# avahi The local network's name and service discovery (mDNS/DNS-SD) as a module (novox/hq to-be 42 Phase 1, research 027). ## What it owns - The `avahi` package. - `avahi-daemon.service`, running and enabled. ## What it improves It was on all four machines and owned by none. It is now declared, and its tools show why discovery does not work today: - **The packet filter drops mDNS.** The mesh's filter has no rule for inbound UDP 5353 on any of the four machines, so avahi announces this machine but hears no other machine's answers. A browse finds nothing, and resolving even the machine's own `.local` name times out. A module's `listens` can reach the private network, this machine or anywhere, but not the local link. Opening the port to anywhere would answer the internet on a public machine, so the module opens nothing. This needs a decision in novox/hq: a local-link source scope for `listens`. Until then, `avahi_status` reports `inbound_mdns_accepted: false`, and browse and resolve say so whenever they hear nothing. ## What it leaves found - **`nss-mdns` and `/etc/nsswitch.conf`.** An ordinary lookup reaches avahi only through the `hosts:` line. That line is one ordered list shared by every name source: containers, files, DNS, mDNS and the resolver daemon. The host can write a marked block into a file, but it cannot add a member to a line. Owning the whole file would make this module the owner of every machine's name resolution. On 2026-10-04 all four machines had the same file, with `mdns4_minimal` wired by hand and nss-mdns installed. Both are left as found, and `avahi_status` reports the wiring. - `/etc/avahi/avahi-daemon.conf`, including each workstation's hand-set `allow-interfaces`, which names that machine's own network interface. ## Tools | tool | | answers | |---|---|---| | `avahi_status` | r | the daemon, its version and configuration, the `hosts:` line and whether mdns is on it, nss-mdns, whether the filter accepts inbound 5353, systemd-resolved beside it, and notes | | `avahi_browse` | r | every service announced in a few seconds (`avahi-browse -prt`), resolved where possible, narrowed to a type | | `avahi_resolve` | r | a `.local` name through avahi and through the name service side by side, or an address to its name | | `avahi_services` | r | what this machine publishes from `/etc/avahi/services` |