Re: Different RPZ behavior for IDN domains between BIND 9.20.23 and 9.20.26
Ondřej Surý <[email protected]> Fri, 24 Jul 2026 13:42:09 +0200
| Newsgroups | gmane.network.dns.bind.user |
|---|---|
| Message-ID | <[email protected]> |
--===============1378076244128253920== Content-Type: multipart/alternative; boundary=Apple-Mail-E3CB1125-80B1-45D8-8A35-FD728150A52F Content-Transfer-Encoding: 7bit --Apple-Mail-E3CB1125-80B1-45D8-8A35-FD728150A52F Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable What is the rule to trigger this? It is hard to debug without seeing the exa= ct ruleset that=E2=80=99s being used. Ondrej -- Ond=C5=99ej Sur=C3=BD (He/Him) [email protected] ADHD brain at work: I sometimes lose track of my inbox. Please feel free to s= end a gentle nudge if you're waiting on a reply! My working hours and your working hours may be different. Please do not feel= obligated to reply outside your normal working hours. > On 24. 7. 2026, at 13:04, Sachchidanand Upadhyay via bind-users <bind-user= [email protected]> wrote: >=20 > =EF=BB=BF > Hello, >=20 > I am observing different RPZ behavior for an IDN domain after upgrading fr= om BIND 9.20.23 to 9.20.26 and would appreciate any guidance. >=20 > Environment: >=20 > BIND 9.20.23: Works as expected > BIND 9.20.26: Fails > The BIND configuration and RPZ configuration are identical on both version= s. >=20 > The queried domain is an IDN. The domain itself is not present in the RPZ,= yet BIND 9.20.26 logs an "RPZ QNAME rewrite failed" message for the query, w= hile the same query is resolved successfully on BIND 9.20.23 using the same c= onfiguration. Below are the logs >=20 > 24-Jul-2026 15:37:16.288 query-errors: debug 3: client @0x7fd386c93800 <cl= ient_IP>#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a= .xn--h2brj9c): view internal: rpz QNAME rewrite xn--i1bn6adp9emg4dcbcajdeflx= p1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c stop on qresult in rpz_rewrite(= ): failure > 24-Jul-2026 15:37:16.288 query-errors: info: client @0x7fd386c93800 <clien= t_IP>#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn= --h2brj9c): view internal: query failed (failure) for xn--i1bn6adp9emg4dcbca= jdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c/IN/A at query.c:7651 > 24-Jul-2026 15:37:16.288 query-errors: debug 4: fetch completed for xn--i1= bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c/A in 0.04= 2000: failure/deadlock found [domain:xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt1= 0abief.xn--11b7cb3a6a.xn--h2brj9c,referral:1,restart:2,qrysent:4,timeout:0,l= ame:0,quota:0,neterr:0,badresp:0,adberr:0,findfail:0,valfail:4] >=20 > If anyone has encountered this issue before or is aware of a workaround or= solution, I would be grateful for your suggestions. >=20 > Regards, > Sachchidanand Upadhyay >=20 >=20 > -- > Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe fro= m this list. --Apple-Mail-E3CB1125-80B1-45D8-8A35-FD728150A52F Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html class=3D"apple-mail-supports-explicit-dark-mode"><head><meta http-equi= v=3D"content-type" content=3D"text/html; charset=3Dutf-8"></head><body dir=3D= "auto">What is the rule to trigger this? It is hard to debug without seeing t= he exact ruleset that=E2=80=99s being used.<div><br></div><div>Ondrej<br id=3D= "lineBreakAtBeginningOfSignature"><div dir=3D"ltr"><span style=3D"background= -color: rgba(255, 255, 255, 0);">--<br>Ond=C5=99ej Sur=C3=BD (He/Him)<br><sp= an dir=3D"ltr">[email protected]</span><br><br>ADHD brain at work: I sometimes l= ose track of my inbox. Please feel free to send a gentle nudge if you're wai= ting on a reply!<br><br>My working hours and your working hours may be diffe= rent. Please do not feel obligated to reply outside your normal working hour= s.</span><br style=3D"font-size: 17px;"></div><div dir=3D"ltr"><br><blockquo= te type=3D"cite">On 24. 7. 2026, at 13:04, Sachchidanand Upadhyay via bind-u= sers <[email protected]> wrote:<br><br></blockquote></div><bloc= kquote type=3D"cite"><div dir=3D"ltr">=EF=BB=BF<meta content=3D"text/html;ch= arset=3DUTF-8" http-equiv=3D"Content-Type"><div style=3D"font-family: Verdan= a, Arial, Helvetica, sans-serif; font-size: 10pt;"><div>Hello, <br></div><di= v><br></div><div>I am observing different RPZ behavior for an IDN domain aft= er upgrading from BIND 9.20.23 to 9.20.26 and would appreciate any guidance.= <br></div><div><br></div><div>Environment:<br></div><div><br></div><div>BIND= 9.20.23: Works as expected<br></div><div>BIND 9.20.26: Fails<br></div><div>= The BIND configuration and RPZ configuration are identical on both versions.= <br></div><div><br></div><div>The queried domain is an IDN. The domain itsel= f is not present in the RPZ, yet BIND 9.20.26 logs an "RPZ QNAME rewrite fai= led" message for the query, while the same query is resolved successfully on= BIND 9.20.23 using the same configuration. Below are the logs<br></div><div= ><br></div><div>24-Jul-2026 15:37:16.288 query-errors: debug 3: client @0x7f= d386c93800 <client_IP>#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10= abief.xn--11b7cb3a6a.xn--h2brj9c): view internal: rpz QNAME rewrite xn--i1bn= 6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c stop on qre= sult in rpz_rewrite(): failure<br></div><div>24-Jul-2026 15:37:16.288 query-= errors: info: client @0x7fd386c93800 <client_IP>#41889 (xn--i1bn6adp9e= mg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c): view internal: q= uery failed (failure) for xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--= 11b7cb3a6a.xn--h2brj9c/IN/A at query.c:7651<br></div><div>24-Jul-2026 15:37:= 16.288 query-errors: debug 4: fetch completed for xn--i1bn6adp9emg4dcbcajdef= lxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c/A in 0.042000: failure/deadlo= ck found [domain:xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6= a.xn--h2brj9c,referral:1,restart:2,qrysent:4,timeout:0,lame:0,quota:0,neterr= :0,badresp:0,adberr:0,findfail:0,valfail:4]<br></div><div><br></div><div>If a= nyone has encountered this issue before or is aware of a workaround or solut= ion, I would be grateful for your suggestions.<br></div><div><br></div><div>= Regards,<br></div><div>Sachchidanand Upadhyay<br></div><div><br></div></div>= <br><span>-- </span><br><span>Visit https://lists.isc.org/mailman/listinfo/b= ind-users to unsubscribe from this list.</span><br></div></blockquote></div>= </body></html>= --Apple-Mail-E3CB1125-80B1-45D8-8A35-FD728150A52F-- --===============1378076244128253920== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list. --===============1378076244128253920==--