public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
From: Matthias Fischer <matthias.fischer@ipfire.org>
To: "IPFire: Tremer, Michael" <michael.tremer@ipfire.org>
Cc: "IPFire: Development-List" <development@lists.ipfire.org>
Subject: Re: Core 203 - DNS firewall doesn't update (?) or add (!) - zone files
Date: Thu, 23 Jul 2026 23:17:40 +0200	[thread overview]
Message-ID: <14b83a61-7167-4a10-aef5-7c909171f4aa@ipfire.org> (raw)
In-Reply-To: <DE57A8D9-6C50-4320-9622-29CEB346FB69@ipfire.org>

[-- Attachment #1: Type: text/plain, Size: 3535 bytes --]

(2nd try - this didn't show up on the public inbox, so I removed the
attachments)

##########

On 23.07.2026 11:05, Michael Tremer wrote:
> Hello Matthias,

Hi Michael,

sorry, this is a bit longer. ;-)

> What happens when you run "update-rpzs”?

Cursor went one line down...waited...and showed normal bash prompt
again. No errors.

But something weird happened before - I had some problems, found a
solution, but don't know what the solution was... ;-)

Steps to reproduce (perhaps?):
- I built an update for 'knot-resolver v6.4.1' under Core 203 - this was
built without any problem, I only had to deactivate the existing patch
file. Hm.

- I stripped the files by hand and built an archive with the command:tar
cvfz ../uploads/knot-resolver-6.4.1-for-ipfire-Core203.tar.gz -C
build_x86_64 --files-from=config/rootfiles/common/knot-resolver

I'm doing this procedure all the time with all updated programs so I can
install and test them on my testmachine or my productive machine,
whatever comes first.

- In the next step I copied this resolver-archive to the root directory
of my productive machine (sigh!), stopped the running 'knot-resolver'
(at least I think this stops him) with '/etc/init.d/knot-resolver stop'
and extracted the archive with the command:
tar xvf knot-resolver-6.4.1-for-ipfire-Core203.tar.gz -C /

E.g., I did this the same way before I pushed the last 'knot
3.5.6'-update. No problem. Until the update for 'knot-resolver 6.4.1'.

Result:
- Restarting the 'knot-resolver 6.4.1' failed, DNS was completely broken.
And the 'Domain Name Sstem'-Log was filled with 'kresd' and
'knot_resolver.manager.server:' errors ("kresd[20064]: [system] error
while loading config: error occurred here" or "Uncaught generic
exception during manager inicialization").

Hm!

Since I had backups of all essential files of the previous version
(6.4.0), I copied them back - with the same result. DNS stayed broken,
no matter what I did. Old version, new version, nothing started, always
the same crashes. I checked rights, I checked contents, rebooted, no
chance. I don't know if I missed something - nothing worked.

Then today I copied a fresh built 'core-upgrade-2.29-203.ipfire' to
'/opt/pakfire/tmp' and updated the whole system just like I did a few
days ago through pakfire, only this time from console per './update.sh'
and rebooted.

Suddenly DNS was running - and I could add the "Gambling" list (e.g.) to
DNS-Firewall - it was downloaded and seems to work.

So now DNS is working (again) but I don't know why it was broken and I
don't know what fixed it in the end... weird.

EDIT:
If it helps I could open a bug report, explain the process and attach an
excerpt of the dns log. ;-)

I don't like to push this update until I know what happened... ;-)

Best
Matthias

> -Michael
> 
>> On 22 Jul 2026, at 14:02, Matthias Fischer <matthias.fischer@ipfire.org> wrote:
>> 
>> Hi,
>> 
>> I have one problem with Core 203 and I'm not sure whats the culprit:
>> 
>> No matter what I do, Core 203 won't download additional zone files.
>> 
>> After rebooting I found the already used and activated blocklists (from
>> Core 202) in the '/var/lib//knot-resolver/zones' dirextory. They're
>> working - no seen problem. But even if I activate them all on the DNSBL
>> page, nothing gets downloaded, the selection and number of block lists
>> always remain the same. It won't add or remove any of the existing lists.
>> 
>> Can anyone confirm? OR give me a hint where to look at?
>> 
>> Thanks in advance
>> Matthias
>> 
>> 
> 
> 

[-- Attachment #2: Deleted: excerpt-from DNS log.txt --]
[-- Type: text/x-moz-deleted, Size: 280 bytes --]

You deleted an attachment from this message. The original MIME headers for the attachment were:
Content-Type: text/plain; charset=UTF-8; name="excerpt-from DNS log.txt"
Content-Disposition: attachment; filename="excerpt-from DNS log.txt"
Content-Transfer-Encoding: base64



[-- Attachment #3: Deleted: knot-resolver-6.4.1-for-ipfire-Core203.tar.gz --]
[-- Type: text/x-moz-deleted, Size: 317 bytes --]

You deleted an attachment from this message. The original MIME headers for the attachment were:
Content-Type: application/gzip;
 name="knot-resolver-6.4.1-for-ipfire-Core203.tar.gz"
Content-Disposition: attachment;
 filename="knot-resolver-6.4.1-for-ipfire-Core203.tar.gz"
Content-Transfer-Encoding: base64



  reply	other threads:[~2026-07-23 21:17 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-22 13:02 Matthias Fischer
2026-07-22 13:28 ` Mentalic
2026-07-23  9:06   ` Michael Tremer
2026-07-23  9:05 ` Michael Tremer
2026-07-23 21:17   ` Matthias Fischer [this message]
2026-07-24 15:44     ` Michael Tremer
2026-07-24 18:34       ` Matthias Fischer
2026-07-25 16:38         ` Matthias Fischer

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=14b83a61-7167-4a10-aef5-7c909171f4aa@ipfire.org \
    --to=matthias.fischer@ipfire.org \
    --cc=development@lists.ipfire.org \
    --cc=michael.tremer@ipfire.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox