From 937246a86837bb8d76725eef64696d1364bc6289 Mon Sep 17 00:00:00 2001 From: Albin Kerouanton Date: Tue, 25 Nov 2025 11:26:05 +0100 Subject: [PATCH] libnet: populateNetworkResourcesOS: updateDNS only if !needResolver When ep.needResolver() is true, sb.startResolver() calls sb.rebuildDNS() which doesn't update the resolv.conf hash file. Subsequent calls to sb.updateDNS() (which is only called by populateNetworkResourcesOS) won't have any effect since it'll compare the hash file and consider that the file was manually modified. Make this explicit by gating the call to updateDNS() on !needResolver(). Signed-off-by: Albin Kerouanton --- daemon/libnetwork/sandbox_linux.go | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/daemon/libnetwork/sandbox_linux.go b/daemon/libnetwork/sandbox_linux.go index 27a37dfd8c..878ff44495 100644 --- a/daemon/libnetwork/sandbox_linux.go +++ b/daemon/libnetwork/sandbox_linux.go @@ -366,6 +366,11 @@ func (sb *Sandbox) populateNetworkResourcesOS(ctx context.Context, ep *Endpoint) if ep.needResolver() { sb.startResolver(false) + } else { + // Make sure /etc/resolv.conf is set up. + if err := sb.updateDNS(ep.getNetwork().enableIPv6); err != nil { + return err + } } if i != nil && i.srcName != "" { @@ -448,10 +453,6 @@ func (sb *Sandbox) populateNetworkResourcesOS(ctx context.Context, ep *Endpoint) } sb.addHostsEntries(ctx, ep.getEtcHostsAddrs()) - // Make sure /etc/resolv.conf is set up. - if err := sb.updateDNS(ep.getNetwork().enableIPv6); err != nil { - return err - } // Populate load balancer only after updating all the other // information including gateway and other routes so that