Hello,

I would like to report what appears to be a regression in Knot Resolver 6.4.2.

An RPZ rule loaded via local-data.rpz does not match queries if the rule's owner name contains uppercase ASCII letters. Rules whose owner names are entirely lowercase work correctly and match queries regardless of query case.

Ordinary DNS lookups on the same resolver behave case-insensitively as expected; for example, mixed-case queries such as GoGle.pl and WP.pl resolve normally.

Affected version

Tested with:

Not affected

Summary

DNS name matching is case-insensitive for ASCII letters. RFC 1034 §3.1 and RFC 4343 specify that DNS name comparisons ignore ASCII case.

With local-data.rpz in Knot Resolver 6.4.2, however, a rule whose owner name contains uppercase letters is never applied.

It does not match when the query:

Real-world example

Our RPZ blocklist contains eight entries with mixed-case owner names, for example:

rabOna-7681.com IN A 10.15.20.254
www.rabOna-7681.com IN A 10.15.20.254
Italy9.cabaretclub.com IN A 10.15.20.254
totaIcasino.nl IN A 10.15.20.254

The same RPZ data is deployed on servers running Knot Resolver 5.7.6 and 6.4.2.

With 5.7.6 and policy.rpz():

$ dig www.rabona-7681.com @127.0.0.1

;; flags: qr aa rd ra;
www.rabona-7681.com. 7200 IN A 10.15.20.254

With 6.4.2 and local-data.rpz:

$ dig www.rabona-7681.com @127.0.0.1
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN

$ dig rabOna-7681.com @127.0.0.1
(no RPZ answer)

None of the eight mixed-case entries receives the configured RPZ answer on 6.4.2. Lowercase entries from the same file work correctly.

Minimal reproducer

/etc/knot-resolver/case-test.rpz:

$TTL 300
@ IN SOA localhost. root.localhost. 1 3600 600 86400 300
@ IN NS localhost.
TeSt-case.example IN A 192.0.2.1
lower-case.example IN A 192.0.2.2

Relevant part of config.yaml:

local-data:
  rpz:
    - file: /etc/knot-resolver/case-test.rpz

kresctl validate --strict succeeds. I then run kresctl reload.

Results:

query                 status      answer
lower-case.example    NOERROR     A 192.0.2.2
LOWER-CASE.example    NOERROR     A 192.0.2.2
test-case.example     SERVFAIL    none
TeSt-case.example     SERVFAIL    none
TEST-CASE.EXAMPLE     SERVFAIL    none
other.example         SERVFAIL    none
WP.pl                 NOERROR     normal DNS answer
GoGle.pl              NOERROR     normal DNS answer

other.example, WP.pl, and GoGle.pl are control queries and are not present in the RPZ file. WP.pl and GoGle.pl demonstrate that ordinary DNS resolution works correctly and remains case-insensitive, while the mixed-case RPZ owner name fails to match.

The lowercase rule matches queries regardless of case. The mixed-case rule does not match any query, including a query using exactly the same case as the owner name in the RPZ file.

Expected behavior

This rule:

TeSt-case.example IN A 192.0.2.1

should match:

test-case.example
TeSt-case.example
TEST-CASE.EXAMPLE

in the same way that the lowercase rule does, and in the same way that Knot Resolver 5.7.6 with policy.rpz() behaves.

Actual behavior

An RPZ rule loaded through local-data.rpz is effectively ignored if its owner name contains uppercase ASCII letters.

Workaround

Convert all owner names in the RPZ file to lowercase before loading the file.


--

Best regards,
Mateusz Masłowski