an application’s close operation while the protocol still retains state for that connection. After an active close completes its FIN exchange, the endpoint normally enters TIME-WAIT instead of discarding the connection record immediately. That retained state has two jobs. It leaves the endpoint able to acknowledge a retransmitted final FIN, and it separates a closed connection from a later incarnation that could use the same local and remote addresses and ports.

Software Engineering 16 Sep 2026 5 min read

TCP TIME-WAIT Delays Four-Tuple Reuse

A TCP endpoint that performs the active close can keep the closed connection in TIME-WAIT after the final ACK has been sent. The application-visible stream is finished, yet the transport retains state for a bounded interval before permitting unrestricted reuse of the same connection identity. That retention is not leftover application state. It protects the protocol boundary between one connection incarnation and a later connection that could otherwise use the same source address, source port, destination address, and destination port.

Tech 16 Sep 2026 6 min read

TCP Keepalive Probes Test Idle Connections

A TCP connection can remain established while carrying no application data. That is valid behavior: an open connection does not need a continuous stream of packets to remain a TCP connection. Silence creates a practical problem when one endpoint disappears without completing the normal close sequence. A machine can lose power, a network path can fail, or state in an intermediate device can vanish. If the surviving endpoint has no data to send, ordinary retransmission logic has nothing to act on.

Tech 16 Sep 2026 3 min read

Receive Side Scaling Distributes Network Flows Across CPU Queues

Receive Side Scaling Distributes Network Flows Across CPU Queues A fast network adapter can receive packets faster than one processor core can handle them efficiently. Receive Side Scaling, commonly abbreviated RSS, spreads incoming traffic across multiple hardware receive queues. Each queue can be associated with a different processor, allowing packet processing to run in parallel. RSS usually assigns packets by flow rather than distributing every packet independently. This preserves useful ordering properties while still spreading many simultaneous connections across available queues.

Tech 16 Sep 2026 4 min read

Path MTU Discovery Finds Packet Size Limits

Every network link has a maximum transmission unit, or MTU, that limits the size of an IP packet carried in one link-layer frame. A route can cross links with different limits, so the smallest relevant MTU along that route constrains packet size end to end. Path MTU Discovery, commonly shortened to PMTUD, lets an endpoint find that constraint and adjust packet sizes rather than relying on fragmentation. One route can contain several MTU limits Ethernet commonly uses an IP MTU of 1500 bytes, but tunnels, VPNs, encapsulation, and other link types can reduce the usable size. A packet that fits the sender’s local interface can therefore be too large for a later hop.

Tech 16 Sep 2026 5 min read

Network Interrupt Coalescing Batches Packets Before CPU Notification

A network interface can receive packets much faster than a CPU should be interrupted for each individual arrival. At high packet rates, one hardware interrupt per packet would consume substantial processor time in interrupt entry, scheduling, driver work, and return paths. Interrupt coalescing changes that pattern. The adapter waits for a small interval, a packet count, or another implementation-specific threshold before notifying the CPU. Several packet arrivals can then be handled from one notification.

Tech 16 Sep 2026 5 min read

Network Interrupt Coalescing Batches Packet Notifications

A network interface can receive packets far faster than a processor should handle individual hardware interrupts. If every packet immediately triggered an interrupt, high packet rates could consume substantial CPU time in interrupt handling and context transitions. Interrupt coalescing changes that pattern. The network adapter waits for several packets, a short timer, or another configured threshold before notifying the CPU. One interrupt can then cover multiple received packets. The tradeoff is direct: fewer interrupts reduce per-packet CPU overhead, while waiting to form a batch can add latency.

Tech 16 Sep 2026 5 min read

Nagle Algorithm Batches Small TCP Writes

TCP applications can issue writes much smaller than the network’s maximum segment size. Sending every tiny write as a separate segment can consume disproportionate header and processing overhead. The Nagle algorithm limits that pattern by allowing one small segment to remain in flight while later small writes wait for an acknowledgment or enough queued data to form a larger segment. This behavior reduces streams of tiny TCP segments. It can also add latency when an application expects each small write to leave immediately.