8 ms·
macOS 26 breaks custom DNS settings including .internal
One of those 'woke up to MacOS updates' and finding none of my dockers are reachable via dnsmasq (which I use), and low and behold, an update silently breaks custom dns resolution. Hopefully Apple will listen to the bug report I've made. Hold off on updating if you use this…
- adamamyl 7mo agoBefore others jump in: I already use Linux (and used to run FreeBSD as my desktop operating system).
- bgentry 7mo agoThanks for sharing your report, it's frustrating to see things like this break in minor patch updates. Small tip for GitHub Gist: set the file format to markdown (give it a .md extension) so that the markdown will be rendered and won't require horizontal scrolling :)
- mrpippy 7mo agoThe report says it broke when updating from macOS 15 to 26, so not a minor patch update. I'm a bit surprised no one noticed this earlier though, since 26 has been out since September and in beta since June.
- deleted 7mo ago[deleted]
- Heer_J 7mo ago[dead]
- deleted 7mo ago[deleted]
- Congeec 7mo agoIf you have ScreenTime turned on. Port :8080 is occupied and your ubuntu apt-get in a docker build gets hash mismatch because they obviously modified packets. Let alone I am having another issue of unable to delete a private key in Keychain Access. The whole macOS thing is amateur
- mococa 7mo agoPort 5000 is also ocupied on macOS.
- 1718627440 7mo agoWhy does macOS use ports above 1024 by default? There is a reason it is reserved to be used by OS services.
- The_President 7mo agoTried to use one recently - but I can't get past all the unkillable CPU hogging processes. It's clear the actuaries are running the software development department.
- deleted 7mo ago[deleted]
- binaryturtle 7mo agoI run a setup like that on my (outdated) Yosemite machine to provide multiple private TLDs for local deployment/development needs. I set that up in like 2014? Even back then it was known already that the quick /etc/resolver way was the deprecated way to do things. So I guess they finally killed that feature off? The proper (more awkward) way is to use scutil directly (which then stores the settings in some binary plist somewhere, I assume). Maybe try this and see if it still works afterwards?
- hrmtst93837 7mo ago[flagged]
- himata4113 7mo agoStill wishing for the day apple is split into the hardware and the software company. I want their silicon, but I will never use their (arguably terrible) operating system. If I can't run my own kernel and kernel modules then it's a device that I don't own. Firmware is alright in some cases, but my laptop next to me is running core boot just to prove a point.
- t-sauer 7mo agoBut you can run your own kernel on Macs, no? Isn‘t driver support the issue?
- deleted 7mo ago[deleted]
- vbezhenar 7mo agoMaybe Apple Hardware would write Linux drivers to sell their hardware for servers. Intel contributes to Linux kernel. AMD contributes to Linux kernel. Nvidia contributes to Linux kernel. A lot of hardware manufacturers support Linux to some extent. It's no longer reverse-engineered wild west.
- himata4113 7mo agoNot on new silicon and asahi linux is still pretty damn far from being able to use it seriously. I do appreciate the effort, but I am just saying that it would be a lot better if you know, apple sold the hardware so vendors could build laptops with apple silicon.
- CamJN 7mo agoApple literally made step by step instructions for compiling and running your own kernel on Apple silicon. Not sure how you think asahi Linux works otherwise. Sure the drivers are anywhere from bad to non existent but that’s not the same thing as being unable to run your own kernel.
- 7mo ago
- pissedoffadmin 7mo ago[dead]
- mrbuttons454 7mo agoPapercuts like this are why I moved away from macOS. I will say, I don't love the use of LLMs to write these bug reports. It's probably fine if reviewed, but at least review for things like "worked on macOS 25", which obviously didn't exist. If that wasn't caught, how sure are you that the rest of the report is accurate? We all want the bugs fixed, but people are going to start throwing out the obviously LLM written reports rather than have to validate each claim, since the author probably didn't.
