On 2026-09-22 10:11:07 +0700, Max Nikulin wrote: > On 22/09/2026 1:22 am, Marco Moock wrote: > > Am 21.09.26 um 19:00 schrieb Max Nikulin: > > > On 21/09/2026 5:06 pm, Marco Moock wrote: > > > > It still does not do any DNS lookups, it uses the libraries in > > > > listed in nsswitch.conf. > > > > > > > > If they handle SERVFAIL improperly, it is not nscd's fault. > [...] > > > Consider the following case: > > > > > > - libnss_dns sends A and AAAA queries due to AF_UNSPEC argument. > > > - The result for AAAA is success with some addresses. > > > - "A" fails with some error. > > > > > > When cache is not involved, trying IPv6 is the best that the calling > > > application can do. So the result is not simple failure. It is > > > rather success. > > > > libnss_resolve will try the servers listed in /etc/resolve and stops > > when it gets an answer (IIRC positive or negative DNS answer, not > > failure). The timeouts can be configured and there is also an option for > > round-robin. > > I admit, I was not precise trying to generalize SERVFAIL to timeouts. Let's > consider just SERVFAIL. Vincent wrote that negative DNS answer is immediate > (I hope, it is not too far from reality),
Yes, at my lab, it is immediate (at home, I also tried "dig" when my FTTH connection was temporarily interrupted, but I got timeouts, not SERVFAIL). > so there is no reason to try other DNS servers. I don't see why. In /etc/resolv.conf, it is possible to have a buggy DNS server and a good one (until a few weeks ago, the machines at my lab had at least 2 buggy DNS servers and 1 good one, though I do not know which one came first). -- Vincent Lefèvre <[email protected]> - Web: <https://www.vinc17.net/> 100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/> Work: CR INRIA - computer arithmetic / Pascaline project (LIP, ENS-Lyon)

