On all four machines and owned by none. The module declares the package and the daemon. It leaves nsswitch.conf and nss-mdns as found — the hosts: line is one list every name source shares, and the host writes blocks, not line members — and opens nothing: the mesh's filter drops inbound UDP 5353 on every machine and `listens` has no local-link scope. avahi_status, _browse, _resolve and _services report both (to-be 42 Phase 1).
43 lines
2.3 KiB
Markdown
43 lines
2.3 KiB
Markdown
# avahi
|
|
|
|
The local network's name and service discovery (mDNS/DNS-SD) as a module (novox/hq to-be 42 Phase 1,
|
|
research 027).
|
|
|
|
## What it owns
|
|
|
|
- The `avahi` package.
|
|
- `avahi-daemon.service`, running and enabled.
|
|
|
|
## What it improves
|
|
|
|
It was on all four machines and owned by none. It is now declared, and its tools show why discovery
|
|
does not work today:
|
|
|
|
- **The packet filter drops mDNS.** The mesh's filter has no rule for inbound UDP 5353 on any of the
|
|
four machines, so avahi announces this machine but hears no other machine's answers. A browse
|
|
finds nothing, and resolving even the machine's own `.local` name times out. A module's `listens`
|
|
can reach the private network, this machine or anywhere, but not the local link. Opening the port
|
|
to anywhere would answer the internet on a public machine, so the module opens nothing. This needs
|
|
a decision in novox/hq: a local-link source scope for `listens`. Until then, `avahi_status` reports
|
|
`inbound_mdns_accepted: false`, and browse and resolve say so whenever they hear nothing.
|
|
|
|
## What it leaves found
|
|
|
|
- **`nss-mdns` and `/etc/nsswitch.conf`.** An ordinary lookup reaches avahi only through the
|
|
`hosts:` line. That line is one ordered list shared by every name source: containers, files, DNS,
|
|
mDNS and the resolver daemon. The host can write a marked block into a file, but it cannot add a
|
|
member to a line. Owning the whole file would make this module the owner of every machine's name
|
|
resolution. On 2026-10-04 all four machines had the same file, with `mdns4_minimal` wired by hand
|
|
and nss-mdns installed. Both are left as found, and `avahi_status` reports the wiring.
|
|
- `/etc/avahi/avahi-daemon.conf`, including each workstation's hand-set `allow-interfaces`, which
|
|
names that machine's own network interface.
|
|
|
|
## Tools
|
|
|
|
| tool | | answers |
|
|
|---|---|---|
|
|
| `avahi_status` | r | the daemon, its version and configuration, the `hosts:` line and whether mdns is on it, nss-mdns, whether the filter accepts inbound 5353, systemd-resolved beside it, and notes |
|
|
| `avahi_browse` | r | every service announced in a few seconds (`avahi-browse -prt`), resolved where possible, narrowed to a type |
|
|
| `avahi_resolve` | r | a `.local` name through avahi and through the name service side by side, or an address to its name |
|
|
| `avahi_services` | r | what this machine publishes from `/etc/avahi/services` |
|