Am 21.09.26 um 19:00 schrieb Max Nikulin:
On 21/09/2026 5:06 pm, Marco Moock wrote:
It still does not do any DNS lookups, it uses the libraries in listed in nsswitch.conf.

If they handle SERVFAIL improperly, it is not nscd's fault.

Marco, are you familiar with related API? Is it possible to mark result as partially failed?

No, I do not have knowledge about the code.

Consider the following case:

- libnss_dns sends A and AAAA queries due to AF_UNSPEC argument.
- The result for AAAA is success with some addresses.
- "A" fails with some error.

When cache is not involved, trying IPv6 is the best that the calling application can do. So the result is not simple failure. It is rather success.

libnss_resolve will try the servers listed in /etc/resolve and stops when it gets an answer (IIRC positive or negative DNS answer, not failure). The timeouts can be configured and there is also an option for round-robin.

However this partial result should be cached as negative to retry soon.

I doubt that this is being done. It does not store if a DNS server is unreachable too, it will try again in the same order and reach timeouts.
systemd-resolve covers that.

I am curious if the resolver plugin may do its job better or it is limitation of the plugin protocol that results are either failures and no addresses are returned or they are pure successes.

That needs to be tested - in a controlled environment with tests and settings documented.

--
Gruß
Marco

Spam bitte an [email protected]

Reply via email to