If you can’t resolve localhost via nss, it seems to be a local configuration 
error rather than bug in named.

> I'm unaware of the reason this was removed

https://kb.isc.org/docs/aa-00800

Ondrej
--
Ondřej Surý (He/Him)

A gentle nudge is always appreciated if I take a little longer to reply.

> On 26. 9. 2026, at 09:43, Athanasius <[email protected]> wrote:
> 
> Package: bind9
> Version: 1:9.20.29-1~deb13u1
> Severity: important
> 
> Dear Maintainer,
> 
> I've just had a failure of my postgresql cluster starting.  But that's
> because it couldn't resolve `localhost` for the address to bind to.
> 
> Checking `named.service` journal logs this is because queries came in
> during the same second the service was starting, but before the relevant
> local zone (`dsl.miggy.org` in this case) was loaded.  Thus the queries
> got refused and postgresql failed to start.
> 
> The systemd unit for `named.service` states it is `Type=notify`, which
> means it should be sending a `READY=1` message to `sd_notify` when it is
> actually ready.  It appears this is being sent too soon.  named is *not*
> ready until it has its zones loaded.
> 
> If it is changed to correctly notify when it's *actually* ready then I
> could gate other units, such as my postgresql cluster, on either
> `named.service` startup being complete, or perhaps on
> `nss-service.target`.  As it is this would have no benefit currently.
> 
> Relevant logging:
> 
> Sep 26 08:09:28 tuesday named[3454]: client @0x7ff3b4a3a000 192.168.1.1#33211 
> (localhost.dsl.miggy.org): query failed (zone not loaded) for 
> localhost.dsl.miggy.org/IN/A at query.c:5738
> ...
> Sep 26 08:09:28 tuesday named[3454]: network unreachable resolving 
> 'localhost/A/IN': 2001:503:ba3e::2:30#53
> Sep 26 08:09:28 tuesday named[3454]: network unreachable resolving 
> 'localhost/AAAA/IN': 2001:500:2f::f#53
> ...
> Sep 26 08:09:28 tuesday named[3454]: zone dsl.miggy.org/IN: loaded serial 
> 2026092100
> Sep 26 08:09:28 tuesday named[3454]: all zones loaded
> 
> Note how the lack of a local zone for `localhost` resolution is causing
> it to *also* create extra load on the root servers.  Far more than the
> two I listed above were logged.
> 
> I believe there was some change, in the bookworm>trixie transition,
> to no longer have a stub zone for `localhost`, which might have negated
> this issue.  That was the old `db.0` zone.  I'm unaware of the reasons
> this was removed, but perhaps its reintroduction could be considered,
> especially as init systems other than systemd are still supported in
> Debian, and I don't know if they have a similar mechanism to "Type=notify"
> to resolve this.
> 
> -- System Information:
> Debian Release: 13.7
>  APT prefers stable-updates
>  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 
> 'stable')
> Architecture: amd64 (x86_64)
> Foreign Architectures: i386
> 
> Kernel: Linux 6.18.54 (SMP w/8 CPU threads; PREEMPT)
> Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), 
> LANGUAGE=en_GB:en
> Shell: /bin/sh linked to /usr/bin/dash
> Init: systemd (via /run/systemd/system)
> 
> Versions of packages bind9 depends on:
> ii  adduser                3.152
> ii  bind9-libs             1:9.20.29-1~deb13u1
> ii  bind9-utils            1:9.20.29-1~deb13u1
> ii  debconf [debconf-2.0]  1.5.91
> ii  dns-root-data          2025080400~deb13u1
> ii  init-system-helpers    1.69~deb13u1
> ii  iproute2               6.15.0-1
> ii  libc6                  2.41-12+deb13u4
> ii  libcap2                1:2.75-10+deb13u1+b3
