# Bug (?) in TCP\_Contents

**URL:** <https://community.zeek.org/t/bug-in-tcp-contents/610>\
**Category:** Zeek\
**Created:** [October 7, 2004, 4:22am UTC](https://community.zeek.org/t/bug-in-tcp-contents/610 "2004-10-07T04:22:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [October 7, 2004, 4:22am UTC](https://community.zeek.org/t/bug-in-tcp-contents/610/1 "2004-10-07T04:22:52Z")

</div>

> When Bro sees an ACK for a packet before the packet  
> itself (packet reordering), it considers that it already  
> delivered the packet to the upper protocols, because  
> it's acked. (see TCP\_Contents.cc, line 272).
> 
> I was wondering whether this is the intended behavior  
> or it's a bug.

Note, that's \*not\* packet reordering in the sense of a network phenomenon.  
Causality requires that acknowledgments come \*after\* the packets they  
acknowledge!

So it's intended behavior. It only becomes a problem in traces for which  
causality is broken. Unfortunately, this can happen due to reading from  
multiple NICs which have large buffers. If this is a problem in your  
environment, you can use packet\_sort\_window to sort the packets based  
on timestamps (assuming your NICs timestamp them correctly - if not,  
then all is lost ...).

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![Igor\_Shabaltas](https://avatars.discourse-cdn.com/v4/letter/i/46a35a/32.png) [@Igor\_Shabaltas](https://community.zeek.org/u/Igor_Shabaltas)\
**Post date:** [October 9, 2004, 8:36am UTC](https://community.zeek.org/t/bug-in-tcp-contents/610/2 "2004-10-09T08:36:44Z")

</div>

Greetings,

bro-pub-0.9a4a$ make  
...  
g++ -I. -I.. -Ilibedit -O -c main.cc  
In file included from PacketFilter.h:9,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;from Sessions.h:29,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;from RuleMatcher.h:12,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;from main.cc:54:  
PrefixTable.h:48: error: struct PrefixTable::iterator redeclared with different  
access  
main.cc: In function `int main(int, char\*\*)':  
main.cc:319: error: array bound forbidden after parenthesized type-id  
main.cc:319: note: try removing the parentheses around the type-id  
\*\*\* Error code 1

bro-pub-0.9a4a$ gcc --version  
gcc (GCC) 3.4.2 [FreeBSD] 20040728

bro-pub-0.9a4a$ uname -v  
FreeBSD 5.3-BETA7 #0: Sat Oct 2 21:01:00 UTC 2004

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/bug-in-tcp-contents/610/3 "2022-05-06T15:37:12Z")

</div>


