On 22/09/2026 9:48 pm, CGS wrote:
On 2026-09-22, Max Nikulin wrote:
The issue is that nscd caches for an hour results with some IPv6
addresses and no IPv4 ones due to SERVFAIL in response to the A query.
As a result various tools can not connect the host due to lack of global
IPv6 routing.
“Combining the NSS status of two distinct queries requires some compromise…”
https://codebrowser.dev/glibc/glibc/resolv/nss_dns/dns-host.c.html?utm
It is worse than I thought. From the same comment:
"Some of the synthesized responses
aren't very well thought out and sometimes appear to imply that
IPv4 responses are always answer 1, and IPv6 responses are always
answer 2, but that's not true...
but certainly needs to be fixed to make this
a more robust implementation."
So I guess nscd is innocent,
In my opinion, it is terrible kind of innocence. The tool may make your
more happy, but it is ready to kick if you are in trouble.
I would say, it is naive due to libnss design.
because gaih_getanswer() combines address
records into one list and collapses NSS statuses to a single status
before returning to nscd.
I do not expect significant improvement for more accurate status when
nscd is not involved.
I believe, it should be prominently documented that it is better to
disable host request cache in nscd and to use some tool designed having
in mind complexity related to DNS: systemd-resolved, dnsmasq.
On 22/09/2026 4:51 pm, Vincent Lefevre wrote:
I don't know how name resolving works internally, but if libnss_dns
sends separate queries, then there is a specification issue in case
of partial failure. The getaddrinfo(3) man page says
I do not see other way than sending A and AAAA requests. Notice that
getaddrinfo is higher level API for specific purpose. There is API for
libnss plugins that works at lower level and it is not only for host
queries. I had hope that it might suit better for partial failures.