- duped 7mo agoUsing LLMs for any kind of writing is unethical, with the narrow exception of translation. If you didn't take the time to compose your words thoughtfully then you aren't owed the time to read them.
- eru 7mo ago[flagged]
- deleted 7mo ago[deleted]
- deleted 7mo ago[deleted]
- kibwen 7mo agoAgreed, which is why I didn't bother reading this comment before downvoting it. If you think that you were owed some other behavior from me despite not paying me for it, feel free to elaborate; for example, you could acknowledge that there exists an implicit social contract when it comes to basic human communication.
- dec0dedab0de 7mo agoThere is a huge difference between using an llm and just blindly dumping it's output on someone verbatim. I think it's fine to have an llm write a first or second draft of something, then go through and reword most of it to be in your own voice.
- neilsharma425 7mo agoHas anyone found a working workaround yet? I use dnsmasq for .local dev routing and held off updating after seeing this but curious if there is a viable path forward short of waiting for Apple to patch it.
- mkagenius 7mo agoholding off update seems like reasonable step till the patch comes. I also run a .local for apple containers though not docker.
- deleted 7mo ago[deleted]
- cortesoft 7mo agoWouldn’t the workaround just be to have your local dns server enable recursive lookups, and point all your DNS queries to it?
- kenny_r 7mo agoWhat I'd suggest is using lvh.me, which always resolves to localhost, as do all it's subdomains. If you need a specific IP you can use nip.io. If you want valid certs you can generate them with mkcert and add them to your system trust store.
- justsomehnguy 7mo agoSolved this type of shenanigans some years ago with this. New-UnboundInterface.sh - linux/rhel-like specific # create a bridge interface for Unbound # because Docker... IFTYPE=bridge IFNAME=unbound0 IPADDR=10.53.0.1 IPADDR6=fd53:fd53:fd53::1 nmcli connection add type $IFTYPE ifname $IFNAME nmcli connection modify $IFTYPE-$IFNAME ip4 $IPADDR/32 nmcli connection modify $IFTYPE-$IFNAME ipv4.dns $IPADDR nmcli connection modify $IFTYPE-$IFNAME ip6 $IPADDR6/64 nmcli connection modify $IFTYPE-$IFNAME ipv6.dns $IPADDR6 nmcli connection up $IFTYPE-$IFNAME firewall-cmd --new-zone=unbound --permanent firewall-cmd --zone=unbound --permanent --change-interface=$IFNAME firewall-cmd --zone=unbound --permanent --add-service=dns firewall-cmd --reload 00-localinterface.conf # should be placed in /etc/unbound/conf.d # bind to a specified IP address, allow access server: interface: 10.53.0.1 interface: fd53:fd53:fd53::1 access-control: 10.53.0.1/32 allow access-control: fd53:fd53:fd53::1/128 allow 91-allow-docker-containers.conf # allow queries from the Docker "bridge" server: access-control: 172.18.0.1/16 allow
- hk1337 7mo agoI've been using macOS since OS X Tiger and I wasn't aware of this feature.
- Razengan 7mo agoIt also seemingly broke removing Safari cookies on a per website basis, something I often used to stop Google's scummy tracking across all their services if you just want to sign into YouTube.
- nottorp 7mo agoFirefox + Google Container extension. Why use Apple's browser when they don't actually care about your privacy?
- Drupon 7mo agoFYI the phrase is "lo and behold" Thank you for the heads up.
- lapcat 7mo ago> https://feedbackassistant.apple.com/feedback/22280434 https://feedbackassistant.apple.com/feedback/22280434 (that seems to need a login?). All Feedbacks that you file are private to your own Apple Account.
- ramon156 7mo agoBit off-topic. I mostly use Linux and I'm of the opinion that it's miles better than Windows, but I don't fully understand why people say MacOS looks bad? Ignoring the current Tahoe mess, MacOS felt relatively polished. I'm purely talking about UX here, as the OS is evidently buggy. The most popular Gnome themes are a re-impl of MacOS, so I can't be the only one.