> ii  libfstrm0              0.6.1-1+b3
> ii  libjemalloc2           5.3.0-3
> ii  libjson-c5             0.18+ds-1
> ii  liblmdb0               0.9.31-1+b2
> ii  libmaxminddb0          1.12.2-1
> ii  libnghttp2-14          1.64.0-1.1+deb13u1
> ii  libprotobuf-c1         1.5.1-1
> ii  libssl3t64             3.5.7-1~deb13u2
> ii  liburcu8t64            0.15.2-2
> ii  libuv1t64              1.50.0-2
> ii  libxml2                2.12.7+dfsg+really2.9.14-2.1+deb13u3
> ii  netbase                6.5
> ii  zlib1g                 1:1.3.dfsg+really1.3.1-1+b1
> 
> bind9 recommends no packages.
> 
> Versions of packages bind9 suggests:
> ii  bind9-dnsutils  1:9.20.29-1~deb13u1
> ii  bind9-doc       1:9.20.29-1~deb13u1
> pn  resolvconf      <none>
> pn  ufw             <none>
> 
> -- Configuration Files:
> /etc/bind/db.root changed:
> ;       This file holds the information on root name servers needed to
> ;       initialize cache of Internet domain name servers
> ;       (e.g. reference this file in the "cache  .  <file>"
> ;       configuration file of BIND domain name servers).
> ;
> ;       This file is made available by InterNIC
> ;       under anonymous FTP as
> ;           file                /domain/named.cache
> ;           on server           FTP.INTERNIC.NET
> ;       -OR-                    RS.INTERNIC.NET
> ;
> ;       last update:     April 18, 2024
> ;       related version of root zone:     2024041801
> ;
> ; FORMERLY NS.INTERNIC.NET
> ;
> .                        3600000      NS    A.ROOT-SERVERS.NET.
> A.ROOT-SERVERS.NET.      3600000      A     198.41.0.4
> A.ROOT-SERVERS.NET.      3600000      AAAA  2001:503:ba3e::2:30
> ;
> ; FORMERLY NS1.ISI.EDU
> ;
> .                        3600000      NS    B.ROOT-SERVERS.NET.
> B.ROOT-SERVERS.NET.      3600000      A     170.247.170.2
> B.ROOT-SERVERS.NET.      3600000      AAAA  2801:1b8:10::b
> ;
> ; FORMERLY C.PSI.NET
> ;
> .                        3600000      NS    C.ROOT-SERVERS.NET.
> C.ROOT-SERVERS.NET.      3600000      A     192.33.4.12
> C.ROOT-SERVERS.NET.      3600000      AAAA  2001:500:2::c
> ;
> ; FORMERLY TERP.UMD.EDU
> ;
> .                        3600000      NS    D.ROOT-SERVERS.NET.
> D.ROOT-SERVERS.NET.      3600000      A     199.7.91.13
> D.ROOT-SERVERS.NET.      3600000      AAAA  2001:500:2d::d
> ;
> ; FORMERLY NS.NASA.GOV
> ;
> .                        3600000      NS    E.ROOT-SERVERS.NET.
> E.ROOT-SERVERS.NET.      3600000      A     192.203.230.10
> E.ROOT-SERVERS.NET.      3600000      AAAA  2001:500:a8::e
> ;
> ; FORMERLY NS.ISC.ORG
> ;
> .                        3600000      NS    F.ROOT-SERVERS.NET.
> F.ROOT-SERVERS.NET.      3600000      A     192.5.5.241
> F.ROOT-SERVERS.NET.      3600000      AAAA  2001:500:2f::f
> ;
> ; FORMERLY NS.NIC.DDN.MIL
> ;
> .                        3600000      NS    G.ROOT-SERVERS.NET.
> G.ROOT-SERVERS.NET.      3600000      A     192.112.36.4
> G.ROOT-SERVERS.NET.      3600000      AAAA  2001:500:12::d0d
> ;
> ; FORMERLY AOS.ARL.ARMY.MIL
> ;
> .                        3600000      NS    H.ROOT-SERVERS.NET.
> H.ROOT-SERVERS.NET.      3600000      A     198.97.190.53
> H.ROOT-SERVERS.NET.      3600000      AAAA  2001:500:1::53
> ;
> ; FORMERLY NIC.NORDU.NET
> ;
> .                        3600000      NS    I.ROOT-SERVERS.NET.
> I.ROOT-SERVERS.NET.      3600000      A     192.36.148.17
> I.ROOT-SERVERS.NET.      3600000      AAAA  2001:7fe::53
> ;
> ; OPERATED BY VERISIGN, INC.
> ;
> .                        3600000      NS    J.ROOT-SERVERS.NET.
