Why DNS in OS X 10.10 is broken, and what you can do to fix it
arstechnica.com
arstechnica.com
All of the bugs cited have to do with ".local" domains. You should never use .local domains as IANA has designated this domain as a special use domain for Multicast DNS as part of IP Zeroconf and Bonjour. http://tools.ietf.org/html/rfc6762
Apple has also made this clear here: http://support.apple.com/en-us/HT203136
Yosemite has split the job of unicast and multicast DNS up such that you cannot resolve single-label .local domains with unicast DNS anymore; you MUST use multicast. This is why hosts will resolve with nslookup or dig but not ping. The old behavior with mDNSresponder was arguably legacy backwards compatibility for unicast DNS resolution of .local hosts.
(I figured this out the hard way over a weekend using the Googles when my local VMs weren't resolving properly via dnsmasq - my fortunes changed when I looked into ".local").
There is one remaining problem with Yosemite DNS I haven't figured out yet, and that's getting unicast DNS resolution via dnsmasq while offline. Frustrating.
Not what I really wanted (checked quite a bit around for a solution without finding any), but at least I don't have this happening multiple times a day.
> Identify your organization's DNS owner and determine what registered DNS names you have available on the network that will host Active Directory.
> If you do not have a registered domain name, you should register a name with an Internet DNS registration authority.
https://technet.microsoft.com/en-us/library/bb727085.aspx
>
http://en.wikipedia.org/wiki/.local#Microsoft_recommendation...
Another Yosemite daemon addition, recentsd, had serious issues (for example: substantial memory leaks when interacting with Mail.app) until 10.10.2.
Apple has gotten very good at eliminating crashes. They're obviously using the reporting mechanism there to great effect. But at the same time, Console.app has never been noisier, and failures that don't result in crashes seem to linger far too long.
They've also become, it seems, far more dependent on an "orchestra" of daemon processes to perform tasks that in the past would have been implemented in passive frameworks used separately by each app. That adds complexity of coordination, and meanwhile a single failure can affect every "client" app on the system.
function restart-discoveryd() {
sudo launchctl unload /System/Library/LaunchDaemons/com.apple.discoveryd.plist
sudo launchctl load /System/Library/LaunchDaemons/com.apple.discoveryd.plist
}
Then simply run `restart-discoveryd` when you can't seem to ping google.com. I always struggle to remember how to start/stop things with launchd, so this is my little shortcut. sudo discoveryutil udnsrestartquestions
instead. The one time I had DNS issues (only once!), I ran that command and all of my DNS issues immediately resolved themselves.In my short time poking around, my belief is discoveryd gets wedged into a state where it thinks DNS queries aren't resolving, and so it doesn't try to resolve them. I'm not sure what exactly is going on there, either all the queries are blocked somehow on some long-lived query that has no response and no timeout, or discoveryd thinks the network is broken and is waiting for it to come back (those are just guesses). Either way, the command tells discoveryd to restart any outstanding "questions" (which presumably means queries). When I had the issue, that was sufficient to flush out whatever it was that was blocking everything, as my machine instantly started working properly again.
Yeah, but the rewrite is buggy as rewrites often are. If it worked as intended, I doubt so many people would have so many problems.
# /usr/local/etc/dnsmasq.conf
address=/.foobar/127.0.0.1
and # /etc/resolver/foobar
nameserver 127.0.0.1# cat /usr/local/etc/dnsmasq.conf address=/dev/127.0.0.1
# cat /etc/resolver/dev nameserver 127.0.0.1
Instead of your choice of foobar.
Doesn't work offline. Your conf looks like the standard dnsmasq conf anyway, so maybe there's one other flag or configuration that you figured out?
I don't know how to configure dnsmasq at all, so that may not be a problem.
Well, I found it — quite a few entries in /etc/hosts, made at 02:30 AM, together with unflattering comments about the parents of those responsible for Yosemites new DNS subsystem...
So sorry for getting your hopes up! I have no idea how I could have misremembered all that so badly.
I have no bad experiences with resolving regular domains on Yosemite, but others in this tread have suggested bouncing discoveryd can help.
That may be the official standard, but .local is a very common, de facto standard. Products need to be compatible with reality.
Just glancing at the RFC, is my impression correct that in February 2013, with .local already widely used for private domains, someone published an RFC appropriating the name for something else? (Could they have used a different name?) They expect the world to change their internal domains in order to accommodate their new idea?
Is there a standard for private second-level domain names? I've never seen one.
This is blatantly wrong. Any device on my network (which uses .lan as a suffix) that sleeps (including Apple TVs) gets the dreaded "(2)" (or 3, 4, 7), before I started disabling "Wake for Network Access".
Yes, things are different. But don't pretend that we're just "doing/holding it wrong". There are things that are -very- broken.
I am not so sure about reenabling mDNSResponder. This may cause worse problems.
Because they regularly break. Swiftype, Swype. Keyboards disappear. All sorts of stuff.
And iOS 8 isn't really that much better. I've seen weird screens where all the apps are shown, in different orientations, text rotated while the app maintains a different orientation, in Apple apps and third party.
I'm so desperately need a fix to this that I'm wondering if there's some kind of a dongle I can plug into my ethernet or USB port to fake a LAN, just so I can use dnsmasq.
The only thing stopping me from wiping out OSX and using Linux full time is the necessity of running Sketch and the Adobe/MS Office suite for work purposes. :/
edit: anyone remember how broken DNS would prevent you from being able to completely login to GNOME? That is what this feels like.
I miss the Snow Leopard days.
I'm going in the other direction. Used to always wait one or two versions before upgrading and always doing a clean install. I installed bot Mavericks and Yosemite over the older versions early on without any problems.
My opinion of Apple's software quality has decreased over the past few months.
I'm a very happy MBP user now, and having a tiling windows manager is such a productivity boost, I doubt I'll ever go back.