- klodolph 7mo agoIt’s selection bias; the people who complain are the most visible online. Especially HN.
- cromka 7mo agoYou don't know that, you could frame any genuine problem with any company as a selection bias.
- klodolph 7mo agoWhen you say “You don’t know that”, you expect the people reading your comment to interpret it generously. A good interpretation of your comment is something like, “You’ve provided no reasoning to back up that argument” or “I think it’s unlikely that you have evidence to support your claims”. A bad interpretation of your comment is, “I can answer with certainty whether you have this specific piece of knowledge, and the answer is no.” I encourage you to apply the same generosity to comments you read.
- nslsm 7mo agoThere’s no “Tahoe mess”. I’ve used it since 26.0 and it’s good. Different indeed, but good. People love complaining.
- celsoazevedo 7mo agoI'm glad that it's working well for you, but from the moment some users with M-series SoCs report laggy animations, something somewhere has to be wrong.
- deleted 7mo ago[deleted]
- ProllyInfamous 7mo agoI am not familiar with dnsmasq at all (is this machine-local?), but absolutely love my PiHole hardware — you can even create rules which intercept hard-coded-IP DNS request and/or httpsDNS. You can also hard-code/intercept .TLD to local service IPs. Programs like LittleSnitch never really seem like "enough" for me, because the computer has to boot before DNS filtering comes online. It also has the design error (IMHO) of pre-resolving IP addresses before clicking Accept/Deny(all). A great blockrule for your personal firewalls would be to ban (at top level) icloud.com, apple.com, &c; system updates can then be performed manually using guides like <http://www.mrmacintosh.com http://www.mrmacintosh.com>. Of course: this breaks everything (in exactly the way I prefer to compute).
- bombcar 7mo agoThis works great (and I use it) internally but when you want things like your docker domains to work when you're on the go, it's annoying. I have setup a VM running DNS on my laptop before ...
- ProllyInfamous 7mo agoIt is not too difficult to allow your PiHole to serve you globally (but does requiring opening some ports in your firewall == additional security risk). There is a simple checkbox within the DNS's web interface to `Allow WAN Requests`. You'd then only run into issues of accessing your local IP addresses if those hosts aren't configured correctly within your network rulesets. ---- I am a user, not an expert; by trade, I am a blue collar electrician. I know very little about internet topology except how to use simple open-source hardware. Perhaps what you said makes sense (e.g. that you cannot use outside your network, some service(s)).
- bombcar 7mo agoYeah that can work, though at that point I start to consider just exposing my "internal" DNS to the world at large - who cares if secret_service.mydomain.net can be seen by everyone to resolve to 192.168.88.4? You can also do VPN tricks, too.
- JimDabell 7mo ago*.localhost works out of the box doesn’t it? You don’t need dnsmasq at all to have multiple hostnames pointing to 127.0.0.1.
- bombcar 7mo agoYou often have internal private IPs you want to resolve to things that aren't localhost
- winstonwinston 7mo ago*.example-private point is to have multiple machines using private addresses such as web.example-private in A 192.168.0.100 and db1.example-private in A 192.168.0.101. If you just want to resolve 127.0.0.1 then you just resolve hostname "localhost" or use 127.0.0.1 directly. Personally i don't bother configuring custom private dns zones, instead i use reserved MDNS *.local that autoconfigure everything using machine name (hostname) and DHCP address: somehostname.local in A <dhcp assigned ip>.
- MoonWalk 7mo agoA couple iOS versions ago, Apple broke self-signed certificates... crippling mobile development by preventing the use of HTTPS to communicate with a local server. It makes you wonder why they were messing around in these areas at all at this point.
