Re: Different RPZ behavior for IDN domains between BIND 9.20.23 and 9.20.26

Sachchidanand Upadhyay via bind-users <[email protected]> Sat, 25 Jul 2026 12:58:07 +0530
Newsgroups gmane.network.dns.bind.user
Message-ID <[email protected]>
--===============0613854745701137796==
Content-Type: multipart/alternative; 
	boundary="----=_Part_560719_1869994493.1784964487294"

------=_Part_560719_1869994493.1784964487294
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi Ondrej,



Thank you for your response.=20



Each listed domain in the RPZ is rewritten via a CNAME to a single policy d=
omain, and that policy domain has an A record in its authoritative zone.



For example:



bad-domain1.example.=C2=A0=C2=A0=C2=A0 CNAME=C2=A0=C2=A0=C2=A0 policy.examp=
le.net.

bad-domain2.example.=C2=A0=C2=A0=C2=A0 CNAME=C2=A0=C2=A0=C2=A0 policy.examp=
le.net.

bad-domain3.example.=C2=A0=C2=A0=C2=A0 CNAME=C2=A0=C2=A0=C2=A0 policy.examp=
le.net.

bad-domain4.example.=C2=A0=C2=A0=C2=A0 CNAME=C2=A0=C2=A0=C2=A0 policy.examp=
le.net.



and in the authoritative zone:



policy.example.net.=C2=A0=C2=A0=C2=A0=C2=A0 A=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0 <IP address>





The same RPZ ruleset works correctly on BIND 9.20.23, while BIND 9.20.26 lo=
gs the rewrite failure for the same query.



Regards,

Sachchidanand Upadhyay












From: Ond=C5=99ej Sur=C3=BD <[email protected]>
To: "Sachchidanand Upadhyay"<[email protected]>
Cc: "bind-users"<[email protected]>
Date: Fri, 24 Jul 2026 17:12:09 +0530
Subject: Re: Different RPZ behavior for IDN domains between BIND 9.20.23 an=
d 9.20.26



What is the rule to trigger this? It is hard to debug without seeing the ex=
act ruleset that=E2=80=99s being used.

Ondrej
--
Ond=C5=99ej Sur=C3=BD (He/Him)
mailto:[email protected]=20

ADHD brain at work: I sometimes lose track of my inbox. Please feel free to=
 send a gentle nudge if you're waiting on a reply!

My working hours and your working hours may be different. Please do not fee=
l obligated to reply outside your normal working hours.


On 24. 7. 2026, at 13:04, Sachchidanand Upadhyay via bind-users < mailto:bi=
[email protected] > wrote:



=EF=BB=BFHello,=20



I am observing different RPZ behavior for an IDN domain after upgrading fro=
m BIND 9.20.23 to 9.20.26 and would appreciate any guidance.



Environment:



BIND 9.20.23: Works as expected

BIND 9.20.26: Fails

The BIND configuration and RPZ configuration are identical on both versions=
.



The queried domain is an IDN. The domain itself is not present in the RPZ, =
yet BIND 9.20.26 logs an "RPZ QNAME rewrite failed" message for the query, =
while the same query is resolved successfully on BIND 9.20.23 using the sam=
e configuration. Below are the logs



24-Jul-2026 15:37:16.288 query-errors: debug 3: client @0x7fd386c93800 <cli=
ent_IP>#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a=
.xn--h2brj9c): view internal: rpz QNAME rewrite xn--i1bn6adp9emg4dcbcajdefl=
xp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c stop on qresult in rpz_rewrit=
e(): failure

24-Jul-2026 15:37:16.288 query-errors: info: client @0x7fd386c93800 <client=
_IP>#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn=
--h2brj9c): view internal: query failed (failure) for xn--i1bn6adp9emg4dcbc=
ajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c/IN/A at query.c:7651

24-Jul-2026 15:37:16.288 query-errors: debug 4: fetch completed for xn--i1b=
n6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c/A in 0.04=
2000: failure/deadlock found [domain:xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt=
10abief.xn--11b7cb3a6a.xn--h2brj9c,referral:1,restart:2,qrysent:4,timeout:0=
,lame:0,quota:0,neterr:0,badresp:0,adberr:0,findfail:0,valfail:4]



If anyone has encountered this issue before or is aware of a workaround or =
solution, I would be grateful for your suggestions.



