TT Lab
Get started
Learn Learning paths Courses

Network Troubleshooting

Reading, Writing and Auditing /etc/hosts

Continue in TT Lab

Goal

You read, edit, and audit /etc/hosts. And you confirm by hand why getent and dig give different answers.

Why it matters

As long as files is first in the hosts: line of nsswitch.conf, /etc/hosts is consulted before DNS. So if one wrong line remains in hosts, however much you fix DNS, the application keeps going to the old address. Worse, this incident does not show the face of a DNS error — the name resolves fine, and the symptom appears as connection refused or a timeout. Because dig does not look at this file at all, the maze "dig is fine but only the application fails" gets created.

Steps

  1. Create the /root/net directory, pick out from /etc/hosts only the lines that have a loopback address, and save them to /root/net/hosts-loopback.txt. Both IPv4 (starting with 127.) and IPv6 (::1) must be included.
  2. Add an entry to /etc/hosts mapping 10.10.0.11 → app1.labhub.local (the canonical name) and app1 (an alias), and save the output of getent hosts app1.labhub.local to /root/net/getent-app1.txt.
  3. Check that the same IP comes out for the alias app1 too and save it to /root/net/getent-alias.txt.
  4. Save the line starting with hosts: in /etc/nsswitch.conf to /root/net/nsswitch-hosts.txt.
  5. Add an IPv6 entry to /etc/hosts mapping fd00:cafe::11 → app6.labhub.local, and save the result of querying only the IPv6 address to /root/net/getent-v6.txt.
  6. In /etc/hosts, add the same name web.labhub.local on one line each for the two IPs 10.10.0.21 and 10.10.0.22, and save the output of getent ahosts web.labhub.local to /root/net/getent-multi.txt.
  7. Audit /opt/fixtures/nt-hosts/hosts.broken. Write only the line numbers that break the three rules below, in ascending order, one per line, in /root/net/hosts-audit.txt.
    • Rule A: every entry line must have at least 2 fields counting the IP and the names together
    • Rule B: each octet of an IPv4 address must be 0–255
    • Rule C: the same canonical name (the second field) must not appear more than once in the file
  8. Submit as /root/net/hosts.final a final version with all the problems found in step 7 fixed. Keep the originally normal entries as they are, fix db01.labhub.local to 10.20.30.13 and bad.labhub.local to 10.20.30.18, fill in the line with no name as 10.20.30.14 log01.labhub.local log01, and change the canonical name of the line with the duplicated canonical name to web01-old.labhub.local.

Notes

Checking the loopback entries

Create the /root/net directory, pick out from /etc/hosts only the lines that have a loopback address, and save them to /root/net/hosts-loopback.txt. Both IPv4 (starting with 127.) and IPv6 (::1) must be included.

The IPv4 loopback and the IPv6 loopback are on different lines. You must pick out both lines.

Adding an entry and checking resolution

Add an entry to /etc/hosts mapping 10.10.0.11 → app1.labhub.local (the canonical name) and app1 (an alias), and save the output of getent hosts app1.labhub.local to /root/net/getent-app1.txt.

getent hosts resolves the name through the same path as the application. The first field of the result is the IP.

Checking that it resolves by alias too

Check that the same IP comes out for the alias app1 too and save it to /root/net/getent-alias.txt.

In one hosts line, the second field is the canonical name and from the third on are aliases. It is normal for an alias to resolve to the same IP.

Checking the resolution order

Save the line starting with hosts: in /etc/nsswitch.conf to /root/net/nsswitch-hosts.txt.

One line starting with hosts is enough. What the first source on that line is, is the key to this lab.

Handling IPv6 entries

Add an IPv6 entry to /etc/hosts mapping fd00:cafe::11 → app6.labhub.local, and save the result of querying only the IPv6 address to /root/net/getent-v6.txt.

The hosts file is not a place that holds only IPv4. Write an IPv6 address and check with getent hosts <이름> (the placeholder is the name).

If you thought of getent ahostsv6, that is a good instinct, but in this environment it comes out empty. The ahosts family of glibc attaches AI_ADDRCONFIG to the lookup, and that flag asks for IPv6 only when this machine has at least one global-scope IPv6 address. The ::1 on lo is host scope, so it does not count, and even getent ahostsv6 ::1 is empty.

This is not a trap but a phenomenon you meet as it is in practice — the common answer to "I definitely wrote it in hosts, so why doesn't it show up" is this. getent hosts goes through a different path (gethostbyname2), so it does not take this flag.

Several IPs for one name

In /etc/hosts, add the same name web.labhub.local on one line each for the two IPs 10.10.0.21 and 10.10.0.22, and save the output of getent ahosts web.labhub.local to /root/net/getent-multi.txt.

You can write the same name on two lines with different IPs. See how many lines getent ahosts returns.

Auditing a broken hosts file

Audit /opt/fixtures/nt-hosts/hosts.broken. Write only the line numbers that break the three rules below, in ascending order, one per line, in /root/net/hosts-audit.txt.

The rules are four. A line with fewer than 2 fields, a line whose IPv4 octet exceeds 255, and a line that reuses a canonical name already used earlier. You count line numbers from 1 at the very top of the file, including comments and blank lines.

Submitting the cleaned-up final version

Submit as /root/net/hosts.final a final version with all the problems found in step 7 fixed. Keep the originally normal entries as they are, fix db01.labhub.local to 10.20.30.13 and bad.labhub.local to 10.20.30.18, fill in the line with no name as 10.20.30.14 log01.labhub.local log01, and change the canonical name of the line with the duplicated canonical name to web01-old.labhub.local.

It must be a file with all the problems found in the audit removed. For a wrong IP, it is more realistic to fix it to the correct value than to delete it.