> J.ROOT-SERVERS.NET.      3600000      A     192.58.128.30
> J.ROOT-SERVERS.NET.      3600000      AAAA  2001:503:c27::2:30
> ;
> ; OPERATED BY RIPE NCC
> ;
> .                        3600000      NS    K.ROOT-SERVERS.NET.
> K.ROOT-SERVERS.NET.      3600000      A     193.0.14.129
> K.ROOT-SERVERS.NET.      3600000      AAAA  2001:7fd::1
> ;
> ; OPERATED BY ICANN
> ;
> .                        3600000      NS    L.ROOT-SERVERS.NET.
> L.ROOT-SERVERS.NET.      3600000      A     199.7.83.42
> L.ROOT-SERVERS.NET.      3600000      AAAA  2001:500:9f::42
> ;
> ; OPERATED BY WIDE
> ;
> .                        3600000      NS    M.ROOT-SERVERS.NET.
> M.ROOT-SERVERS.NET.      3600000      A     202.12.27.33
> M.ROOT-SERVERS.NET.      3600000      AAAA  2001:dc3::35
> ; End of file
> /etc/bind/named.conf.local changed:
> //
> // vim: syntax=named
> // Do any local configuration here
> //
> logging {
>    category default { default_syslog; default_debug; };
>    channel all_queries {
>        file "/var/log/bind-named/queries" versions 5 size 20m;
>        print-time yes;
>        print-category yes;
>        print-severity yes;
>        severity info;
>    };
>    category queries { all_queries; };
>    // Something needed to divert 'rndc trace' traffic
>    // to /var/log/bind-named/trace.log
> };
> // Filter IPv6/AAAA responses if needs be
> //plugin query "filter-aaaa.so" {
> //    filter-aaaa-on-v4 yes;
> //    filter-aaaa-on-v6 yes;
> //    filter-aaaa { 192.168.1.122; };
> //};
> zone "dsl.miggy.org" {
>    type primary;
>    file "/etc/bind/dsl.miggy.org";
>    allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; };
> };
> zone "1.168.192.in-addr.arpa" {
>    type primary;
>    file "/etc/bind/1.168.192.in-addr.arpa";
>    allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; };
> };
> /*
> zone "2.168.192.in-addr.arpa" {
>    type primary;
>    file "/etc/bind/2.168.192.in-addr.arpa";
>    allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; };
> };
> */
> /*
> zone "3.168.192.in-addr.arpa" {
>    type primary;
>    file "/etc/bind/3.168.192.in-addr.arpa";
>    allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; };
> };
> */
> // VLAN subnets
> // vlanid 2
> zone "12.168.192.in-addr.arpa" {
>    type primary;
>    file "/etc/bind/12.168.192.in-addr.arpa";
>    allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; };
> };
> // vlanid 4
> zone "14.168.192.in-addr.arpa" {
>    type primary;
>    file "/etc/bind/14.168.192.in-addr.arpa";
>    allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; };
> };
> zone "miggy.org" {
>    type secondary;
>    file "/var/cache/bind/miggy.org.S";
>    masters { 87.98.248.19; };
>    allow-transfer { 87.98.248.19; 127.0.0.1; 192.168.1.0/24; 194.164.227.225; 
> };
>    // We're secondary, we don't need to notify
>    notify no;
> };
> zone "b.c.a.0.9.0.f.1.0.7.4.0.1.0.0.2.ip6.arpa" {
>    type primary;
>    file "/etc/bind/b.c.a.0.9.0.f.1.0.7.4.0.1.0.0.2.ip6.arpa";
>    allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; };
> };
> // Blacklisted zones
> // Firefox DoH canary
> zone "use-application-dns.net" {
>    type primary;
>    file "/etc/bind/blockeddomain.db";
>    allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; };
> };
> 
> /etc/bind/named.conf.options [Errno 13] Permission denied: 
> '/etc/bind/named.conf.options'
> 
> -- debconf information:
>  bind9/run-resolvconf: false
>  bind9/different-configuration-file:
>  bind9/start-as-user: bind

Reply via email to