On 2026-09-22 10:18:10 +0700, Max Nikulin wrote:
> It seems, resolv.conf(5) was not updated by commits related to the bug
> 27929. From <file:///usr/share/doc/libc6/NEWS.gz>:
> 
> > Version 2.41
> > * The DNS stub resolver now supports the strict-error option.  If
> >   activated, getaddrinfo for the AF_UNSPEC address family (with dual
> >   A/AAAA DNS lookups) attemps to obtain an A/AAAA response pair from
> >   another DNS server if one of the responses indicates failure.  Without
> >   the strict-error option, getaddrinfo returns the A record data it has
> >   obtained even if the AAAA query failed.  The new strict error mode is
> >   incompatible with some DNS environments which do not follow the RFCs,
> >   which is why this mode is not enabled by default.  A future version
> >   of the library may turn it on by default, however.
> 
> It doesn't look better than "no-aaaa" as a workaround.

The opposite of "Without the strict-error option, getaddrinfo returns
the A record data it has obtained even if the AAAA query failed.",
i.e. with A and AAAA reversed, would also be interesting. Perhaps it
does, but since this is undocumented, one does not know. Even if it
does, this is not better than "no-aaaa", because here, both DNS
servers could return SERVFAIL. Note also that this option is not
available on bookworm (libc 2.36).

BTW, I can also see

* In /etc/resolv.conf and the RES_OPTIONS environment variable, option
  flags can now be prefixed with “-” to clear previously set flags.
  For example, if /etc/resolv.conf contains “options no-aaaa”, a
  process running with the RES_OPTIONS=-no-aaaa environment variable
  performs AAAA DNS queries when the glibc DNS stub resolver is used.

However, when nscd is running, RES_OPTIONS has no effect for the end
user (as tested on a trixie machine). I'm wondering whether there is
a way for the end user to skip nscd. This would make sense.

-- 
Vincent Lefèvre <[email protected]> - Web: <https://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / Pascaline project (LIP, ENS-Lyon)

Reply via email to