If you can’t resolve localhost via nss, it seems to be a local configuration error rather than bug in named.
> I'm unaware of the reason this was removed https://kb.isc.org/docs/aa-00800 Ondrej -- Ondřej Surý (He/Him) A gentle nudge is always appreciated if I take a little longer to reply. > On 26. 9. 2026, at 09:43, Athanasius <[email protected]> wrote: > > Package: bind9 > Version: 1:9.20.29-1~deb13u1 > Severity: important > > Dear Maintainer, > > I've just had a failure of my postgresql cluster starting. But that's > because it couldn't resolve `localhost` for the address to bind to. > > Checking `named.service` journal logs this is because queries came in > during the same second the service was starting, but before the relevant > local zone (`dsl.miggy.org` in this case) was loaded. Thus the queries > got refused and postgresql failed to start. > > The systemd unit for `named.service` states it is `Type=notify`, which > means it should be sending a `READY=1` message to `sd_notify` when it is > actually ready. It appears this is being sent too soon. named is *not* > ready until it has its zones loaded. > > If it is changed to correctly notify when it's *actually* ready then I > could gate other units, such as my postgresql cluster, on either > `named.service` startup being complete, or perhaps on > `nss-service.target`. As it is this would have no benefit currently. > > Relevant logging: > > Sep 26 08:09:28 tuesday named[3454]: client @0x7ff3b4a3a000 192.168.1.1#33211 > (localhost.dsl.miggy.org): query failed (zone not loaded) for > localhost.dsl.miggy.org/IN/A at query.c:5738 > ... > Sep 26 08:09:28 tuesday named[3454]: network unreachable resolving > 'localhost/A/IN': 2001:503:ba3e::2:30#53 > Sep 26 08:09:28 tuesday named[3454]: network unreachable resolving > 'localhost/AAAA/IN': 2001:500:2f::f#53 > ... > Sep 26 08:09:28 tuesday named[3454]: zone dsl.miggy.org/IN: loaded serial > 2026092100 > Sep 26 08:09:28 tuesday named[3454]: all zones loaded > > Note how the lack of a local zone for `localhost` resolution is causing > it to *also* create extra load on the root servers. Far more than the > two I listed above were logged. > > I believe there was some change, in the bookworm>trixie transition, > to no longer have a stub zone for `localhost`, which might have negated > this issue. That was the old `db.0` zone. I'm unaware of the reasons > this was removed, but perhaps its reintroduction could be considered, > especially as init systems other than systemd are still supported in > Debian, and I don't know if they have a similar mechanism to "Type=notify" > to resolve this. > > -- System Information: > Debian Release: 13.7 > APT prefers stable-updates > APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, > 'stable') > Architecture: amd64 (x86_64) > Foreign Architectures: i386 > > Kernel: Linux 6.18.54 (SMP w/8 CPU threads; PREEMPT) > Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), > LANGUAGE=en_GB:en > Shell: /bin/sh linked to /usr/bin/dash > Init: systemd (via /run/systemd/system) > > Versions of packages bind9 depends on: > ii adduser 3.152 > ii bind9-libs 1:9.20.29-1~deb13u1 > ii bind9-utils 1:9.20.29-1~deb13u1 > ii debconf [debconf-2.0] 1.5.91 > ii dns-root-data 2025080400~deb13u1 > ii init-system-helpers 1.69~deb13u1 > ii iproute2 6.15.0-1 > ii libc6 2.41-12+deb13u4 > ii libcap2 1:2.75-10+deb13u1+b3 > ii libfstrm0 0.6.1-1+b3 > ii libjemalloc2 5.3.0-3 > ii libjson-c5 0.18+ds-1 > ii liblmdb0 0.9.31-1+b2 > ii libmaxminddb0 1.12.2-1 > ii libnghttp2-14 1.64.0-1.1+deb13u1 > ii libprotobuf-c1 1.5.1-1 > ii libssl3t64 3.5.7-1~deb13u2 > ii liburcu8t64 0.15.2-2 > ii libuv1t64 1.50.0-2 > ii libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3 > ii netbase 6.5 > ii zlib1g 1:1.3.dfsg+really1.3.1-1+b1 > > bind9 recommends no packages. > > Versions of packages bind9 suggests: > ii bind9-dnsutils 1:9.20.29-1~deb13u1 > ii bind9-doc 1:9.20.29-1~deb13u1 > pn resolvconf <none> > pn ufw <none> > > -- Configuration Files: > /etc/bind/db.root changed: > ; This file holds the information on root name servers needed to > ; initialize cache of Internet domain name servers > ; (e.g. reference this file in the "cache . <file>" > ; configuration file of BIND domain name servers). > ; > ; This file is made available by InterNIC > ; under anonymous FTP as > ; file /domain/named.cache > ; on server FTP.INTERNIC.NET > ; -OR- RS.INTERNIC.NET > ; > ; last update: April 18, 2024 > ; related version of root zone: 2024041801 > ; > ; FORMERLY NS.INTERNIC.NET > ; > . 3600000 NS A.ROOT-SERVERS.NET. > A.ROOT-SERVERS.NET. 3600000 A 198.41.0.4 > A.ROOT-SERVERS.NET. 3600000 AAAA 2001:503:ba3e::2:30 > ; > ; FORMERLY NS1.ISI.EDU > ; > . 