Leap 16 name resolution broken after update

Hello,

I updated to Leap 16 and name resolution is broken now.

dig and nslookup are working fine but e.g. zypper up gives me errors for any repo:

Repository ‘repo-non-oss (16.0)’ is invalid.
[openSUSE:repo-non-oss|/distribution/leap/16.0/repo/non-oss/x86_64 - openSUSE Download] Failed to retrieve new repository metadata.
History:

trying with dig:
; <<>> DiG 9.20.11 <<>> cdn.opensuse.org

;; global options: +cmd

;; Got answer:

;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 35874

;; flags: qr rd ra; QUERY: 1, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:

; EDNS: version: 0, flags:; udp: 1232

;; QUESTION SECTION:

;cdn.opensuse.org. IN A

;; ANSWER SECTION:

cdn.opensuse.org. 353 IN CNAME dualstack.n.sni.global.fastly.net.

dualstack.n.sni.global.fastly.net. 60 IN A 151.101.1.91

dualstack.n.sni.global.fastly.net. 60 IN A 151.101.65.91

dualstack.n.sni.global.fastly.net. 60 IN A 151.101.129.91

dualstack.n.sni.global.fastly.net. 60 IN A 151.101.193.91

;; Query time: 16 msec

;; SERVER: 192.168.100.2#53(192.168.100.2) (UDP)

;; WHEN: Wed Oct 08 19:52:52 CEST 2025

;; MSG SIZE rcvd: 156

With nslookup:

nslookup cdn.opensuse.org

Server: 192.168.100.2

Address: 192.168.100.2#53

Non-authoritative answer:

cdn.opensuse.org canonical name = dualstack.n.sni.global.fastly.net.

Name: dualstack.n.sni.global.fastly.net

Address: 151.101.129.91

Name: dualstack.n.sni.global.fastly.net

Address: 151.101.193.91

Name: dualstack.n.sni.global.fastly.net

Address: 151.101.1.91

Name: dualstack.n.sni.global.fastly.net

Address: 151.101.65.91

Name: dualstack.n.sni.global.fastly.net

Address: 2a04:4e42:600::347

Name: dualstack.n.sni.global.fastly.net

Address: 2a04:4e42::347

Name: dualstack.n.sni.global.fastly.net

Address: 2a04:4e42:200::347

Name: dualstack.n.sni.global.fastly.net

Address: 2a04:4e42:400::347

Show

grep hosts /etc/nsswitch.conf

Use preformatted text to post computer output.

hosts:  	files dns

Do you still have this problem?

Yes. I guess it is related to selinux. I used the opensuse-migration-tool to upgrade and selected the selinux option. There are no selinux profiles installed at all and no tools for selinux, but in the config file selinux was enabled. Meanwhile I disabled it in the config file, removed it from grub config and entered app armor again. I also enabled app armor service again. Still the same. I have added the domains that curl couldn’t resolve in /etc/hosts and download of package is working, but during installation I get librpm.so.10: cannot open shared object file: Permission denied.

Progress. After aa-complain rpm I can install packages. So it’s clearly related to security settings now.

Well, it is the second report. Someone finally needs to open bug report.

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.