1 /* Copyright (C) 1996-2003, 2004 Free Software Foundation, Inc.
2 This file is part of the GNU C Library.
3 Extended from original form by Ulrich Drepper <drepper@cygnus.com>, 1996.
5 The GNU C Library is free software; you can redistribute it and/or
6 modify it under the terms of the GNU Lesser General Public
7 License as published by the Free Software Foundation; either
8 version 2.1 of the License, or (at your option) any later version.
10 The GNU C Library is distributed in the hope that it will be useful,
11 but WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
13 Lesser General Public License for more details.
15 You should have received a copy of the GNU Lesser General Public
16 License along with the GNU C Library; if not, write to the Free
17 Software Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA
20 /* Parts of this file are plain copies of the file `gethtnamadr.c' from
21 the bind package and it has the following copyright. */
24 * ++Copyright++ 1985, 1988, 1993
26 * Copyright (c) 1985, 1988, 1993
27 * The Regents of the University of California. All rights reserved.
29 * Redistribution and use in source and binary forms, with or without
30 * modification, are permitted provided that the following conditions
32 * 1. Redistributions of source code must retain the above copyright
33 * notice, this list of conditions and the following disclaimer.
34 * 2. Redistributions in binary form must reproduce the above copyright
35 * notice, this list of conditions and the following disclaimer in the
36 * documentation and/or other materials provided with the distribution.
37 * 4. Neither the name of the University nor the names of its contributors
38 * may be used to endorse or promote products derived from this software
39 * without specific prior written permission.
41 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
42 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
43 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
44 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
45 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
46 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
47 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
48 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
49 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
50 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
53 * Portions Copyright (c) 1993 by Digital Equipment Corporation.
55 * Permission to use, copy, modify, and distribute this software for any
56 * purpose with or without fee is hereby granted, provided that the above
57 * copyright notice and this permission notice appear in all copies, and that
58 * the name of Digital Equipment Corporation not be used in advertising or
59 * publicity pertaining to distribution of the document or software without
60 * specific, written prior permission.
62 * THE SOFTWARE IS PROVIDED "AS IS" AND DIGITAL EQUIPMENT CORP. DISCLAIMS ALL
63 * WARRANTIES WITH REGARD TO THIS SOFTWARE, INCLUDING ALL IMPLIED WARRANTIES
64 * OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL DIGITAL EQUIPMENT
65 * CORPORATION BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL
66 * DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR
67 * PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS
68 * ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS
81 #include <sys/syslog.h>
85 /* Get implementation for some internal functions. */
86 #include <resolv/mapv4v6addr.h>
87 #include <resolv/mapv4v6hostent.h>
91 /* Maximum number of aliases we allow. */
92 #define MAX_NR_ALIASES 48
93 #define MAX_NR_ADDRS 48
96 # define MAXPACKET PACKETSZ
98 # define MAXPACKET 65536
100 /* As per RFC 1034 and 1035 a host name cannot exceed 255 octets in length. */
101 #ifdef MAXHOSTNAMELEN
102 # undef MAXHOSTNAMELEN
104 #define MAXHOSTNAMELEN 256
106 static const char AskedForGot
[] = "\
107 gethostby*.getanswer: asked for \"%s\", got \"%s\"";
110 /* We need this time later. */
111 typedef union querybuf
114 u_char buf
[MAXPACKET
];
117 /* These functions are defined in res_comp.c. */
118 #define NS_MAXCDNAME 255 /* maximum compressed domain name */
119 extern int __ns_name_ntop (const u_char
*, char *, size_t);
120 extern int __ns_name_unpack (const u_char
*, const u_char
*,
121 const u_char
*, u_char
*, size_t);
124 static enum nss_status
getanswer_r (const querybuf
*answer
, int anslen
,
125 const char *qname
, int qtype
,
126 struct hostent
*result
, char *buffer
,
127 size_t buflen
, int *errnop
, int *h_errnop
,
128 int map
, int32_t *ttlp
, char **canonp
);
130 extern enum nss_status
_nss_dns_gethostbyname3_r (const char *name
, int af
,
131 struct hostent
*result
,
132 char *buffer
, size_t buflen
,
133 int *errnop
, int *h_errnop
,
136 hidden_proto (_nss_dns_gethostbyname3_r
)
139 _nss_dns_gethostbyname3_r (const char *name
, int af
, struct hostent
*result
,
140 char *buffer
, size_t buflen
, int *errnop
,
141 int *h_errnop
, int32_t *ttlp
, char **canonp
)
148 querybuf
*orig_host_buffer
;
149 char tmp
[NS_MAXDNAME
];
154 enum nss_status status
;
156 if (__res_maybe_init (&_res
, 0) == -1)
157 return NSS_STATUS_UNAVAIL
;
170 *errnop
= EAFNOSUPPORT
;
171 return NSS_STATUS_UNAVAIL
;
174 result
->h_addrtype
= af
;
175 result
->h_length
= size
;
178 * if there aren't any dots, it could be a user-level alias.
