Re: Different RPZ behavior for IDN domains between BIND 9.20.23 and 9.20.26
Sachchidanand Upadhyay via bind-users <[email protected]> Sat, 25 Jul 2026 12:58:07 +0530
| Newsgroups | gmane.network.dns.bind.user |
|---|---|
| Message-ID | <[email protected]> |
--===============0613854745701137796== Content-Type: multipart/alternative; boundary="----=_Part_560719_1869994493.1784964487294" ------=_Part_560719_1869994493.1784964487294 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi Ondrej, Thank you for your response.=20 Each listed domain in the RPZ is rewritten via a CNAME to a single policy d= omain, and that policy domain has an A record in its authoritative zone. For example: bad-domain1.example.=C2=A0=C2=A0=C2=A0 CNAME=C2=A0=C2=A0=C2=A0 policy.examp= le.net. bad-domain2.example.=C2=A0=C2=A0=C2=A0 CNAME=C2=A0=C2=A0=C2=A0 policy.examp= le.net. bad-domain3.example.=C2=A0=C2=A0=C2=A0 CNAME=C2=A0=C2=A0=C2=A0 policy.examp= le.net. bad-domain4.example.=C2=A0=C2=A0=C2=A0 CNAME=C2=A0=C2=A0=C2=A0 policy.examp= le.net. and in the authoritative zone: policy.example.net.=C2=A0=C2=A0=C2=A0=C2=A0 A=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0 <IP address> The same RPZ ruleset works correctly on BIND 9.20.23, while BIND 9.20.26 lo= gs the rewrite failure for the same query. Regards, Sachchidanand Upadhyay From: Ond=C5=99ej Sur=C3=BD <[email protected]> To: "Sachchidanand Upadhyay"<[email protected]> Cc: "bind-users"<[email protected]> Date: Fri, 24 Jul 2026 17:12:09 +0530 Subject: Re: Different RPZ behavior for IDN domains between BIND 9.20.23 an= d 9.20.26 What is the rule to trigger this? It is hard to debug without seeing the ex= act ruleset that=E2=80=99s being used. Ondrej -- Ond=C5=99ej Sur=C3=BD (He/Him) mailto:[email protected]=20 ADHD brain at work: I sometimes lose track of my inbox. Please feel free to= send a gentle nudge if you're waiting on a reply! My working hours and your working hours may be different. Please do not fee= l obligated to reply outside your normal working hours. On 24. 7. 2026, at 13:04, Sachchidanand Upadhyay via bind-users < mailto:bi= [email protected] > wrote: =EF=BB=BFHello,=20 I am observing different RPZ behavior for an IDN domain after upgrading fro= m BIND 9.20.23 to 9.20.26 and would appreciate any guidance. Environment: BIND 9.20.23: Works as expected BIND 9.20.26: Fails The BIND configuration and RPZ configuration are identical on both versions= . The queried domain is an IDN. The domain itself is not present in the RPZ, = yet BIND 9.20.26 logs an "RPZ QNAME rewrite failed" message for the query, = while the same query is resolved successfully on BIND 9.20.23 using the sam= e configuration. Below are the logs 24-Jul-2026 15:37:16.288 query-errors: debug 3: client @0x7fd386c93800 <cli= ent_IP>#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a= .xn--h2brj9c): view internal: rpz QNAME rewrite xn--i1bn6adp9emg4dcbcajdefl= xp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c stop on qresult in rpz_rewrit= e(): failure 24-Jul-2026 15:37:16.288 query-errors: info: client @0x7fd386c93800 <client= _IP>#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn= --h2brj9c): view internal: query failed (failure) for xn--i1bn6adp9emg4dcbc= ajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c/IN/A at query.c:7651 24-Jul-2026 15:37:16.288 query-errors: debug 4: fetch completed for xn--i1b= n6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c/A in 0.04= 2000: failure/deadlock found [domain:xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt= 10abief.xn--11b7cb3a6a.xn--h2brj9c,referral:1,restart:2,qrysent:4,timeout:0= ,lame:0,quota:0,neterr:0,badresp:0,adberr:0,findfail:0,valfail:4] If anyone has encountered this issue before or is aware of a workaround or = solution, I would be grateful for your suggestions. Regards, Sachchidanand Upadhyay --=20 Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe fro= m this list. ------=_Part_560719_1869994493.1784964487294 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head>= <meta content=3D"text/html;charset=3DUTF-8" http-equiv=3D"Content-Type"></h= ead><body ><div style=3D"font-family: Verdana, Arial, Helvetica, sans-serif= ; font-size: 10pt;"><div>Hi Ondrej,<br></div><div><br></div><div>Thank you = for your response. <br></div><div><br></div><div>Each listed domain in the = RPZ is rewritten via a CNAME to a single policy domain, and that policy dom= ain has an A record in its authoritative zone.<br></div><div><br></div><div= >For example:<br></div><div><br></div><div>bad-domain1.example. = CNAME policy.example.net.<br></div><div>bad-domain= 2.example. CNAME policy.example.net.<br= ></div><div>bad-domain3.example. CNAME = policy.example.net.<br></div><div>bad-domain4.example. CN= AME policy.example.net.