nsswitch.conf - db service for hosts

Carlos O'Donell carlos@redhat.com
Fri Jul 29 16:23:16 GMT 2022


On 7/24/22 12:56, Peter Polgar via Libc-help wrote:
> Thanks! Now it's clear to me.
> 
> Then any idea on how to achieve a static fallback for IP if DNS fails?
> My idea was to have it likes this:
> hosts:   files mdns dns db

The only solutions I know about involve a local DNS server that can be tried as a last
resort which provides the fallback resolution.

> So files and mdns can handle localhost and .local first then if dns fails
> db can have a record for the host in question. Without db this apparently
> won't work.

NSS was not designed to be used in this way.

Each service provider should be fully authoritative for the service it provides,
with files being the exception that generally goes first or last, depending on
the use case (MERGE is useful there too).

A solution along the lines of remembering the last result [1][2] and using that
result if everything else fails was discussed, but this kind of design change
has additional complexity that we don't want to accept unless it really
can't be solved in another way.

What you might use is a "fallback" NSS module that does what you want and is 
placed at the end of the list. I know that Alt Linux (CC'ing Dmitry) has a
libnss_fallback module, but I don't know if it meets your requirements.

Good luck.

-- 
Cheers,
Carlos.

[1] https://developers.redhat.com/blog/2018/11/26/etc-nsswitch-conf-non-complexity
[2] https://bugzilla.redhat.com/show_bug.cgi?id=1374228



More information about the Libc-help mailing list