Date: Wed, 21 Sep 2005 07:09:43 -0700 From: Brooks Davis <brooks@one-eyed-alien.net> To: "Matthew N. Dodd" <mdodd@FreeBSD.ORG> Cc: arch@FreeBSD.ORG, Doug Barton <dougb@FreeBSD.ORG> Subject: Re: [CFR] reflect resolv.conf update to running application Message-ID: <20050921140943.GB3739@odin.ac.hmc.edu> In-Reply-To: <20050915094948.K79434@sasami.jurai.net> References: <ygefyt4yiaz.wl%ume@mahoroba.org> <20050826202713.X1915@sasami.jurai.net> <20050827014153.GA14720@odin.ac.hmc.edu> <20050826221016.B1915@sasami.jurai.net> <20050827170600.GB14720@odin.ac.hmc.edu> <20050828022351.F63789@sasami.jurai.net> <20050908181052.GH31354@odin.ac.hmc.edu> <20050914091957.P56212@sasami.jurai.net> <43293189.5000200@FreeBSD.org> <20050915094948.K79434@sasami.jurai.net>
next in thread | previous in thread | raw e-mail | index | archive | help
--pvezYHf7grwyp3Bc Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Thu, Sep 15, 2005 at 09:59:48AM -0400, Matthew N. Dodd wrote: > On Thu, 15 Sep 2005, Doug Barton wrote: > >Yes, include works, but it runs a similar risk to modifying the=20 > >named.conf file, namely if the syntax of the the statements in the=20 > >include file are not right, loading named.conf will fail. So, we should= =20 > >build some caution into the process of updating the file, but that's=20 > >easily done with the named-checkconf program that comes with the=20 > >distribution. >=20 > I'm not sure such paranoia is needed; dhclient has always exposed the=20 > system to the risk of having an invalid resolv.conf and regenerating the= =20 > named.conf file is no different. Since we're regenerating the included= =20 > file completely I don't see that this is risky at all. The domain name server values will be valid host names. dhclient checks that so we can count on it. I had broken the search checks, but have since fixed that. It might be useful to still write a resolv.conf that only refers to 127.0.0.1 and includes the search directive if we write the forwarder's file. -- Brooks -- Any statement of the form "X is the one, true Y" is FALSE. PGP fingerprint 655D 519C 26A7 82E7 2529 9BF0 5D8E 8BE9 F238 1AD4 --pvezYHf7grwyp3Bc Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) iD8DBQFDMWmlXY6L6fI4GtQRAqNYAJ4z8cXGL57onEUlzreEzOUHH7md0QCfaUK0 KQz7m2YCNoK/iQhHAEzbW9M= =YJjj -----END PGP SIGNATURE----- --pvezYHf7grwyp3Bc--
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20050921140943.GB3739>