Different RPZ behavior for IDN domains between BIND 9.20.23 and 9.20.26
Sachchidanand Upadhyay via bind-users <[email protected]> Fri, 24 Jul 2026 16:33:15 +0530
| Newsgroups | gmane.network.dns.bind.user |
|---|---|
| Message-ID | <[email protected]> |
--===============8626190499375644034== Content-Type: multipart/alternative; boundary="----=_Part_337307_1549346295.1784890995003" ------=_Part_337307_1549346295.1784890995003 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: 7bit Hello, I am observing different RPZ behavior for an IDN domain after upgrading from BIND 9.20.23 to 9.20.26 and would appreciate any guidance. Environment: BIND 9.20.23: Works as expected BIND 9.20.26: Fails The BIND configuration and RPZ configuration are identical on both versions. The queried domain is an IDN. The domain itself is not present in the RPZ, yet BIND 9.20.26 logs an "RPZ QNAME rewrite failed" message for the query, while the same query is resolved successfully on BIND 9.20.23 using the same configuration. Below are the logs 24-Jul-2026 15:37:16.288 query-errors: debug 3: client @0x7fd386c93800 <client_IP>#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c): view internal: rpz QNAME rewrite xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c stop on qresult in rpz_rewrite(): failure 24-Jul-2026 15:37:16.288 query-errors: info: client @0x7fd386c93800 <client_IP>#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c): view internal: query failed (failure) for xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c/IN/A at query.c:7651 24-Jul-2026 15:37:16.288 query-errors: debug 4: fetch completed for xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c/A in 0.042000: failure/deadlock found [domain:xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c,referral:1,restart:2,qrysent:4,timeout:0,lame:0,quota:0,neterr:0,badresp:0,adberr:0,findfail:0,valfail:4] If anyone has encountered this issue before or is aware of a workaround or solution, I would be grateful for your suggestions. Regards, Sachchidanand Upadhyay ------=_Part_337307_1549346295.1784890995003 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head>= <meta content=3D"text/html;charset=3DUTF-8" http-equiv=3D"Content-Type"></h= ead><body ><div style=3D"font-family: Verdana, Arial, Helvetica, sans-serif= ; font-size: 10pt;"><div>Hello, <br></div><div><br></div><div>I am observin= g different RPZ behavior for an IDN domain after upgrading from BIND 9.20.2= 3 to 9.20.26 and would appreciate any guidance.<br></div><div><br></div><di= v>Environment:<br></div><div><br></div><div>BIND 9.20.23: Works as expected= <br></div><div>BIND 9.20.26: Fails<br></div><div>The BIND configuration and= RPZ configuration are identical on both versions.<br></div><div><br></div>= <div>The queried domain is an IDN. The domain itself is not present in the = RPZ, yet BIND 9.20.26 logs an "RPZ QNAME rewrite failed" message for the qu= ery, while the same query is resolved successfully on BIND 9.20.23 using th= e same configuration. Below are the logs<br></div><div><br></div><div>24-Ju= l-2026 15:37:16.288 query-errors: debug 3: client @0x7fd386c93800 <clien= t_IP>#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6= a.xn--h2brj9c): view internal: rpz QNAME rewrite xn--i1bn6adp9emg4dcbcajdef= lxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c stop on qresult in rpz_rewri= te(): failure<br></div><div>24-Jul-2026 15:37:16.288 query-errors: info: cl= ient @0x7fd386c93800 <client_IP>#41889 (xn--i1bn6adp9emg4dcbcajdeflxp= 1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c): view internal: query failed (= failure) for xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.x= n--h2brj9c/IN/A at query.c:7651<br></div><div>24-Jul-2026 15:37:16.288 quer= y-errors: debug 4: fetch completed for xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7= bt10abief.xn--11b7cb3a6a.xn--h2brj9c/A in 0.042000: failure/deadlock found = [domain:xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2= brj9c,referral:1,restart:2,qrysent:4,timeout:0,lame:0,quota:0,neterr:0,badr= esp:0,adberr:0,findfail:0,valfail:4]<br></div><div><br></div><div>If anyone= has encountered this issue before or is aware of a workaround or solution,= I would be grateful for your suggestions.<br></div><div><br></div><div>Reg= ards,<br></div><div>Sachchidanand Upadhyay<br></div><div><br></div></div><b= r></body></html> ------=_Part_337307_1549346295.1784890995003-- --===============8626190499375644034== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list. --===============8626190499375644034==--