Concept and mechanism
TCP states describe protocol phases. CLOSE_WAIT means remote FIN was received and local close remains when appropriate. Many persistent entries justify observing how the application handles end-of-stream, resources, and dependencies. TIME_WAIT has a normal closing function; its count alone does not prove a leak. Compare connection rate, duration, errors, and limits before changing timers. On established sockets, received unread data can grow when the consumer is slow. Do not automatically apply that interpretation to LISTEN socket queues, where context differs. Successive observations distinguish a transient queue from sustained pressure.
Guided application
Flow control protects capacity advertised by the receiver. A zero window limits normal new-data sending; probes allow tracking reopening. This does not itself prove congestion or packet loss. Congestion control is a separate limit related to pressure on the path; a large receive window does not remove it. In the fictional case, the receive queue grows while threads wait on a dependency. Correlate that wait with read rate before increasing buffers. More memory can merely delay saturation. A bounded mitigation can reduce new arrivals while recovering the consumer, with data controls and criteria for returning to normal.
CLOSE_WAIT points to pending local close; zero window points to advertised receive capacity.
Common pitfalls
Every state as a leak; LISTEN queue as unread bytes; zero window as loss; tuning before measurement.
Related topics: Addresses, prefixes, and scope · Routes and next-hop resolution · Transport, acknowledgement, and messages
Use state, trend, and consumption to locate the limitation.
Reference: Linux TCP sockets and receive queue · DR TCP/IP 2026-09; TCP RFC 9293; IPv6 RFC 8200 with RFC 9673 update; Linux socket and iproute2 guidance