Hello,
I would like to report what appears to be a regression in Knot Resolver 6.4.2.
An RPZ rule loaded via local-data.rpz does not match queries if the rule's owner name contains uppercase ASCII letters. Rules whose owner names are entirely lowercase work correctly and match queries regardless of query case.
Ordinary DNS lookups on the same resolver behave case-insensitively as expected; for example, mixed-case queries such as GoGle.pl and WP.pl resolve normally.
Tested with:
knot-resolver6 6.4.2-cznic.1~bookworm
knot-resolver6-module-dnstap 6.4.2-cznic.1~bookworm
libknot16 3.5.8
libdnssec10 3.5.8
Debian 12 (bookworm)
Knot Resolver 5.7.6 (cznic.1), with the same RPZ data loaded using Lua policy.rpz()
DNS name matching is case-insensitive for ASCII letters. RFC 1034 §3.1 and RFC 4343 specify that DNS name comparisons ignore ASCII case.
With local-data.rpz in Knot Resolver 6.4.2, however, a rule whose owner name contains uppercase letters is never applied.
It does not match when the query:
is entirely lowercase,
uses exactly the same case as the RPZ owner name, or
is entirely uppercase.
Our RPZ blocklist contains eight entries with mixed-case owner names, for example:
rabOna-7681.com IN A 10.15.20.254
www.rabOna-7681.com IN A 10.15.20.254
Italy9.cabaretclub.com IN A 10.15.20.254
totaIcasino.nl IN A 10.15.20.254The same RPZ data is deployed on servers running Knot Resolver 5.7.6 and 6.4.2.
With 5.7.6 and policy.rpz():
$ dig www.rabona-7681.com @127.0.0.1
;; flags: qr aa rd ra;
www.rabona-7681.com. 7200 IN A 10.15.20.254With 6.4.2 and local-data.rpz:
$ dig www.rabona-7681.com @127.0.0.1
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN
$ dig rabOna-7681.com @127.0.0.1
(no RPZ answer)None of the eight mixed-case entries receives the configured RPZ answer on 6.4.2. Lowercase entries from the same file work correctly.
/etc/knot-resolver/case-test.rpz:
$TTL 300
@ IN SOA localhost. root.localhost. 1 3600 600 86400 300
@ IN NS localhost.
TeSt-case.example IN A 192.0.2.1
lower-case.example IN A 192.0.2.2Relevant part of config.yaml:
local-data:
rpz:
- file: /etc/knot-resolver/case-test.rpzkresctl validate --strict succeeds. I then run kresctl reload.
Results:
query status answer
lower-case.example NOERROR A 192.0.2.2
LOWER-CASE.example NOERROR A 192.0.2.2
test-case.example SERVFAIL none
TeSt-case.example SERVFAIL none
TEST-CASE.EXAMPLE SERVFAIL none
other.example SERVFAIL none
WP.pl NOERROR normal DNS answer
GoGle.pl NOERROR normal DNS answerother.example, WP.pl, and GoGle.pl are control queries and are not present in the RPZ file. WP.pl and GoGle.pl demonstrate that ordinary DNS resolution works correctly and remains case-insensitive, while the mixed-case RPZ owner name fails to match.
The lowercase rule matches queries regardless of case. The mixed-case rule does not match any query, including a query using exactly the same case as the owner name in the RPZ file.
This rule:
TeSt-case.example IN A 192.0.2.1should match:
test-case.example
TeSt-case.example
TEST-CASE.EXAMPLEin the same way that the lowercase rule does, and in the same way that Knot Resolver 5.7.6 with policy.rpz() behaves.
An RPZ rule loaded through local-data.rpz is effectively ignored if its owner name contains uppercase ASCII letters.
Convert all owner names in the RPZ file to lowercase before loading the file.
--
Best regards,
Mateusz Masłowski