Summary
- A cumulative ACK proves progress in TCP sequence space; after retransmission, it does not identify whether the original or later copy caused that progress.
- RFC 1122 and RFC 6298 require Karn's rule: do not take an RTT sample from retransmitted data. After an RTO expires, double the timer and retain that caution until unambiguous evidence arrives.
- Negotiated TCP timestamps can label the acknowledged instance well enough to restore sampling, but they do not prove path, loss cause, identity or wall-clock history.
One answer, two incompatible clocks
Suppose a sender transmits a segment and starts a timer. The timer expires before an ACK returns, so the sender retransmits the same sequence numbers. An ACK then arrives.
The ACK is useful. Under RFC 793, its acknowledgment number says which byte the receiver expects next. It may advance the send window and release retained data. Yet the ACK does not carry the biography of the copy that caused it. The original could have been delayed and arrived just before the retry. Or the original could have vanished and the retry could have succeeded.
Those histories demand opposite measurements. Timing from the first send makes the round trip look long. Timing from the retransmission makes it look short. The same valid ACK cannot decide between them. Delivery evidence has exceeded neither its truth nor its authority; only the sender's proposed inference has exceeded both.
The timer could learn its own mistake
TCP needs a retransmission timeout because paths do not announce a fixed delay. A timer that is too short creates needless copies; one that is too long leaves recoverable loss idle. The sender therefore estimates round-trip time from observed sends and acknowledgments.
The original TCP specification supplied a smoothed estimate, but retransmission created a feedback trap. If an ambiguous ACK is treated as a quick answer to the retry, the estimated RTT may fall. The next timeout fires even sooner, creating more retransmissions and more ambiguous samples. If it is always attributed to the original, the estimate can instead become unnecessarily slow. Either policy converts an unknown cause into a confident number.
The error is epistemic before it is arithmetic. A better averaging formula cannot repair a mislabeled observation.
Karn made refusal part of correctness
RFC 1122 made two different corrections mandatory. A host TCP must implement Jacobson's variance-aware RTO calculation, and it must implement Karn's selection rule so ambiguous round trips do not corrupt that calculation.
Karn's rule is austere: when a segment has been retransmitted, do not derive an RTT sample from its ACK. RFC 6298 preserves the rule as a MUST NOT. The sender may still accept the ACK for sequence progress. It withholds only the timing claim.
This separation matters. Rejecting a sample is not rejecting a packet, accusing the receiver or declaring the path broken. It is a local statement that the observation lacks the causal label required by one estimator.
Backoff carried uncertainty forward
Silence after a timeout is itself consequential. RFC 1122 requires exponential backoff for successive RTO values for the same segment. The procedure later standardized in RFC 2988 and retained by RFC 6298 says that when the timer expires, retransmit the earliest unacknowledged segment and set RTO <- RTO * 2.
The doubling prevents a sender from answering repeated uncertainty with increasing aggression. More importantly, the backed-off value must not be erased by the ambiguous ACK that follows. Once new data is sent and acknowledged without retransmission, a valid sample can run through the normal estimator and bring the RTO down again.
Backoff is therefore revisable restraint, not a permanent penalty. It preserves caution until evidence becomes attributable.
A timestamp supplied the missing label
TCP later acquired a bounded exception. RFC 7323 defines the Timestamp option's TSval and echoed TSecr. When the option has been negotiated and the returned value identifies the relevant transmitted instance, RFC 6298 permits sampling retransmitted data because the ambiguity has been removed.
The exception is narrower than its name suggests. A timestamp is not a civil-time certificate. It does not authenticate the peer, reveal the route, measure one-way delay or prove why a packet was lost. It provides connection-local evidence that can associate an ACK with a particular timestamped send.
RFC 7323 adds another boundary: an echoed timestamp may update the averaged RTT only when the segment advances the left edge of the send window. An echo that accompanies no new acknowledgment progress does not automatically become a timing sample.
More observations could shorten memory
Timestamps make many more RTT measurements possible. That looks unambiguously beneficial, but RFC 7323 warns that the RFC 6298 estimator's weights assumed roughly one sample per RTT. Feeding it a sample for every packet can make old path conditions disappear from the estimate too quickly. A path that varies over several round trips may then produce more spurious retransmissions.
The implementation should preserve the intended history of the estimator when several samples are available. Precision is not merely sample count. The rate at which observations enter a model determines what past the model can still remember.
This is the second refusal in the design. First, exclude a sample whose cause is unknown. Then, even among labeled samples, resist letting abundance impersonate independent information.
The ACK kept its proper authority
An ACK remains powerful. It advances SND.UNA, retires stored bytes and drives sender state. But it does not prove which physical copy arrived, where delay accumulated, whether loss was congestion, or whether a receiver told the truth.
Karn's lasting contribution was not merely a timer trick. It was a discipline for shared systems: let evidence perform the action it supports, and no more. TCP could trust an ACK for delivery progress while distrusting it for elapsed-time attribution. The sender retained local control of its model without asking the network for a central clock or an explanation it could not provide.
Sources and limits
The closed source set is RFC 793, RFC 1122, RFC 2988, RFC 6298 and RFC 7323. These specifications establish semantics and normative rules, not current implementation prevalence, platform defaults or the cause of a live timeout. An ambiguous sample may have matched reality by accident; Karn's rule says the sender cannot know which interpretation was valid.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
