On 22/09/2026 8:33 pm, Marco Moock wrote:
Am 22.09.26 um 05:30 schrieb Max Nikulin:
The issue is that nscd caches for an hour results with some IPv6
addresses and no IPv4 ones due to SERVFAIL in response to the A query.
As a result various tools can not connect the host due to lack of
global IPv6 routing.
Not an IPv6 issue and not an nscd issue.
Working IPv6 routing makes the issue hardly noticeable. In this case
tools are able to connect to host using successfully obtained IPv6
address. Absent IPv4 address is not critical.
Without nscd, it is single time failure that does not last for an hour.
There is a good chance that next try will be successful.
So the issue is result of interference of several factors.
The failing DNS servers need to be handled at libnss_dns.
Do you have an idea what specifically may be fixed in libnss_dns? I
expect that even libnss_resolve (with its own caching daemon) may cause
similar issues when (despite it is strange) nscd is running if front of
it. Any resolver may receive SERVFAIL.
There is some room for improvement in glibc to make combined query
status more symmetrical, but it would have marginal effect on nscd.
nscd is just the cache - I do not see why that is the issue here,
especially in this buggy environment with uncooperative people unwilling
to fix serious network issues.
The world is imperfect. When possible, errors should be handled gracefully.