On Thu, Sep 24, 2026 at 1:11 AM Max Nikulin <[email protected]> wrote:
>
> On 23/09/2026 5:04 pm, Vincent Lefevre wrote:
> > On 2026-09-23 09:53:46 +0700, Max Nikulin wrote:
> >> I believe, it should be prominently documented that it is better to disable
> >> host request cache in nscd and to use some tool designed having in mind
> >> complexity related to DNS: systemd-resolved, dnsmasq.
> >
> > Or nscd should be fixed. If the libnss API cannot handle partial
> > failures with AF_UNSPEC, I recall that it is possible to obtain
> > IPv4 and IPv6 addresses separately (with AF_INET and AF_INET6,
> > respectively), thus probably detect failures in a more reliable
> > way. So nscd could do that.
>
> Are there Name Services (notice: not *DNS*, but in broad sense here)
> other than "host" (that usually includes DNS among other means for
> hostname resolution) where partial failures are possible?

There are other name services, like WIndows Internet Name Service
(WINS) used in older versions of Microsoft for NetBIOS names.  And
there's NetBIOS Name Service (NBNS) used on old Token Ring networks.
(The US Social Security Administration had one of the largest Token
Ring networks in the world).

I don't recall how they handle partial failures, however.  It's been
too long ago.

> ... If not then I
> do not see any point in wasting resources for redesigning libnss and for
> rewriting its plugins (including 3rd party and internal ones). I
> believe, it is easier to stop using nscd for the "host" service leaving
> the tool to the scope where it performs reasonably well.
>
> I suspect, nscd has no notion of AF_UNSPEC, AF_INET, AF_INET6 and
> instead it operates on more generic level.

Jeff

Reply via email to