<br></div><div><br></div><div>and = in the authoritative zone:<br></div><div><br></div><div>policy.example.net.= A <IP= address><br></div><div><br></div><div><br></div><div>The same RPZ rules= et works correctly on BIND 9.20.23, while BIND 9.20.26 logs the rewrite fai= lure for the same query.<br></div><div><br></div><div>Regards,<br></div><di= v>Sachchidanand Upadhyay</div><div><br></div><div><br></div><div><br></div>= <div><br></div><div class=3D"zmail_extra_hr" style=3D"border-top: 1px solid= rgb(204, 204, 204); height: 0px; margin-top: 10px; margin-bottom: 10px; li= ne-height: 0px;"><br></div><div class=3D"zmail_extra" data-zbluepencil-igno= re=3D"true"><div><br></div><div id=3D"Zm-_Id_-Sgn1">From: Ond=C5=99ej Sur= =C3=BD <[email protected]><br>To: "Sachchidanand Upadhyay"<supadhyay@= nkn.in><br>Cc: "bind-users"<[email protected]><br>Date: Fri= , 24 Jul 2026 17:12:09 +0530<br>Subject: Re: Different RPZ behavior for IDN= domains between BIND 9.20.23 and 9.20.26<br></div><div><br></div><blockquo= te style=3D"margin: 0px;" id=3D"blockquote_zmail"><div dir=3D"auto">What is= the rule to trigger this? It is hard to debug without seeing the exact rul= eset that=E2=80=99s being used.<div><br></div><div>Ondrej<br id=3D"x_380161= 398lineBreakAtBeginningOfSignature"><div dir=3D"ltr"><span class=3D"highlig= ht" style=3D"background-color:rgba(255, 255, 255, 0)">--<br>Ond=C5=99ej Sur= =C3=BD (He/Him)<br><span dir=3D"ltr"><a target=3D"_blank" href=3D"mailto:on= [email protected]">[email protected]</a></span><br><br>ADHD brain at work: I someti= mes lose track of my inbox. Please feel free to send a gentle nudge if you'= re waiting on a reply!<br><br>My working hours and your working hours may b= e different. Please do not feel obligated to reply outside your normal work= ing hours.</span><br style=3D"font-size: 17px"></div><div dir=3D"ltr"><br><= blockquote>On 24. 7. 2026, at 13:04, Sachchidanand Upadhyay via bind-users = <<a target=3D"_blank" href=3D"mailto:[email protected]">bind-user= [email protected]</a>> wrote:<br><br></blockquote></div><blockquote><div d= ir=3D"ltr">=EF=BB=BF<div style=3D"font-family: Verdana, Arial, Helvetica, s= ans-serif; font-size: 10pt"><div>Hello, <br></div><div><br></div><div>I am = observing different RPZ behavior for an IDN domain after upgrading from BIN= D 9.20.23 to 9.20.26 and would appreciate any guidance.<br></div><div><br><= /div><div>Environment:<br></div><div><br></div><div>BIND 9.20.23: Works as = expected<br></div><div>BIND 9.20.26: Fails<br></div><div>The BIND configura= tion and RPZ configuration are identical on both versions.<br></div><div><b= r></div><div>The queried domain is an IDN. The domain itself is not present= in the RPZ, yet BIND 9.20.26 logs an "RPZ QNAME rewrite failed" message fo= r the query, while the same query is resolved successfully on BIND 9.20.23 = using the same configuration. Below are the logs<br></div><div><br></div><d= iv>24-Jul-2026 15:37:16.288 query-errors: debug 3: client @0x7fd386c93800 &= lt;client_IP>#41889 (xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--1= 1b7cb3a6a.xn--h2brj9c): view internal: rpz QNAME rewrite xn--i1bn6adp9emg4d= cbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c stop on qresult in r= pz_rewrite(): failure<br></div><div>24-Jul-2026 15:37:16.288 query-errors: = info: client @0x7fd386c93800 <client_IP>#41889 (xn--i1bn6adp9emg4dcbc= ajdeflxp1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c): view internal: query = failed (failure) for xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7= cb3a6a.xn--h2brj9c/IN/A at query.c:7651<br></div><div>24-Jul-2026 15:37:16.= 288 query-errors: debug 4: fetch completed for xn--i1bn6adp9emg4dcbcajdeflx= p1gua1n7bt10abief.xn--11b7cb3a6a.xn--h2brj9c/A in 0.042000: failure/deadloc= k found [domain:xn--i1bn6adp9emg4dcbcajdeflxp1gua1n7bt10abief.xn--11b7cb3a6= a.xn--h2brj9c,referral:1,restart:2,qrysent:4,timeout:0,lame:0,quota:0,neter= r:0,badresp:0,adberr:0,findfail:0,valfail:4]<br></div><div><br></div><div>I= f anyone has encountered this issue before or is aware of a workaround or s= olution, I would be grateful for your suggestions.<br></div><div><br></div>= <div>Regards,<br></div><div>Sachchidanand Upadhyay<br></div><div><br></div>= </div><br><span>-- </span><br><span>Visit <a target=3D"_blank" href=3D"http= s://lists.isc.org/mailman/listinfo/bind-users">https://lists.isc.org/mailma= n/listinfo/bind-users</a> to unsubscribe from this list.</span><br></div></= blockquote></div></div></blockquote></div><div><br></div></div><br></body><= /html> ------=_Part_560719_1869994493.1784964487294-- --===============0613854745701137796== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list. --===============0613854745701137796==--