179 * this is also done in res_query() since we are not the only
180 * function that looks up host names.
182 if (strchr (name
, '.') == NULL
183 && (cp
= res_hostalias (&_res
, name
, tmp
, sizeof (tmp
))) != NULL
)
186 host_buffer
.buf
= orig_host_buffer
= (querybuf
*) alloca (1024);
188 n
= __libc_res_nsearch (&_res
, name
, C_IN
, type
, host_buffer
.buf
->buf
,
189 1024, &host_buffer
.ptr
);
192 enum nss_status status
= (errno
== ECONNREFUSED
193 ? NSS_STATUS_UNAVAIL
: NSS_STATUS_NOTFOUND
);
195 if (h_errno
== TRY_AGAIN
)
198 __set_errno (olderr
);
200 /* If we are looking for a IPv6 address and mapping is enabled
201 by having the RES_USE_INET6 bit in _res.options set, we try
203 if (af
== AF_INET6
&& (_res
.options
& RES_USE_INET6
))
204 n
= __libc_res_nsearch (&_res
, name
, C_IN
, T_A
, host_buffer
.buf
->buf
,
205 host_buffer
.buf
!= orig_host_buffer
206 ? MAXPACKET
: 1024, &host_buffer
.ptr
);
210 if (host_buffer
.buf
!= orig_host_buffer
)
211 free (host_buffer
.buf
);
217 result
->h_addrtype
= AF_INET
;
218 result
->h_length
= INADDRSZ
;;
221 status
= getanswer_r (host_buffer
.buf
, n
, name
, type
, result
, buffer
, buflen
,
222 errnop
, h_errnop
, map
, ttlp
, canonp
);
223 if (host_buffer
.buf
!= orig_host_buffer
)
224 free (host_buffer
.buf
);
227 hidden_def (_nss_dns_gethostbyname3_r
)
231 _nss_dns_gethostbyname2_r (const char *name
, int af
, struct hostent
*result
,
232 char *buffer
, size_t buflen
, int *errnop
,
235 return _nss_dns_gethostbyname3_r (name
, af
, result
, buffer
, buflen
, errnop
,
236 h_errnop
, NULL
, NULL
);
241 _nss_dns_gethostbyname_r (const char *name
, struct hostent
*result
,
242 char *buffer
, size_t buflen
, int *errnop
,
245 enum nss_status status
= NSS_STATUS_NOTFOUND
;
247 if (_res
.options
& RES_USE_INET6
)
248 status
= _nss_dns_gethostbyname3_r (name
, AF_INET6
, result
, buffer
,
249 buflen
, errnop
, h_errnop
, NULL
, NULL
);
250 if (status
== NSS_STATUS_NOTFOUND
)
251 status
= _nss_dns_gethostbyname3_r (name
, AF_INET
, result
, buffer
,
252 buflen
, errnop
, h_errnop
, NULL
, NULL
);
259 _nss_dns_gethostbyaddr_r (const void *addr
, socklen_t len
, int af
,
260 struct hostent
*result
, char *buffer
, size_t buflen
,
261 int *errnop
, int *h_errnop
)
263 static const u_char mapped
[] = { 0,0, 0,0, 0,0, 0,0, 0,0, 0xff,0xff };
264 static const u_char tunnelled
[] = { 0,0, 0,0, 0,0, 0,0, 0,0, 0,0 };
265 static const u_char v6local
[] = { 0,0, 0,1 };
266 const u_char
*uaddr
= (const u_char
*)addr
;
269 char *aliases
[MAX_NR_ALIASES
];
