On 2026-09-23 09:53:46 +0700, Max Nikulin wrote: > On 22/09/2026 9:48 pm, CGS wrote: > > On 2026-09-22, Max Nikulin wrote: > > > > > > The issue is that nscd caches for an hour results with some IPv6 > > > addresses and no IPv4 ones due to SERVFAIL in response to the A query. > > > As a result various tools can not connect the host due to lack of global > > > IPv6 routing. > > > > “Combining the NSS status of two distinct queries requires some compromise…” > > > > https://codebrowser.dev/glibc/glibc/resolv/nss_dns/dns-host.c.html?utm > > It is worse than I thought. From the same comment: > "Some of the synthesized responses > aren't very well thought out and sometimes appear to imply that > IPv4 responses are always answer 1, and IPv6 responses are always > answer 2, but that's not true... > but certainly needs to be fixed to make this > a more robust implementation." > > > So I guess nscd is innocent, > > In my opinion, it is terrible kind of innocence. The tool may make your more > happy, but it is ready to kick if you are in trouble. > > I would say, it is naive due to libnss design.
Perhaps the libnss design is due to some reason. For instance, the getaddrinfo API with AF_UNSPEC needs a synthesized response, thus may hide failures. This may be fine when the result is not cached. But caches need to be more careful: hidden failures should not be cached. > > because gaih_getanswer() combines address > > records into one list and collapses NSS statuses to a single status > > before returning to nscd. > > I do not expect significant improvement for more accurate status when nscd > is not involved. > > I believe, it should be prominently documented that it is better to disable > host request cache in nscd and to use some tool designed having in mind > complexity related to DNS: systemd-resolved, dnsmasq. Or nscd should be fixed. If the libnss API cannot handle partial failures with AF_UNSPEC, I recall that it is possible to obtain IPv4 and IPv6 addresses separately (with AF_INET and AF_INET6, respectively), thus probably detect failures in a more reliable way. So nscd could do that. -- Vincent Lefèvre <[email protected]> - Web: <https://www.vinc17.net/> 100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/> Work: CR INRIA - computer arithmetic / Pascaline project (LIP, ENS-Lyon)

