On 2026-09-23 09:53:46 +0700, Max Nikulin wrote:
> On 22/09/2026 9:48 pm, CGS wrote:
> > On 2026-09-22, Max Nikulin wrote:
> > > 
> > > The issue is that nscd caches for an hour results with some IPv6
> > > addresses and no IPv4 ones due to SERVFAIL in response to the A query.
> > > As a result various tools can not connect the host due to lack of global
> > > IPv6 routing.
> > 
> > “Combining the NSS status of two distinct queries requires some compromise…”
> > 
> > https://codebrowser.dev/glibc/glibc/resolv/nss_dns/dns-host.c.html?utm
> 
> It is worse than I thought. From the same comment:
> "Some of the synthesized responses
> aren't very well thought out and sometimes appear to imply that
> IPv4 responses are always answer 1, and IPv6 responses are always
> answer 2, but that's not true...
> but certainly needs to be fixed to make this
> a more robust implementation."
> 
> > So I guess nscd is innocent,
> 
> In my opinion, it is terrible kind of innocence. The tool may make your more
> happy, but it is ready to kick if you are in trouble.
> 
> I would say, it is naive due to libnss design.

Perhaps the libnss design is due to some reason. For instance,
the getaddrinfo API with AF_UNSPEC needs a synthesized response,
thus may hide failures. This may be fine when the result is not
cached. But caches need to be more careful: hidden failures
should not be cached.

> > because gaih_getanswer() combines address
> > records into one list and collapses NSS statuses to a single status
> > before returning to nscd.
> 
> I do not expect significant improvement for more accurate status when nscd
> is not involved.
> 
> I believe, it should be prominently documented that it is better to disable
> host request cache in nscd and to use some tool designed having in mind
> complexity related to DNS: systemd-resolved, dnsmasq.

Or nscd should be fixed. If the libnss API cannot handle partial
failures with AF_UNSPEC, I recall that it is possible to obtain
IPv4 and IPv6 addresses separately (with AF_INET and AF_INET6,
respectively), thus probably detect failures in a more reliable
way. So nscd could do that.

-- 
Vincent Lefèvre <[email protected]> - Web: <https://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / Pascaline project (LIP, ENS-Lyon)

Reply via email to