3600000 NS B.ROOT-SERVERS.NET. > B.ROOT-SERVERS.NET. 3600000 A 170.247.170.2 > B.ROOT-SERVERS.NET. 3600000 AAAA 2801:1b8:10::b > ; > ; FORMERLY C.PSI.NET > ; > . 3600000 NS C.ROOT-SERVERS.NET. > C.ROOT-SERVERS.NET. 3600000 A 192.33.4.12 > C.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:2::c > ; > ; FORMERLY TERP.UMD.EDU > ; > . 3600000 NS D.ROOT-SERVERS.NET. > D.ROOT-SERVERS.NET. 3600000 A 199.7.91.13 > D.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:2d::d > ; > ; FORMERLY NS.NASA.GOV > ; > . 3600000 NS E.ROOT-SERVERS.NET. > E.ROOT-SERVERS.NET. 3600000 A 192.203.230.10 > E.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:a8::e > ; > ; FORMERLY NS.ISC.ORG > ; > . 3600000 NS F.ROOT-SERVERS.NET. > F.ROOT-SERVERS.NET. 3600000 A 192.5.5.241 > F.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:2f::f > ; > ; FORMERLY NS.NIC.DDN.MIL > ; > . 3600000 NS G.ROOT-SERVERS.NET. > G.ROOT-SERVERS.NET. 3600000 A 192.112.36.4 > G.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:12::d0d > ; > ; FORMERLY AOS.ARL.ARMY.MIL > ; > . 3600000 NS H.ROOT-SERVERS.NET. > H.ROOT-SERVERS.NET. 3600000 A 198.97.190.53 > H.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:1::53 > ; > ; FORMERLY NIC.NORDU.NET > ; > . 3600000 NS I.ROOT-SERVERS.NET. > I.ROOT-SERVERS.NET. 3600000 A 192.36.148.17 > I.ROOT-SERVERS.NET. 3600000 AAAA 2001:7fe::53 > ; > ; OPERATED BY VERISIGN, INC. > ; > . 3600000 NS J.ROOT-SERVERS.NET. > J.ROOT-SERVERS.NET. 3600000 A 192.58.128.30 > J.ROOT-SERVERS.NET. 3600000 AAAA 2001:503:c27::2:30 > ; > ; OPERATED BY RIPE NCC > ; > . 3600000 NS K.ROOT-SERVERS.NET. > K.ROOT-SERVERS.NET. 3600000 A 193.0.14.129 > K.ROOT-SERVERS.NET. 3600000 AAAA 2001:7fd::1 > ; > ; OPERATED BY ICANN > ; > . 3600000 NS L.ROOT-SERVERS.NET. > L.ROOT-SERVERS.NET. 3600000 A 199.7.83.42 > L.ROOT-SERVERS.NET. 3600000 AAAA 2001:500:9f::42 > ; > ; OPERATED BY WIDE > ; > . 3600000 NS M.ROOT-SERVERS.NET. > M.ROOT-SERVERS.NET. 3600000 A 202.12.27.33 > M.ROOT-SERVERS.NET. 3600000 AAAA 2001:dc3::35 > ; End of file > /etc/bind/named.conf.local changed: > // > // vim: syntax=named > // Do any local configuration here > // > logging { > category default { default_syslog; default_debug; }; > channel all_queries { > file "/var/log/bind-named/queries" versions 5 size 20m; > print-time yes; > print-category yes; > print-severity yes; > severity info; > }; > category queries { all_queries; }; > // Something needed to divert 'rndc trace' traffic > // to /var/log/bind-named/trace.log > }; > // Filter IPv6/AAAA responses if needs be > //plugin query "filter-aaaa.so" { > // filter-aaaa-on-v4 yes; > // filter-aaaa-on-v6 yes; > // filter-aaaa { 192.168.1.122; }; > //}; > zone "dsl.miggy.org" { > type primary; > file "/etc/bind/dsl.miggy.org"; > allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; }; > }; > zone "1.168.192.in-addr.arpa" { > type primary; > file "/etc/bind/1.168.192.in-addr.arpa"; > allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; }; > }; > /* > zone "2.168.192.in-addr.arpa" { > type primary; > file "/etc/bind/2.168.192.in-addr.arpa"; > allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; }; > }; > */ > /* > zone "3.168.192.in-addr.arpa" { > type primary; > file "/etc/bind/3.168.192.in-addr.arpa"; > allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; }; > }; > */ > // VLAN subnets > // vlanid 2 > zone "12.168.192.in-addr.arpa" { > type primary; > file "/etc/bind/12.168.192.in-addr.arpa"; > allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; }; > }; > // vlanid 4 > zone "14.168.192.in-addr.arpa" { > type primary; > file "/etc/bind/14.168.192.in-addr.arpa"; > allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; }; > }; > zone "miggy.org" { > type secondary; > file "/var/cache/bind/miggy.org.S"; > masters { 87.98.248.19; }; > allow-transfer { 87.98.248.19; 127.0.0.1; 192.168.1.0/24; 194.164.227.225; > }; > // We're secondary, we don't need to notify > notify no; > }; > zone "b.c.a.0.9.0.f.1.0.7.4.0.1.0.0.2.ip6.arpa" { > type primary; > file "/etc/bind/b.c.a.0.9.0.f.1.0.7.4.0.1.0.0.2.ip6.arpa"; > allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; }; > }; > // Blacklisted zones > // Firefox DoH canary > zone "use-application-dns.net" { > type primary; > file "/etc/bind/blockeddomain.db"; > allow-transfer { 127.0.0.1; 192.168.1.0/24; 194.164.227.225; }; > }; > > /etc/bind/named.conf.options [Errno 13] Permission denied: > '/etc/bind/named.conf.options' > > -- debconf information: > bind9/run-resolvconf: false > bind9/different-configuration-file: > bind9/start-as-user: bind

