Package: bind9
Version: 1:9.20.29-1~deb13u1
Severity: important
Dear Maintainer,
I've just had a failure of my postgresql cluster starting. But that's
because it couldn't resolve `localhost` for the address to bind to.
Checking `named.service` journal logs this is because queries came in
during the same second the service was starting, but before the relevant
local zone (`dsl.miggy.org` in this case) was loaded. Thus the queries
got refused and postgresql failed to start.
The systemd unit for `named.service` states it is `Type=notify`, which
means it should be sending a `READY=1` message to `sd_notify` when it is
actually ready. It appears this is being sent too soon. named is *not*
ready until it has its zones loaded.
If it is changed to correctly notify when it's *actually* ready then I
could gate other units, such as my postgresql cluster, on either
`named.service` startup being complete, or perhaps on
`nss-service.target`. As it is this would have no benefit currently.
Relevant logging:
Sep 26 08:09:28 tuesday named[3454]: client @0x7ff3b4a3a000 192.168.1.1#33211
(localhost.dsl.miggy.org): query failed (zone not loaded) for
localhost.dsl.miggy.org/IN/A at query.c:5738
...
Sep 26 08:09:28 tuesday named[3454]: network unreachable resolving
'localhost/A/IN': 2001:503:ba3e::2:30#53
Sep 26 08:09:28 tuesday named[3454]: network unreachable resolving
'localhost/AAAA/IN': 2001:500:2f::f#53
...
Sep 26 08:09:28 tuesday named[3454]: zone dsl.miggy.org/IN: loaded serial
2026092100
Sep 26 08:09:28 tuesday named[3454]: all zones loaded
Note how the lack of a local zone for `localhost` resolution is causing
it to *also* create extra load on the root servers. Far more than the
two I listed above were logged.
I believe there was some change, in the bookworm>trixie transition,
to no longer have a stub zone for `localhost`, which might have negated
this issue. That was the old `db.0` zone. I'm unaware of the reasons
this was removed, but perhaps its reintroduction could be considered,
especially as init systems other than systemd are still supported in
Debian, and I don't know if they have a similar mechanism to "Type=notify"
to resolve this.
-- System Information:
Debian Release: 13.7
APT prefers stable-updates
APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386
Kernel: Linux 6.18.54 (SMP w/8 CPU threads; PREEMPT)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8),
LANGUAGE=en_GB:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
Versions of packages bind9 depends on:
ii adduser 3.152
ii bind9-libs 1:9.20.29-1~deb13u1
ii bind9-utils 1:9.20.29-1~deb13u1
ii debconf [debconf-2.0] 1.5.91
ii dns-root-data 2025080400~deb13u1
ii init-system-helpers 1.69~deb13u1
ii iproute2 6.15.0-1
ii libc6 2.41-12+deb13u4
ii libcap2 1:2.75-10+deb13u1+b3
ii libfstrm0 0.6.1-1+b3
ii libjemalloc2 5.3.0-3
ii libjson-c5 0.18+ds-1
ii liblmdb0 0.9.31-1+b2
ii libmaxminddb0 1.12.2-1
ii libnghttp2-14 1.64.0-1.1+deb13u1
ii libprotobuf-c1 1.5.1-1
ii libssl3t64 3.5.7-1~deb13u2
ii liburcu8t64 0.15.2-2
ii libuv1t64 1.50.0-2
ii libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3
ii netbase 6.5
ii zlib1g 1:1.3.dfsg+really1.3.1-1+b1
bind9 recommends no packages.
Versions of packages bind9 suggests:
ii bind9-dnsutils 1:9.20.29-1~deb13u1
ii bind9-doc 1:9.20.29-1~deb13u1
pn resolvconf <none>
pn ufw <none>
-- Configuration Files:
/etc/bind/db.root changed:
; This file holds the information on root name servers needed to
; initialize cache of Internet domain name servers
; (e.g. reference this file in the "cache . <file>"
; configuration file of BIND domain name servers).
;
; This file is made available by InterNIC
; under anonymous FTP as
; file /domain/named.cache
; on server FTP.INTERNIC.NET
; -OR- RS.INTERNIC.NET
;
; last update: April 18, 2024
; related version of root zone: 2024041801
;
; FORMERLY NS.INTERNIC.NET
;
. 3600000 NS A.ROOT-SERVERS.NET.
A.ROOT-SERVERS.NET. 3600000 A 198.41.0.4
A.ROOT-SERVERS.NET. 3600000 AAAA 2001:503:ba3e::2:30
;
; FORMERLY NS1.ISI.EDU
;
. 3600000 NS B.ROOT-SERVERS.NET.
B.ROOT-SERVERS.NET. 3600000 A 170.247.170.2
B.ROOT-SERVERS.NET. 3600000 AAAA 2801:1b8:10::b
;
; FORMERLY C.PSI.NET
;
. 3600000 NS C.ROOT-SERVERS.NET.
C.ROOT-SERVERS.NET. 3600000 A 192.33.4.12
C.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:2::c
;
; FORMERLY TERP.UMD.EDU
;
. 3600000 NS D.ROOT-SERVERS.NET.
