On 2026-09-22 10:11:07 +0700, Max Nikulin wrote:
> On 22/09/2026 1:22 am, Marco Moock wrote:
> > Am 21.09.26 um 19:00 schrieb Max Nikulin:
> > > On 21/09/2026 5:06 pm, Marco Moock wrote:
> > > > It still does not do any DNS lookups, it uses the libraries in
> > > > listed in nsswitch.conf.
> > > > 
> > > > If they handle SERVFAIL improperly, it is not nscd's fault.
> [...]
> > > Consider the following case:
> > > 
> > > - libnss_dns sends A and AAAA queries due to AF_UNSPEC argument.
> > > - The result for AAAA is success with some addresses.
> > > - "A" fails with some error.
> > > 
> > > When cache is not involved, trying IPv6 is the best that the calling
> > > application can do. So the result is not simple failure. It is
> > > rather success.
> > 
> > libnss_resolve will try the servers listed in /etc/resolve and stops
> > when it gets an answer (IIRC positive or negative DNS answer, not
> > failure). The timeouts can be configured and there is also an option for
> > round-robin.
> 
> I admit, I was not precise trying to generalize SERVFAIL to timeouts. Let's
> consider just SERVFAIL. Vincent wrote that negative DNS answer is immediate
> (I hope, it is not too far from reality),

Yes, at my lab, it is immediate (at home, I also tried "dig" when
my FTTH connection was temporarily interrupted, but I got timeouts,
not SERVFAIL).

> so there is no reason to try other DNS servers.

I don't see why. In /etc/resolv.conf, it is possible to have a buggy
DNS server and a good one (until a few weeks ago, the machines at my
lab had at least 2 buggy DNS servers and 1 good one, though I do not
know which one came first).

-- 
Vincent Lefèvre <[email protected]> - Web: <https://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / Pascaline project (LIP, ENS-Lyon)

Reply via email to