Different RPZ behavior for IDN domains between BIND 9.20.23 and 9.20.26

Sachchidanand Upadhyay via bind-users <[email protected]> Fri, 24 Jul 2026 16:33:15 +0530
Newsgroups gmane.network.dns.bind.user
Message-ID <[email protected]>
--===============8626190499375644034==
Content-Type: multipart/alternative; 
	boundary="----=_Part_337307_1549346295.1784890995003"

------=_Part_337307_1549346295.1784890995003
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 7bit

Hello, 



I am observing different RPZ behavior for an IDN domain after upgrading from BIND 9.20.23 to 9.20.26 and would appreciate any guidance.



Environment:



BIND 9.20.23: Works as expected

BIND 9.20.26: Fails

The BIND configuration and RPZ configuration are identical on both versions.



The queried domain is an IDN. The domain itself is not present in the RPZ, yet BIND 9.20.26 logs an "RPZ QNAME rewrite failed" message for the query, while the same query is resolved successfully on BIND 9.20.23 using the same configuration. Below are the logs



24-Jul-2026 15:37:16.288 query-errors: debug 3: client @0x7fd386c93800 <client_IP>#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c): view internal: rpz QNAME rewrite xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c stop on qresult in rpz_rewrite(): failure

24-Jul-2026 15:37:16.288 query-errors: info: client @0x7fd386c93800 <client_IP>#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c): view internal: query failed (failure) for xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c/IN/A at query.c:7651

24-Jul-2026 15:37:16.288 query-errors: debug 4: fetch completed for xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c/A in 0.042000: failure/deadlock found [domain:xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c,referral:1,restart:2,qrysent:4,timeout:0,lame:0,quota:0,neterr:0,badresp:0,adberr:0,findfail:0,valfail:4]



If anyone has encountered this issue before or is aware of a workaround or solution, I would be grateful for your suggestions.



Regards,

Sachchidanand Upadhyay
------=_Part_337307_1549346295.1784890995003
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head>=
<meta content=3D"text/html;charset=3DUTF-8" http-equiv=3D"Content-Type"></h=
ead><body ><div style=3D"font-family: Verdana, Arial, Helvetica, sans-serif=
; font-size: 10pt;"><div>Hello, <br></div><div><br></div><div>I am observin=
g different RPZ behavior for an IDN domain after upgrading from BIND 9.20.2=
3 to 9.20.26 and would appreciate any guidance.<br></div><div><br></div><di=
v>Environment:<br></div><div><br></div><div>BIND 9.20.23: Works as expected=
<br></div><div>BIND 9.20.26: Fails<br></div><div>The BIND configuration and=
 RPZ configuration are identical on both versions.<br></div><div><br></div>=
<div>The queried domain is an IDN. The domain itself is not present in the =
RPZ, yet BIND 9.20.26 logs an "RPZ QNAME rewrite failed" message for the qu=
ery, while the same query is resolved successfully on BIND 9.20.23 using th=
e same configuration. Below are the logs<br></div><div><br></div><div>24-Ju=
l-2026 15:37:16.288 query-errors: debug 3: client @0x7fd386c93800 &lt;clien=
t_IP&gt;#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6=
a.xn--h2brj9c): view internal: rpz QNAME rewrite xn--i1bn6adp9emg4dcbcajdef=
lxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c stop on qresult in rpz_rewri=
te(): failure<br></div><div>24-Jul-2026 15:37:16.288 query-errors: info: cl=
ient @0x7fd386c93800 &lt;client_IP&gt;#41889 (xn--i1bn6adp9emg4dcbcajdeflxp=
1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c): view internal: query failed (=
failure) for xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.x=
n--h2brj9c/IN/A at query.c:7651<br></div><div>24-Jul-2026 15:37:16.288 quer=
y-errors: debug 4: fetch completed for xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7=
bt10abief.xn--11b7cb3a6a.xn--h2brj9c/A in 0.042000: failure/deadlock found =
[domain:xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2=
brj9c,referral:1,restart:2,qrysent:4,timeout:0,lame:0,quota:0,neterr:0,badr=
esp:0,adberr:0,findfail:0,valfail:4]<br></div><div><br></div><div>If anyone=
 has encountered this issue before or is aware of a workaround or solution,=
 I would be grateful for your suggestions.<br></div><div><br></div><div>Reg=
ards,<br></div><div>Sachchidanand Upadhyay<br></div><div><br></div></div><b=
r></body></html>
------=_Part_337307_1549346295.1784890995003--


--===============8626190499375644034==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list.

--===============8626190499375644034==--