- whatsupdog 7mo ago[flagged]
- PennyWise99176 7mo ago[dead]
- deleted 7mo ago[deleted]
- yearolinuxdsktp 7mo agoApple container CLI configures internal domains (`container system dns`) by adding an internal resolver and it worked for me when I specified an actual domain previously handled by external DNS and it showed up as a custom resolver. Here’s a GitHub comment showing someone on MacOS 26 with a `.test` domain, which you claim is broken: https://github.com/apple/container/issues/856#issuecomment-3616616225 https://github.com/apple/container/issues/856#issuecomment-3... —- maybe you are configuring it incorrectly.
- philo23 7mo agoIt's not quite the same, but I've moved to using *.localhost for all my local web dev work. All modern browsers will resolve *.localhost to 127.0.0.1 internally. No need to setup any DNS resolvers or edit your hosts file. But that only really helps you when you're dealing with websites in a browser, and when you want the address to resolve back to your local machine. So it wont help you with other programs like python/wget/etc or any calls you make to getaddrinfo()
- andrewmcwatters 7mo ago[dead]
- whalesalad 7mo agowe have dev.our-root-domain.com in public DNS pointing to 127.0.0.1
- stock_toaster 7mo agoI've run into resolvers that filter things like that to prevent dns rebinding attacks. And localhost (the hostname) does not work for CORS. Best option is probably to set dev.our-root-domain.com in /etc/hosts [1]: https://en.wikipedia.org/wiki/DNS_rebinding https://en.wikipedia.org/wiki/DNS_rebinding
- whalesalad 7mo agoHaven't had an issue yet, with a team scattered across US, Canada and UK. I'm sure it's possible - but so far we've been using this for about 3 years with no hiccups.
- stock_toaster 7mo agoDefinitely more common on corporate networks. I guess most home users (remote employees) are probably either using their ISP's resolvers, or browser DoH (Dns-Over-HTTPS).
- 7mo ago
- intrasight 7mo agoHonest question: How would this affect me and the vast majority of macOS users who use the device for media consumption and productivity applications? Next question: what reason would Apple have to make a change that would interfere with developers using their operating system?
- mikestew 7mo agoYour “next question” seems very leading. Can you make your point more clear? What’s your answer to that question?
- intrasight 7mo agoI don't understand your question since my question was honestly posed. What might lead Apple to make a change that would reduce the audience of their devices. I don't develop on macOS but I know developers who do. Did they just make a mistake and they're gonna fix it?
- mikestew 7mo agoI doubt it was an intentional change. A lot of bugs result from, "hmm, didn't think about that use case. Ooops." There's just the question of how long it'll be before they ship a fix. It seems like there ought to be an automated test for something like this, but Apple seems to be shedding QA as fast as Microsoft is. (And apologies if it seemed that I was insinuating ill intent on your part.)
- lysace 7mo ago> Ah, the joys of waking up to find the Mac's done an overnight upgrade Wait, it does that (from 15 to 26) without user interaction?
- timw4mail 7mo agoNo.
- mikestew 7mo agoNo, it does not. It’ll bug the shit out of you to upgrade, but it won’t automatically do a major version upgrade. By default it will automatically do minor version upgrades (that can be turned off). That’s what makes the LLM bug report make no sense in light of OP’s report here. Bug says it’s a regression from 25.x (which doesn’t exist), so maybe they mean 15.x? But OP says they “woke up” and it was upgraded and broken, but macOS doesn’t major version upgrades w/o user action. So which is it?
- lysace 7mo agoPhew.