270 unsigned char host_addr
[16]; /* IPv4 or IPv6 */
271 char *h_addr_ptrs
[MAX_NR_ADDRS
+ 1];
273 } *host_data
= (struct host_data
*) buffer
;
279 querybuf
*orig_host_buffer
;
280 char qbuf
[MAXDNAME
+1], *qp
= NULL
;
285 if (__res_maybe_init (&_res
, 0) == -1)
286 return NSS_STATUS_UNAVAIL
;
288 if (af
== AF_INET6
&& len
== IN6ADDRSZ
289 && (memcmp (uaddr
, mapped
, sizeof mapped
) == 0
290 || (memcmp (uaddr
, tunnelled
, sizeof tunnelled
) == 0
291 && memcmp (&uaddr
[sizeof tunnelled
], v6local
, sizeof v6local
))))
294 addr
+= sizeof mapped
;
295 uaddr
+= sizeof mapped
;
309 *errnop
= EAFNOSUPPORT
;
310 *h_errnop
= NETDB_INTERNAL
;
311 return NSS_STATUS_UNAVAIL
;
315 *errnop
= EAFNOSUPPORT
;
316 *h_errnop
= NETDB_INTERNAL
;
317 return NSS_STATUS_UNAVAIL
;
320 host_buffer
.buf
= orig_host_buffer
= (querybuf
*) alloca (1024);
325 sprintf (qbuf
, "%u.%u.%u.%u.in-addr.arpa", (uaddr
[3] & 0xff),
326 (uaddr
[2] & 0xff), (uaddr
[1] & 0xff), (uaddr
[0] & 0xff));
329 /* Only lookup with the byte string format if the user wants it. */
330 if (__builtin_expect (_res
.options
& RES_USEBSTRING
, 0))
332 qp
= stpcpy (qbuf
, "\\[x");
333 for (n
= 0; n
< IN6ADDRSZ
; ++n
)
334 qp
+= sprintf (qp
, "%02hhx", uaddr
[n
]);
335 strcpy (qp
, "].ip6.arpa");
336 n
= __libc_res_nquery (&_res
, qbuf
, C_IN
, T_PTR
,
337 host_buffer
.buf
->buf
, 1024, &host_buffer
.ptr
);
342 for (n
= IN6ADDRSZ
- 1; n
>= 0; n
--)
344 static const char nibblechar
[16] = "0123456789abcdef";
345 *qp
++ = nibblechar
[uaddr
[n
] & 0xf];
347 *qp
++ = nibblechar
[(uaddr
[n
] >> 4) & 0xf];
350 strcpy(qp
, "ip6.arpa");
357 n
= __libc_res_nquery (&_res
, qbuf
, C_IN
, T_PTR
, host_buffer
.buf
->buf
,
358 1024, &host_buffer
.ptr
);
359 if (n
< 0 && af
== AF_INET6
&& (_res
.options
& RES_NOIP6DOTINT
) == 0)
361 strcpy (qp
, "ip6.int");
362 n
= __libc_res_nquery (&_res
, qbuf
, C_IN
, T_PTR
, host_buffer
.buf
->buf
,
363 host_buffer
.buf
!= orig_host_buffer
364 ? MAXPACKET
: 1024, &host_buffer
.ptr
);
369 __set_errno (olderr
);
370 if (host_buffer
.buf
!= orig_host_buffer
)
371 free (host_buffer
.buf
);
372 return errno
== ECONNREFUSED
? NSS_STATUS_UNAVAIL
: NSS_STATUS_NOTFOUND
;
376 status
= getanswer_r (host_buffer
.buf
, n
, qbuf
, T_PTR
, result
, buffer
, buflen
,
377 errnop
, h_errnop
, 0 /* XXX */, NULL
, NULL
);
378 if (host_buffer
.buf
!= orig_host_buffer
)
379 free (host_buffer
.buf
);
380 if (status
!= NSS_STATUS_SUCCESS
)
388 This is
not implemented because it is
not possible to use the current
389 source from bind in a multi
-threaded program
.
