On Thu, Sep 24, 2026 at 09:55:07AM +0700, Max Nikulin wrote: > On 23/09/2026 5:04 pm, Vincent Lefevre wrote: > > On 2026-09-23 09:53:46 +0700, Max Nikulin wrote: > > > I believe, it should be prominently documented that it is better to > > > disable > > > host request cache in nscd and to use some tool designed having in mind > > > complexity related to DNS: systemd-resolved, dnsmasq. > > > > Or nscd should be fixed. If the libnss API cannot handle partial > > failures with AF_UNSPEC, I recall that it is possible to obtain > > IPv4 and IPv6 addresses separately (with AF_INET and AF_INET6, > > respectively), thus probably detect failures in a more reliable > > way. So nscd could do that. > > Are there Name Services (notice: not *DNS*, but in broad sense here) other > than "host" (that usually includes DNS among other means for hostname > resolution) where partial failures are possible?
I don't know whether this https://ldap.com/ldap-result-code-reference-core-ldapv3-result-codes/#rc-referral counts as "partial failure", but if it does, then the answer would be "yes, LDAP". (LDAP has almost everything: never trust a protocol carrying "lightweight" in its name ;-) Cheers -- t
signature.asc
Description: PGP signature