- deleted 7mo ago[deleted]
- alin23 7mo agomacOS 26 has to be the most breaking version so far, its problems and intended breaking changes making my app dev life so hard this year. Just to name a few: - Reference Presets no longer allow setting arbitrary SDR nits, making it impossible to natively unlock 1600nits of brightness on MacBook Pros or 2000nits on Studio Display XDR which breaks my Lunar app [0] (this seems to be intended, no idea what hurt Apple that they had to block this under SIP) - The orange microphone dot indicator and its very colored friends can no longer have their brightness changed for dimming them, which made my YellowDot app useless [1] (I guess this is for privacy, I still think this could have a setting guarded under TouchID like Accessibility Permissions works) - Floating non-titled windows don't accept mouse events (thankfully this got fixed) [2] - Gamma table changes don't work on MacBook Neo and M5 Pro/Max which breaks Sub-zero Dimming and dimming external monitors that don't support DDC (thankfully, Apple is looking into it) [3] - The resizing area thing on very rounded windows which drives everyone nuts, I had to add custom resize handlers to some of my windows - The `com.apple.SwiftUI.Drag-` temporary file paths that get generated for any file that gets dragged from a drag&drop handler which makes it impossible to get to the original file when dragging images from Clop [4] or file shelf apps like Yoink, Dropover etc. - NSImage returning different pixel count for .size than what the image actually has, breaking workflows that depended on that to determine the image DPI [0] https://lunar.fyi/#xdr https://lunar.fyi/#xdr [1] https://github.com/FuzzyIdeas/YellowDot/issues/18 https://github.com/FuzzyIdeas/YellowDot/issues/18 [2] https://developer.apple.com/forums//thread/814798 https://developer.apple.com/forums//thread/814798 [3] https://developer.apple.com/forums/thread/819331 https://developer.apple.com/forums/thread/819331 [4] https://lowtechguys.com/clop https://lowtechguys.com/clop
- reaperducer 7mo ago[flagged]
- alin23 7mo agoDoes everything need to be snark on HN now? What is happening with this place? Those are valid problems affecting real people. For some are just missing conveniences, for others they are full on accessibility issues.
- nickdothutton 7mo agoAh great another reason to add to the many reasons not to use this OS. Semi serious question, is Apple looking to dump its existing customer base for a new, perhaps consumer not pro-sumer one?
- butILoveLife 7mo agoWait... someone is under the impression that Apple was ever good to its customers? I thought we all just dealt with the overpriced hardware, the prisons, the control, that they are a US company that gives away data to the government(PRISM), has weak security(Pegasus), lies about hardware issues(butterfly keyboard and holding your phone wrong), deceptive marketing... All so we can compile iOS apps. If you arent compiling iOS apps... Do you not know about Fedora? Ofc Windows sucks, but we have Fedora.
- Hizonner 7mo agoSeems bad that people feel forced to use GitHub to talk about Apple's bugs.
- bpicolo 7mo agoAnother funny thing about Mac networking. There's a game I play (Old School Runescape) that does network ticks every .6s. Mac does some sort of aggressive optimization on the network hardware/software, so network this infrequent doesn't keep the layers "hot", and you end up getting delayed ticks regularly, meaning you learn what should be happening in the game .2-.5s late. This optimization for (I assume) battery life makes the software not work as intended. Playing anything that streams, like video, or triggering TCP connections (e.g. curl) at a more frequent clip while the game is running fixes the problem. No way other than hacks that I've found to fix it, and I have no idea how you could report this to the right team at Apple to get it actually fixed.
- speff 7mo agoVery interesting. I play RS3 and made a helper tool[0] for tracking ticks. I noticed increased jitter on my MBair (~50-150ms) compared to Windows, but I chalked it up to the air being on a wifi connection. I wonder if your explanation's the real reason. [0]: https://files.catbox.moe/5n09lg.webm https://files.catbox.moe/5n09lg.webm
- kccqzy 7mo agoThat sounds like the timer coalescing feature introduced in OS X 10.9 I think.
- thedougd 7mo agoI had to abandon Apple MacOS container because it has so many issues with networking and DNS. I'm looking forward to try it again if they can get it fixed. https://github.com/apple/container/issues?q=is%3Aissue%20state%3Aopen%20dns https://github.com/apple/container/issues?q=is%3Aissue%20sta...
