On Sat, Sep 26, 2026 at 10:39:42PM +0700, Max Nikulin wrote: > On 25/09/2026 1:01 pm, tomas wrote: > > Yes, LDAP is... particular. But a referral (which might be just a part > > of a response) may point to another server (well, "DSA", in LDAP parlance, > > but it is a sequence of one or more URLs). So a complete answer may be > > composed of bits and pieces gathered over more than one server. > > > > Still no idea whether that "counts" (as I tried to express that above). > > As a person familiar to LDAP, you are in better position to answer.
Uh-oh. I think you're overstimating me: I've wrestled with LDAP here and there, that's all. And never in the libnss context. > Can you > imagine realistic configuration when query in some category/service/database > (alternative words used for the same term in man pages) needs more than one > request to LDAP servers, some request mail fail, and incomplete result still > may be useful? (Similar to failed A DNS request when IPv6 addresses from > AAAA request is enough if IPv6 is fully supported on the machine.) Have a > look into getent(1) or nsswitch.conf(5) for inspiration. > > An example may be added to Vincent's bug to show that impact is not limited > to "hosts". Tough question: for that one would have to understand what libnss_ldap does and whether incomplete (in the LDAP sense) replies are relevant to it. For me, that's far beyond the "one afternoon project" :-) Cheers and thanks for your insights. -- tomás
signature.asc
Description: PGP signature

