On 2026-09-21 23:42:34 +0700, Max Nikulin wrote:
> On 21/09/2026 5:06 pm, Marco Moock wrote:
> > It still does not do any DNS lookups, it uses the libraries in listed in
> > nsswitch.conf.
> >
> > If they handle SERVFAIL improperly, it is not nscd's fault.
>
> Marco, are you familiar with related API? Is it possible to mark result as
> partially failed?
>
> Consider the following case:
>
> - libnss_dns sends A and AAAA queries due to AF_UNSPEC argument.
> - The result for AAAA is success with some addresses.
> - "A" fails with some error.
I don't know how name resolving works internally, but if libnss_dns
sends separate queries, then there is a specification issue in case
of partial failure. The getaddrinfo(3) man page says:
getaddrinfo() returns 0 if it succeeds, or one of the following
nonzero error codes:
[...]
EAI_AGAIN
The name server returned a temporary failure indication. Try again
later.
[...]
The question is what getaddrinfo() does if it gets an IP address
for AAAA and a temporary failure (SERVFAIL) for A. From the API,
it is not possible to give a partial answer and indicate that
there was a temporary failure at the same time.
This may have an influence on the cache if not implemented properly.
> When cache is not involved, trying IPv6 is the best that the calling
> application can do. So the result is not simple failure. It is rather
> success.
Yes, that's probably why getaddrinfo() should not return a failure
in such a case.
> However this partial result should be cached as negative to retry soon.
If the cache uses the non-cached getaddrinfo() with AF_UNSPEC,
it cannot distinguish a failure from a really negative result.
I would say that it should use AF_INET (AAAA without A) or
AF_INET6 (A without AAAA) to be able to do the distinction.
--
Vincent Lefèvre <[email protected]> - Web: <https://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / Pascaline project (LIP, ENS-Lyon)