Regards,

Sachchidanand Upadhyay





--=20
Visit https://lists.isc.org/mailman/listinfo/bind-users  to unsubscribe fro=
m this list.
------=_Part_560719_1869994493.1784964487294
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head>=
<meta content=3D"text/html;charset=3DUTF-8" http-equiv=3D"Content-Type"></h=
ead><body ><div style=3D"font-family: Verdana, Arial, Helvetica, sans-serif=
; font-size: 10pt;"><div>Hi Ondrej,<br></div><div><br></div><div>Thank you =
for your response. <br></div><div><br></div><div>Each listed domain in the =
RPZ is rewritten via a CNAME to a single policy domain, and that policy dom=
ain has an A record in its authoritative zone.<br></div><div><br></div><div=
>For example:<br></div><div><br></div><div>bad-domain1.example.&nbsp;&nbsp;=
&nbsp; CNAME&nbsp;&nbsp;&nbsp; policy.example.net.<br></div><div>bad-domain=
2.example.&nbsp;&nbsp;&nbsp; CNAME&nbsp;&nbsp;&nbsp; policy.example.net.<br=
></div><div>bad-domain3.example.&nbsp;&nbsp;&nbsp; CNAME&nbsp;&nbsp;&nbsp; =
policy.example.net.<br></div><div>bad-domain4.example.&nbsp;&nbsp;&nbsp; CN=
AME&nbsp;&nbsp;&nbsp; policy.example.net.<br></div><div><br></div><div>and =
in the authoritative zone:<br></div><div><br></div><div>policy.example.net.=
&nbsp;&nbsp;&nbsp;&nbsp; A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;IP=
 address&gt;<br></div><div><br></div><div><br></div><div>The same RPZ rules=
et works correctly on BIND 9.20.23, while BIND 9.20.26 logs the rewrite fai=
lure for the same query.<br></div><div><br></div><div>Regards,<br></div><di=
v>Sachchidanand Upadhyay</div><div><br></div><div><br></div><div><br></div>=
<div><br></div><div class=3D"zmail_extra_hr" style=3D"border-top: 1px solid=
 rgb(204, 204, 204); height: 0px; margin-top: 10px; margin-bottom: 10px; li=
ne-height: 0px;"><br></div><div class=3D"zmail_extra" data-zbluepencil-igno=
re=3D"true"><div><br></div><div id=3D"Zm-_Id_-Sgn1">From: Ond=C5=99ej Sur=
=C3=BD &lt;[email protected]&gt;<br>To: "Sachchidanand Upadhyay"&lt;supadhyay@=
nkn.in&gt;<br>Cc: "bind-users"&lt;[email protected]&gt;<br>Date: Fri=
, 24 Jul 2026 17:12:09 +0530<br>Subject: Re: Different RPZ behavior for IDN=
 domains between BIND 9.20.23 and 9.20.26<br></div><div><br></div><blockquo=
te style=3D"margin: 0px;" id=3D"blockquote_zmail"><div dir=3D"auto">What is=
 the rule to trigger this? It is hard to debug without seeing the exact rul=
eset that=E2=80=99s being used.<div><br></div><div>Ondrej<br id=3D"x_380161=
398lineBreakAtBeginningOfSignature"><div dir=3D"ltr"><span class=3D"highlig=
ht" style=3D"background-color:rgba(255, 255, 255, 0)">--<br>Ond=C5=99ej Sur=
=C3=BD (He/Him)<br><span dir=3D"ltr"><a target=3D"_blank" href=3D"mailto:on=
[email protected]">[email protected]</a></span><br><br>ADHD brain at work: I someti=
mes lose track of my inbox. Please feel free to send a gentle nudge if you'=
re waiting on a reply!<br><br>My working hours and your working hours may b=
e different. Please do not feel obligated to reply outside your normal work=
ing hours.</span><br style=3D"font-size: 17px"></div><div dir=3D"ltr"><br><=
blockquote>On 24. 7. 2026, at 13:04, Sachchidanand Upadhyay via bind-users =
&lt;<a target=3D"_blank" href=3D"mailto:[email protected]">bind-user=
[email protected]</a>&gt; wrote:<br><br></blockquote></div><blockquote><div d=
ir=3D"ltr">=EF=BB=BF<div style=3D"font-family: Verdana, Arial, Helvetica, s=
ans-serif; font-size: 10pt"><div>Hello, <br></div><div><br></div><div>I am =
observing different RPZ behavior for an IDN domain after upgrading from BIN=
D 9.20.23 to 9.20.26 and would appreciate any guidance.<br></div><div><br><=
/div><div>Environment:<br></div><div><br></div><div>BIND 9.20.23: Works as =
expected<br></div><div>BIND 9.20.26: Fails<br></div><div>The BIND configura=
tion and RPZ configuration are identical on both versions.<br></div><div><b=
r></div><div>The queried domain is an IDN. The domain itself is not present=
 in the RPZ, yet BIND 9.20.26 logs an "RPZ QNAME rewrite failed" message fo=
r the query, while the same query is resolved successfully on BIND 9.20.23 =
using the same configuration. Below are the logs<br></div><div><br></div><d=
iv>24-Jul-2026 15:37:16.288 query-errors: debug 3: client @0x7fd386c93800 &=
lt;client_IP&gt;#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--1=
1b7cb3a6a.xn--h2brj9c): view internal: rpz QNAME rewrite xn--i1bn6adp9emg4d=
cbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c stop on qresult in r=
pz_rewrite(): failure<br></div><div>24-Jul-2026 15:37:16.288 query-errors: =
info: client @0x7fd386c93800 &lt;client_IP&gt;#41889 (xn--i1bn6adp9emg4dcbc=
ajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c): view internal: query =
failed (failure) for xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7=
cb3a6a.xn--h2brj9c/IN/A at query.c:7651<br></div><div>24-Jul-2026 15:37:16.=
288 query-errors: debug 4: fetch completed for xn--i1bn6adp9emg4dcbcajdeflx=
p1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c/A in 0.042000: failure/deadloc=
k found [domain:xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6=
a.xn--h2brj9c,referral:1,restart:2,qrysent:4,timeout:0,lame:0,quota:0,neter=
r:0,badresp:0,adberr:0,findfail:0,valfail:4]<br></div><div><br></div><div>I=
f anyone has encountered this issue before or is aware of a workaround or s=
olution, I would be grateful for your suggestions.<br></div><div><br></div>=
<div>Regards,<br></div><div>Sachchidanand Upadhyay<br></div><div><br></div>=
</div><br><span>-- </span><br><span>Visit <a target=3D"_blank" href=3D"http=
s://lists.isc.org/mailman/listinfo/bind-users">https://lists.isc.org/mailma=
n/listinfo/bind-users</a> to unsubscribe from this list.</span><br></div></=
blockquote></div></div></blockquote></div><div><br></div></div><br></body><=
/html>
------=_Part_560719_1869994493.1784964487294--


--===============0613854745701137796==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list.

--===============0613854745701137796==--