Agent thread message 010 revealed critical update: conntrack fix didn't resolve the production blocker. ### What Actually Happened: Host physical NIC pcap (tcpdump -i enp1s0) showed ZERO ACK packets arriving at docker-2. The loss is upstream in carrier infrastructure (ClearFly ↔ Twilio seam), not at the conntrack layer. ### Documentation Updates: - Added prominent warning box at top of case study - Updated verification section to emphasize host-NIC pcap FIRST - Clarified that conntrack + ACK fast-path are defense-in-depth, not fixes ### Key Lesson: Same symptom (Timer H expiry at 64s), different root cause. Container pcaps show what reaches userspace but can't prove what never arrived. Always verify at the physical NIC layer before concluding a lower-layer fix worked. ### Still Valuable: - Conntrack 30→120s: prevents future UDP timeout issues - ACK fast-path: architecturally correct, prevents security pipeline drops - Case study: documents real failure mode worth knowing about The diagnostic convergence was sound; the actual blocker was one layer further up the stack. See: docs/agent-threads/ack-loss-from-twilio-trunk/010-* |
||
|---|---|---|
| .. | ||
| ack-loss-from-twilio-trunk | ||
| PROTOCOL.md | ||