392 result
->h_addrtype
= af
;
393 result
->h_length
= len
;
394 memcpy (host_data
->host_addr
, addr
, len
);
395 host_data
->h_addr_ptrs
[0] = (char *) host_data
->host_addr
;
396 host_data
->h_addr_ptrs
[1] = NULL
;
398 /* XXX I think this is wrong. Why should an IPv4 address be
399 converted to IPv6 if the user explicitly asked for IPv4? */
400 if (af
== AF_INET
&& (_res
.options
& RES_USE_INET6
))
402 map_v4v6_address ((char *) host_data
->host_addr
,
403 (char *) host_data
->host_addr
);
404 result
->h_addrtype
= AF_INET6
;
405 result
->h_length
= IN6ADDRSZ
;
408 *h_errnop
= NETDB_SUCCESS
;
409 return NSS_STATUS_SUCCESS
;
413 static void addrsort (char **ap
, int num
);
416 addrsort (char **ap
, int num
)
420 short aval
[MAX_NR_ADDRS
];
424 if (num
> MAX_NR_ADDRS
)
426 for (i
= 0; i
< num
; i
++, p
++)
428 for (j
= 0 ; (unsigned)j
< _res
.nsort
; j
++)
429 if (_res
.sort_list
[j
].addr
.s_addr
==
430 (((struct in_addr
*)(*p
))->s_addr
& _res
.sort_list
[j
].mask
))
433 if (needsort
== 0 && i
> 0 && j
< aval
[i
-1])
439 while (needsort
++ < num
)
440 for (j
= needsort
- 2; j
>= 0; j
--)
441 if (aval
[j
] > aval
[j
+1])
458 static enum nss_status
459 getanswer_r (const querybuf
*answer
, int anslen
, const char *qname
, int qtype
,
460 struct hostent
*result
, char *buffer
, size_t buflen
,
461 int *errnop
, int *h_errnop
, int map
, int32_t *ttlp
, char **canonp
)
465 char *aliases
[MAX_NR_ALIASES
];
466 unsigned char host_addr
[16]; /* IPv4 or IPv6 */
467 char *h_addr_ptrs
[0];
468 } *host_data
= (struct host_data
*) buffer
;
469 int linebuflen
= buflen
- sizeof (struct host_data
);
470 register const HEADER
*hp
;
471 const u_char
*end_of_message
, *cp
;
472 int n
, ancount
, qdcount
;
473 int haveanswer
, had_error
;
474 char *bp
, **ap
, **hap
;
477 int (*name_ok
) (const char *);
478 u_char packtmp
[NS_MAXCDNAME
];
482 if (__builtin_expect (linebuflen
, 0) < 0)
484 /* The buffer is too small. */
487 *h_errnop
= NETDB_INTERNAL
;
488 return NSS_STATUS_TRYAGAIN
;
492 result
->h_name
= NULL
;
493 end_of_message
= answer
->buf
+ anslen
;
505 return NSS_STATUS_UNAVAIL
; /* XXX should be abort(); */
509 * find first satisfactory answer
512 ancount
= ntohs (hp
->ancount
);
513 qdcount
= ntohs (hp
->qdcount
);
514 cp
= answer
->buf
+ HFIXEDSZ
;
515 if (__builtin_expect (qdcount
, 1) != 1)
517 *h_errnop
= NO_RECOVERY
;
518 return NSS_STATUS_UNAVAIL
;
520 if (sizeof (struct host_data
) + (ancount
+ 1) * sizeof (char *) >= buflen
)
522 bp
= (char *) &host_data
->h_addr_ptrs
[ancount
+ 1];
523 linebuflen
-= (ancount
+ 1) * sizeof (char *);
525 n
= __ns_name_unpack (answer
->buf
, end_of_message
, cp
,
526 packtmp
, sizeof packtmp
);
527 if (n
!= -1 && __ns_name_ntop (packtmp
, bp
, linebuflen
) == -1)
529 if (__builtin_expect (errno
, 0) == EMSGSIZE
)
535 if (n
> 0 && bp
[0] == '.')
