Re: Different RPZ behavior for IDN domains between BIND 9.20.23 and 9.20.26

Ondřej Surý <[email protected]> Fri, 24 Jul 2026 13:42:09 +0200
Newsgroups gmane.network.dns.bind.user
Message-ID <[email protected]>
--===============1378076244128253920==
Content-Type: multipart/alternative; boundary=Apple-Mail-E3CB1125-80B1-45D8-8A35-FD728150A52F
Content-Transfer-Encoding: 7bit


--Apple-Mail-E3CB1125-80B1-45D8-8A35-FD728150A52F
Content-Type: text/plain;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

What is the rule to trigger this? It is hard to debug without seeing the exa=
ct ruleset that=E2=80=99s being used.

Ondrej
--
Ond=C5=99ej Sur=C3=BD (He/Him)
[email protected]

ADHD brain at work: I sometimes lose track of my inbox. Please feel free to s=
end a gentle nudge if you're waiting on a reply!

My working hours and your working hours may be different. Please do not feel=
 obligated to reply outside your normal working hours.

> On 24. 7. 2026, at 13:04, Sachchidanand Upadhyay via bind-users <bind-user=
[email protected]> wrote:
>=20
> =EF=BB=BF
> Hello,
>=20
> I am observing different RPZ behavior for an IDN domain after upgrading fr=
om BIND 9.20.23 to 9.20.26 and would appreciate any guidance.
>=20
> Environment:
>=20
> BIND 9.20.23: Works as expected
> BIND 9.20.26: Fails
> The BIND configuration and RPZ configuration are identical on both version=
s.
>=20
> The queried domain is an IDN. The domain itself is not present in the RPZ,=
 yet BIND 9.20.26 logs an "RPZ QNAME rewrite failed" message for the query, w=
hile the same query is resolved successfully on BIND 9.20.23 using the same c=
onfiguration. Below are the logs
>=20
> 24-Jul-2026 15:37:16.288 query-errors: debug 3: client @0x7fd386c93800 <cl=
ient_IP>#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a=
.xn--h2brj9c): view internal: rpz QNAME rewrite xn--i1bn6adp9emg4dcbcajdeflx=
p1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c stop on qresult in rpz_rewrite(=
): failure
> 24-Jul-2026 15:37:16.288 query-errors: info: client @0x7fd386c93800 <clien=
t_IP>#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn=
--h2brj9c): view internal: query failed (failure) for xn--i1bn6adp9emg4dcbca=
jdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c/IN/A at query.c:7651
> 24-Jul-2026 15:37:16.288 query-errors: debug 4: fetch completed for xn--i1=
bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c/A in 0.04=
2000: failure/deadlock found [domain:xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt1=
0abief.xn--11b7cb3a6a.xn--h2brj9c,referral:1,restart:2,qrysent:4,timeout:0,l=
ame:0,quota:0,neterr:0,badresp:0,adberr:0,findfail:0,valfail:4]
>=20
> If anyone has encountered this issue before or is aware of a workaround or=
 solution, I would be grateful for your suggestions.
>=20
> Regards,
> Sachchidanand Upadhyay
>=20
>=20
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe fro=
m this list.

--Apple-Mail-E3CB1125-80B1-45D8-8A35-FD728150A52F
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html class=3D"apple-mail-supports-explicit-dark-mode"><head><meta http-equi=
v=3D"content-type" content=3D"text/html; charset=3Dutf-8"></head><body dir=3D=
"auto">What is the rule to trigger this? It is hard to debug without seeing t=
he exact ruleset that=E2=80=99s being used.<div><br></div><div>Ondrej<br id=3D=
"lineBreakAtBeginningOfSignature"><div dir=3D"ltr"><span style=3D"background=
-color: rgba(255, 255, 255, 0);">--<br>Ond=C5=99ej Sur=C3=BD (He/Him)<br><sp=
an dir=3D"ltr">[email protected]</span><br><br>ADHD brain at work: I sometimes l=
ose track of my inbox. Please feel free to send a gentle nudge if you're wai=
ting on a reply!<br><br>My working hours and your working hours may be diffe=
rent. Please do not feel obligated to reply outside your normal working hour=
s.</span><br style=3D"font-size: 17px;"></div><div dir=3D"ltr"><br><blockquo=
te type=3D"cite">On 24. 7. 2026, at 13:04, Sachchidanand Upadhyay via bind-u=
sers &lt;[email protected]&gt; wrote:<br><br></blockquote></div><bloc=
kquote type=3D"cite"><div dir=3D"ltr">=EF=BB=BF<meta content=3D"text/html;ch=
arset=3DUTF-8" http-equiv=3D"Content-Type"><div style=3D"font-family: Verdan=
a, Arial, Helvetica, sans-serif; font-size: 10pt;"><div>Hello, <br></div><di=
v><br></div><div>I am observing different RPZ behavior for an IDN domain aft=
er upgrading from BIND 9.20.23 to 9.20.26 and would appreciate any guidance.=
<br></div><div><br></div><div>Environment:<br></div><div><br></div><div>BIND=
 9.20.23: Works as expected<br></div><div>BIND 9.20.26: Fails<br></div><div>=
The BIND configuration and RPZ configuration are identical on both versions.=
<br></div><div><br></div><div>The queried domain is an IDN. The domain itsel=
f is not present in the RPZ, yet BIND 9.20.26 logs an "RPZ QNAME rewrite fai=
led" message for the query, while the same query is resolved successfully on=
 BIND 9.20.23 using the same configuration. Below are the logs<br></div><div=
><br></div><div>24-Jul-2026 15:37:16.288 query-errors: debug 3: client @0x7f=
d386c93800 &lt;client_IP&gt;#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10=
abief.xn--11b7cb3a6a.xn--h2brj9c): view internal: rpz QNAME rewrite xn--i1bn=
6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c stop on qre=
sult in rpz_rewrite(): failure<br></div><div>24-Jul-2026 15:37:16.288 query-=
errors: info: client @0x7fd386c93800 &lt;client_IP&gt;#41889 (xn--i1bn6adp9e=
mg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c): view internal: q=
uery failed (failure) for xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--=
11b7cb3a6a.xn--h2brj9c/IN/A at query.c:7651<br></div><div>24-Jul-2026 15:37:=
16.288 query-errors: debug 4: fetch completed for xn--i1bn6adp9emg4dcbcajdef=
lxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c/A in 0.042000: failure/deadlo=
ck found [domain:xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6=
a.xn--h2brj9c,referral:1,restart:2,qrysent:4,timeout:0,lame:0,quota:0,neterr=
:0,badresp:0,adberr:0,findfail:0,valfail:4]<br></div><div><br></div><div>If a=
nyone has encountered this issue before or is aware of a workaround or solut=
ion, I would be grateful for your suggestions.<br></div><div><br></div><div>=
Regards,<br></div><div>Sachchidanand Upadhyay<br></div><div><br></div></div>=
<br><span>-- </span><br><span>Visit https://lists.isc.org/mailman/listinfo/b=
ind-users to unsubscribe from this list.</span><br></div></blockquote></div>=
</body></html>=

--Apple-Mail-E3CB1125-80B1-45D8-8A35-FD728150A52F--

--===============1378076244128253920==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list.

--===============1378076244128253920==--