Hello,
I would like to report what appears to be a regression in Knot Resolver
6.4.2.
An RPZ rule loaded via local-data.rpz does not match queries if the rule's
owner name contains uppercase ASCII letters. Rules whose owner names are
entirely lowercase work correctly and match queries regardless of query
case.
Ordinary DNS lookups on the same resolver behave case-insensitively as
expected; for example, mixed-case queries such as GoGle.pl and WP.pl
resolve normally.
Affected version
Tested with:
-
knot-resolver6 6.4.2-cznic.1~bookworm
-
knot-resolver6-module-dnstap 6.4.2-cznic.1~bookworm
-
libknot16 3.5.8
-
libdnssec10 3.5.8
-
Debian 12 (bookworm)
Not affected
-
Knot Resolver 5.7.6 (cznic.1), with the same RPZ data loaded using Lua
policy.rpz()
Summary
DNS name matching is case-insensitive for ASCII letters. RFC 1034 §3.1 and
RFC 4343 specify that DNS name comparisons ignore ASCII case.
With local-data.rpz in Knot Resolver 6.4.2, however, a rule whose owner
name contains uppercase letters is never applied.
It does not match when the query:
-
is entirely lowercase,
-
uses exactly the same case as the RPZ owner name, or
-
is entirely uppercase.
Real-world example
Our RPZ blocklist contains eight entries with mixed-case owner names, for
example:
rabOna-7681.com IN A
10.15.20.254www.rabOna-7681.com IN A
10.15.20.254Italy9.cabaretclub.com IN A 10.15.20.254
totaIcasino.nl IN A 10.15.20.254
The same RPZ data is deployed on servers running Knot Resolver 5.7.6 and
6.4.2.
With 5.7.6 and policy.rpz():
$ dig
www.rabona-7681.com @127.0.0.1
;; flags: qr aa rd
ra;www.rabona-7681.com. 7200 IN A 10.15.20.254
With 6.4.2 and local-data.rpz:
$ dig
www.rabona-7681.com @127.0.0.1
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN
$ dig
rabOna-7681.com @127.0.0.1
(no RPZ answer)
None of the eight mixed-case entries receives the configured RPZ answer on
6.4.2. Lowercase entries from the same file work correctly.
Minimal reproducer
/etc/knot-resolver/case-test.rpz:
$TTL 300
@ IN SOA localhost. root.localhost. 1 3600 600 86400 300
@ IN NS localhost.
TeSt-case.example IN A 192.0.2.1
lower-case.example IN A 192.0.2.2
Relevant part of config.yaml:
local-data:
rpz:
- file: /etc/knot-resolver/case-test.rpz
kresctl validate --strict succeeds. I then run kresctl reload.
Results:
query status answer
lower-case.example NOERROR A 192.0.2.2
LOWER-CASE.example NOERROR A 192.0.2.2
test-case.example SERVFAIL none
TeSt-case.example SERVFAIL none
TEST-CASE.EXAMPLE SERVFAIL none
other.example SERVFAIL none
WP.pl NOERROR normal DNS answer
GoGle.pl NOERROR normal DNS answer
other.example, WP.pl, and GoGle.pl are control queries and are not present
in the RPZ file. WP.pl and GoGle.pl demonstrate that ordinary DNS
resolution works correctly and remains case-insensitive, while the
mixed-case RPZ owner name fails to match.
The lowercase rule matches queries regardless of case. The mixed-case rule
does not match any query, including a query using exactly the same case as
the owner name in the RPZ file.
Expected behavior
This rule:
TeSt-case.example IN A 192.0.2.1
should match:
test-case.example
TeSt-case.example
TEST-CASE.EXAMPLE
in the same way that the lowercase rule does, and in the same way that Knot
Resolver 5.7.6 with policy.rpz() behaves.
Actual behavior
An RPZ rule loaded through local-data.rpz is effectively ignored if its
owner name contains uppercase ASCII letters.
Workaround
Convert all owner names in the RPZ file to lowercase before loading the
file.
--
Best regards,
Mateusz Masłowski