538 if (n
< 0 || (*name_ok
) (bp
) == 0)
541 *h_errnop
= NO_RECOVERY
;
542 return NSS_STATUS_UNAVAIL
;
546 if (qtype
== T_A
|| qtype
== T_AAAA
)
548 /* res_send() has already verified that the query name is the
549 * same as the one we sent; this just gets the expanded name
550 * (i.e., with the succeeding search-domain tacked on).
552 n
= strlen (bp
) + 1; /* for the \0 */
553 if (n
>= MAXHOSTNAMELEN
)
555 *h_errnop
= NO_RECOVERY
;
557 return NSS_STATUS_TRYAGAIN
;
564 /* The qname can be abbreviated, but h_name is now absolute. */
565 qname
= result
->h_name
;
568 ap
= host_data
->aliases
;
570 result
->h_aliases
= host_data
->aliases
;
571 hap
= host_data
->h_addr_ptrs
;
573 result
->h_addr_list
= host_data
->h_addr_ptrs
;
577 while (ancount
-- > 0 && cp
< end_of_message
&& had_error
== 0)
581 n
= __ns_name_unpack (answer
->buf
, end_of_message
, cp
,
582 packtmp
, sizeof packtmp
);
583 if (n
!= -1 && __ns_name_ntop (packtmp
, bp
, linebuflen
) == -1)
585 if (__builtin_expect (errno
, 0) == EMSGSIZE
)
591 if (n
< 0 || (*name_ok
) (bp
) == 0)
597 type
= ns_get16 (cp
);
598 cp
+= INT16SZ
; /* type */
599 class = ns_get16 (cp
);
600 cp
+= INT16SZ
; /* class */
602 cp
+= INT32SZ
; /* TTL */
604 cp
+= INT16SZ
; /* len */
607 /* XXX - debug? syslog? */
609 continue; /* XXX - had_error++ ? */
612 if ((qtype
==T_A
|| qtype
== T_AAAA
) && type
== T_CNAME
)
614 if (ap
>= &host_data
->aliases
[MAX_NR_ALIASES
- 1])
616 n
= dn_expand (answer
->buf
, end_of_message
, cp
, tbuf
, sizeof tbuf
);
617 if (n
< 0 || (*name_ok
) (tbuf
) == 0)
625 n
= strlen (bp
) + 1; /* For the \0. */
626 if (__builtin_expect (n
, 0) >= MAXHOSTNAMELEN
)
633 /* Get canonical name. */
634 n
= strlen (tbuf
) + 1; /* For the \0. */
635 if (__builtin_expect (n
> linebuflen
, 0))
637 if (__builtin_expect (n
, 0) >= MAXHOSTNAMELEN
)
643 bp
= __mempcpy (bp
, tbuf
, n
); /* Cannot overflow. */
648 if (qtype
== T_PTR
&& type
== T_CNAME
)
650 n
= dn_expand (answer
->buf
, end_of_message
, cp
, tbuf
, sizeof tbuf
);
651 if (n
< 0 || res_dnok (tbuf
) == 0)
657 /* Get canonical name. */
658 n
= strlen (tbuf
) + 1; /* For the \0. */
659 if (__builtin_expect (n
> linebuflen
, 0))
661 if (__builtin_expect (n
, 0) >= MAXHOSTNAMELEN
)
667 bp
= __mempcpy (bp
, tbuf
, n
); /* Cannot overflow. */
671 if (__builtin_expect (type
== T_SIG
, 0)
672 || __builtin_expect (type
== T_KEY
, 0)
673 || __builtin_expect (type
== T_NXT
, 0))
675 /* We don't support DNSSEC yet. For now, ignore the record