- bdcravens 7mo ago> The only reliable workaround is to add entries manually to /etc/hosts, which bypasses mDNSResponder entirely. This is impractical for dynamic use cases (e.g. Docker container DNS, where host entries change frequently) and requires sudo for every change. I suppose I'm lazy - I've always used /etc/hosts, but then again, I've never had use cases like those mentioned in the linked gist.
- JimmaDaRustla 7mo agoAgain? This happened like 6 or 7 years ago. I had so many issues with macOS in the few years I was forced to use a MacBook that I refused to use it. Not surprised to see this stuff still happening.
- cardsstacked47 7mo ago[dead]
- hnarn 7mo agoIf Asahi had the same battery life and performance as MacOS there is zero chance I would be running MacOS.
- cromka 7mo agoIt does. I am getting 8-10 hours on my M1 Air.
- chillpenguin 7mo agoI'm glad to find out it's not just me! My homelab has a lot of domains on .home.arpa, and I was getting issues related to this.
- kandros 7mo agoI still want to believe macOS 26 was vibe coded with Apple Intelligence and siri. Makes it easier to digest daily use
- rusakov-field 7mo agoI don't know , I like macOS, mainly that zsh is readily available and I can (almost) do anything I can do on a linux box in a personal computer.
- irusensei 7mo agoI never knew about this feature but it's so cool and I wish I knew it earlier. Sadly it seems features like these are being left to rot in MacOS because it's not what the average normie uses.
- pfortuny 7mo agoLo and behold, just FYI. Trying to help.
- wsesamemr55 7mo ago[dead]
- temp0826 7mo agoAfaik ".internal" isn't reserved/defined anywhere, it's just a convention some people/devices use, and doesn't have anything to do with the root cause here (a custom resolve.conf or whatever it is called in macos changing after an update), no?
- nh2 7mo agoNo. It is reserved. https://www.icann.org/en/board-activities-and-meetings/materials/approved-resolutions-special-meeting-of-the-icann-board-29-07-2024-en#section2.a https://www.icann.org/en/board-activities-and-meetings/mater... A look on Google or Wikipedia would also clear that up faster than I can type this response https://en.wikipedia.org/wiki/.internal https://en.wikipedia.org/wiki/.internal
- nguyenvuhuyen62 7mo ago[dead]
- justinsaccount 7mo ago> none of my dockers Containers ran using docker are called containers, not dockers.
- patabyte 7mo agoInteresting - I run a nearly identical set, with many TLDs configured in `/etc/resolver/X` and dnsmasq handling the resolve and I have not had a single issue. the resolver confs all contain this content: # /etc/resolver/example-private nameserver: 127.0.0.1 domain example-private I noticed in the author's bug report they do not include `domain`, which is documented in `man 5 resolver` as: # The domain directive is only necessary, if your local # router advertises something like localdomain and you have # set up your hostnames via an external domain. In the real world though, I've found the `domain` setting to be required nearly every time. I wonder if adding it will resolve the issue?
- samgranieri 7mo agoI used to use dnsmasq and etc/resolvers for stuff like dot dev or dit whatever back in the day. These days I’m just using Caddy to do ..localhost for my web dev and it works like a charm. This is exceptionally sloppy on Apple’s part.
- PixVerse_69 7mo ago[dead]
- AIinfoclip14 7mo ago[dead]
- eddie-wang 7mo ago[flagged]
- pvtmert 7mo agoI am pretty sure this will get fixed as Amazon had depended on this feature to resolve internal domains through the ACME managed openvpn-service. Rather than overriding global DNS settings which may break on certain hotspot configurations.
- adamamyl 6mo ago"The long-established behavior of encrypted DNS protocol settings from a profile overriding non-VPN domain-specific DNS settings has been confirmed internally from macOS 15.7.1 to macOS 26.5.: "You will continute [sic] to run into the behavior of Quad9 DoT overriding the per-domain DNS settings so long as the profile is installed." — there we have it from "privacy friendly" (whilst sneaking out age checks) Apple.