From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
From: Yuri Nesterov <yuriy.nesterov@unikie.com>
Date: Wed, 21 Jun 2023 17:17:38 +0300
Subject: [PATCH] timesyncd: disable NSCD when DNSSEC validation is disabled

Systemd-timesyncd sets SYSTEMD_NSS_RESOLVE_VALIDATE=0 in the unit file
to disable DNSSEC validation but it doesn't work when NSCD is used in
the system. This patch disabes NSCD in systemd-timesyncd when
SYSTEMD_NSS_RESOLVE_VALIDATE is set to 0 so that it uses NSS libraries
directly.
---
 src/timesync/timesyncd.c | 11 +++++++++++
 1 file changed, 11 insertions(+)

diff --git a/src/timesync/timesyncd.c b/src/timesync/timesyncd.c
index 5e0d13023a..1bfe0b1e6f 100644
--- a/src/timesync/timesyncd.c
+++ b/src/timesync/timesyncd.c
@@ -22,6 +22,11 @@
 #include "timesyncd-bus.h"
 #include "timesyncd-conf.h"
 #include "timesyncd-manager.h"
+#include "env-util.h"
+
+struct traced_file;
+extern void __nss_disable_nscd(void (*)(size_t, struct traced_file *));
+static void register_traced_file(size_t dbidx, struct traced_file *finfo) {}
 
 static int advance_tstamp(int fd, usec_t epoch) {
         assert(fd >= 0);
@@ -169,6 +174,12 @@ static int run(int argc, char *argv[]) {
         if (r < 0)
                 return log_error_errno(r, "Failed to parse fallback server strings: %m");
 
+        r = secure_getenv_bool("SYSTEMD_NSS_RESOLVE_VALIDATE");
+        if (r == 0) {
+                log_info("Disabling NSCD because DNSSEC validation is turned off");
+                __nss_disable_nscd(register_traced_file);
+        }
+
         log_debug("systemd-timesyncd running as pid " PID_FMT, getpid_cached());
 
         notify_message = notify_start("READY=1\n"