676 and send a low priority message to syslog. */
677 syslog (LOG_DEBUG
| LOG_AUTH
,
678 "gethostby*.getanswer: asked for \"%s %s %s\", got type \"%s\"",
679 qname
, p_class (C_IN
), p_type(qtype
), p_type (type
));
684 if (type
== T_A
&& qtype
== T_AAAA
&& map
)
686 else if (__builtin_expect (type
!= qtype
, 0))
688 syslog (LOG_NOTICE
| LOG_AUTH
,
689 "gethostby*.getanswer: asked for \"%s %s %s\", got type \"%s\"",
690 qname
, p_class (C_IN
), p_type (qtype
), p_type (type
));
692 continue; /* XXX - had_error++ ? */
698 if (__strcasecmp (tname
, bp
) != 0)
700 syslog (LOG_NOTICE
| LOG_AUTH
, AskedForGot
, qname
, bp
);
702 continue; /* XXX - had_error++ ? */
705 n
= __ns_name_unpack (answer
->buf
, end_of_message
, cp
,
706 packtmp
, sizeof packtmp
);
707 if (n
!= -1 && __ns_name_ntop (packtmp
, bp
, linebuflen
) == -1)
709 if (__builtin_expect (errno
, 0) == EMSGSIZE
)
715 if (n
< 0 || res_hnok (bp
) == 0)
720 #if MULTI_PTRS_ARE_ALIASES
724 else if (ap
< &host_data
->aliases
[MAXALIASES
-1])
730 n
= strlen (bp
) + 1; /* for the \0 */
731 if (__builtin_expect (n
, 0) >= MAXHOSTNAMELEN
)
744 n
= strlen (bp
) + 1; /* for the \0 */
745 if (n
>= MAXHOSTNAMELEN
)
752 map_v4v6_hostent (result
, &bp
, &linebuflen
);
754 *h_errnop
= NETDB_SUCCESS
;
755 return NSS_STATUS_SUCCESS
;
759 if (__builtin_expect (strcasecmp (result
->h_name
, bp
), 0) != 0)
761 syslog (LOG_NOTICE
| LOG_AUTH
, AskedForGot
, result
->h_name
, bp
);
763 continue; /* XXX - had_error++ ? */
765 if (n
!= result
->h_length
)
774 if (ttlp
!= NULL
&& ttl
!= 0)
779 nn
= strlen (bp
) + 1; /* for the \0 */
784 linebuflen
-= sizeof (align
) - ((u_long
) bp
% sizeof (align
));
785 bp
+= sizeof (align
) - ((u_long
) bp
% sizeof (align
));
787 if (__builtin_expect (n
> linebuflen
, 0))
789 bp
= __mempcpy (*hap
++ = bp
, cp
, n
);
804 #if defined RESOLVSORT
806 * Note: we sort even if host can take only one address
807 * in its return structures - should give it the "best"
808 * address in that case, not some random one
810 if (_res
.nsort
&& haveanswer
> 1 && qtype
== T_A
)
811 addrsort (host_data
->h_addr_ptrs
, haveanswer
);
812 #endif /*RESOLVSORT*/
814 if (result
->h_name
== NULL
)
816 n
= strlen (qname
) + 1; /* For the \0. */
819 if (n
>= MAXHOSTNAMELEN
)
822 bp
= __mempcpy (bp
, qname
, n
); /* Cannot overflow. */
827 map_v4v6_hostent (result
, &bp
, &linebuflen
);
828 *h_errnop
= NETDB_SUCCESS
;
829 return NSS_STATUS_SUCCESS
;
832 *h_errnop
= NO_RECOVERY
;
834 return NSS_STATUS_TRYAGAIN
;