D.ROOT-SERVERS.NET. 3600000 A 199.7.91.13
D.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:2d::d
;
; FORMERLY NS.NASA.GOV
;
. 3600000 NS E.ROOT-SERVERS.NET.
E.ROOT-SERVERS.NET. 3600000 A 192.203.230.10
E.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:a8::e
;
; FORMERLY NS.ISC.ORG
;
. 3600000 NS F.ROOT-SERVERS.NET.
F.ROOT-SERVERS.NET. 3600000 A 192.5.5.241
F.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:2f::f
;
; FORMERLY NS.NIC.DDN.MIL
;
. 3600000 NS G.ROOT-SERVERS.NET.
G.ROOT-SERVERS.NET. 3600000 A 192.112.36.4
G.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:12::d0d
;
; FORMERLY AOS.ARL.ARMY.MIL
;
. 3600000 NS H.ROOT-SERVERS.NET.
H.ROOT-SERVERS.NET. 3600000 A 198.97.190.53
H.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:1::53
;
; FORMERLY NIC.NORDU.NET
;
. 3600000 NS I.ROOT-SERVERS.NET.
I.ROOT-SERVERS.NET. 3600000 A 192.36.148.17
I.ROOT-SERVERS.NET. 3600000 AAAA 2001:7fe::53
;
; OPERATED BY VERISIGN, INC.
;
. 3600000 NS J.ROOT-SERVERS.NET.
J.ROOT-SERVERS.NET. 3600000 A 192.58.128.30
J.ROOT-SERVERS.NET. 3600000 AAAA 2001:503:c27::2:30
;
; OPERATED BY RIPE NCC
;
. 3600000 NS K.ROOT-SERVERS.NET.
K.ROOT-SERVERS.NET. 3600000 A 193.0.14.129
K.ROOT-SERVERS.NET. 3600000 AAAA 2001:7fd::1
;
; OPERATED BY ICANN
;
. 3600000 NS L.ROOT-SERVERS.NET.
L.ROOT-SERVERS.NET. 3600000 A 199.7.83.42
L.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:9f::42
;
; OPERATED BY WIDE
;
. 3600000 NS M.ROOT-SERVERS.NET.
M.ROOT-SERVERS.NET. 3600000 A 202.12.27.33
M.ROOT-SERVERS.NET. 3600000 AAAA 2001:dc3::35
; End of file
/etc/bind/named.conf.local changed:
//
// vim: syntax=named
// Do any local configuration here
//
logging {
category default { default_syslog; default_debug; };
channel all_queries {
file "/var/log/bind-named/queries" versions 5 size 20m;
print-time yes;
print-category yes;
print-severity yes;
severity info;
};
category queries { all_queries; };
// Something needed to divert 'rndc trace' traffic
// to /var/log/bind-named/trace.log
};
// Filter IPv6/AAAA responses if needs be
//plugin query "filter-aaaa.so" {
// filter-aaaa-on-v4 yes;
// filter-aaaa-on-v6 yes;
// filter-aaaa { 192.168.1.122; };
//};
zone "dsl.miggy.org" {
type primary;
file "/etc/bind/dsl.miggy.org";
allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; };
};
zone "1.168.192.in-addr.arpa" {
type primary;
file "/etc/bind/1.168.192.in-addr.arpa";
allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; };
};
/*
zone "2.168.192.in-addr.arpa" {
type primary;
file "/etc/bind/2.168.192.in-addr.arpa";
allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; };
};
*/
/*
zone "3.168.192.in-addr.arpa" {
type primary;
file "/etc/bind/3.168.192.in-addr.arpa";
allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; };
};
*/
// VLAN subnets
// vlanid 2
zone "12.168.192.in-addr.arpa" {
type primary;
file "/etc/bind/12.168.192.in-addr.arpa";
allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; };
};
// vlanid 4
zone "14.168.192.in-addr.arpa" {
type primary;
file "/etc/bind/14.168.192.in-addr.arpa";
allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; };
};
zone "miggy.org" {
type secondary;
file "/var/cache/bind/miggy.org.S";
masters { 87.98.248.19; };
allow-transfer { 87.98.248.19; 127.0.0.1; 192.168.1.0/24;
194.164.227.225; };
// We're secondary, we don't need to notify
notify no;
};
zone "b.c.a.0.9.0.f.1.0.7.4.0.1.0.0.2.ip6.arpa" {
type primary;
file "/etc/bind/b.c.a.0.9.0.f.1.0.7.4.0.1.0.0.2.ip6.arpa";
allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; };
};
// Blacklisted zones
// Firefox DoH canary
zone "use-application-dns.net" {
type primary;
file "/etc/bind/blockeddomain.db";
allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; };
};
/etc/bind/named.conf.options [Errno 13] Permission denied:
'/etc/bind/named.conf.options'
-- debconf information:
bind9/run-resolvconf: false
bind9/different-configuration-file:
bind9/start-as-user: bind