From: Matthias Fischer <matthias.fischer@ipfire.org>
To: "IPFire: Tremer, Michael" <michael.tremer@ipfire.org>
Cc: "IPFire: Development-List" <development@lists.ipfire.org>
Subject: Re: Core 203 - DNS firewall doesn't update (?) or add (!) - zone files
Date: Thu, 23 Jul 2026 23:17:40 +0200 [thread overview]
Message-ID: <14b83a61-7167-4a10-aef5-7c909171f4aa@ipfire.org> (raw)
In-Reply-To: <DE57A8D9-6C50-4320-9622-29CEB346FB69@ipfire.org>
[-- Attachment #1: Type: text/plain, Size: 3535 bytes --]
(2nd try - this didn't show up on the public inbox, so I removed the
attachments)
##########
On 23.07.2026 11:05, Michael Tremer wrote:
> Hello Matthias,
Hi Michael,
sorry, this is a bit longer. ;-)
> What happens when you run "update-rpzs”?
Cursor went one line down...waited...and showed normal bash prompt
again. No errors.
But something weird happened before - I had some problems, found a
solution, but don't know what the solution was... ;-)
Steps to reproduce (perhaps?):
- I built an update for 'knot-resolver v6.4.1' under Core 203 - this was
built without any problem, I only had to deactivate the existing patch
file. Hm.
- I stripped the files by hand and built an archive with the command:tar
cvfz ../uploads/knot-resolver-6.4.1-for-ipfire-Core203.tar.gz -C
build_x86_64 --files-from=config/rootfiles/common/knot-resolver
I'm doing this procedure all the time with all updated programs so I can
install and test them on my testmachine or my productive machine,
whatever comes first.
- In the next step I copied this resolver-archive to the root directory
of my productive machine (sigh!), stopped the running 'knot-resolver'
(at least I think this stops him) with '/etc/init.d/knot-resolver stop'
and extracted the archive with the command:
tar xvf knot-resolver-6.4.1-for-ipfire-Core203.tar.gz -C /
E.g., I did this the same way before I pushed the last 'knot
3.5.6'-update. No problem. Until the update for 'knot-resolver 6.4.1'.
Result:
- Restarting the 'knot-resolver 6.4.1' failed, DNS was completely broken.
And the 'Domain Name Sstem'-Log was filled with 'kresd' and
'knot_resolver.manager.server:' errors ("kresd[20064]: [system] error
while loading config: error occurred here" or "Uncaught generic
exception during manager inicialization").
Hm!
Since I had backups of all essential files of the previous version
(6.4.0), I copied them back - with the same result. DNS stayed broken,
no matter what I did. Old version, new version, nothing started, always
the same crashes. I checked rights, I checked contents, rebooted, no
chance. I don't know if I missed something - nothing worked.
Then today I copied a fresh built 'core-upgrade-2.29-203.ipfire' to
'/opt/pakfire/tmp' and updated the whole system just like I did a few
days ago through pakfire, only this time from console per './update.sh'
and rebooted.
Suddenly DNS was running - and I could add the "Gambling" list (e.g.) to
DNS-Firewall - it was downloaded and seems to work.
So now DNS is working (again) but I don't know why it was broken and I
don't know what fixed it in the end... weird.
EDIT:
If it helps I could open a bug report, explain the process and attach an
excerpt of the dns log. ;-)
I don't like to push this update until I know what happened... ;-)
Best
Matthias
> -Michael
>
>> On 22 Jul 2026, at 14:02, Matthias Fischer <matthias.fischer@ipfire.org> wrote:
>>
>> Hi,
>>
>> I have one problem with Core 203 and I'm not sure whats the culprit:
>>
>> No matter what I do, Core 203 won't download additional zone files.
>>
>> After rebooting I found the already used and activated blocklists (from
>> Core 202) in the '/var/lib//knot-resolver/zones' dirextory. They're
>> working - no seen problem. But even if I activate them all on the DNSBL
>> page, nothing gets downloaded, the selection and number of block lists
>> always remain the same. It won't add or remove any of the existing lists.
>>
>> Can anyone confirm? OR give me a hint where to look at?
>>
>> Thanks in advance
>> Matthias
>>
>>
>
>
[-- Attachment #2: Deleted: excerpt-from DNS log.txt --]
[-- Type: text/x-moz-deleted, Size: 280 bytes --]
You deleted an attachment from this message. The original MIME headers for the attachment were:
Content-Type: text/plain; charset=UTF-8; name="excerpt-from DNS log.txt"
Content-Disposition: attachment; filename="excerpt-from DNS log.txt"
Content-Transfer-Encoding: base64
[-- Attachment #3: Deleted: knot-resolver-6.4.1-for-ipfire-Core203.tar.gz --]
[-- Type: text/x-moz-deleted, Size: 317 bytes --]
You deleted an attachment from this message. The original MIME headers for the attachment were:
Content-Type: application/gzip;
name="knot-resolver-6.4.1-for-ipfire-Core203.tar.gz"
Content-Disposition: attachment;
filename="knot-resolver-6.4.1-for-ipfire-Core203.tar.gz"
Content-Transfer-Encoding: base64
next prev parent reply other threads:[~2026-07-23 21:17 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-22 13:02 Matthias Fischer
2026-07-22 13:28 ` Mentalic
2026-07-23 9:06 ` Michael Tremer
2026-07-23 9:05 ` Michael Tremer
2026-07-23 21:17 ` Matthias Fischer [this message]
2026-07-24 15:44 ` Michael Tremer
2026-07-24 18:34 ` Matthias Fischer
2026-07-25 16:38 ` Matthias Fischer
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=14b83a61-7167-4a10-aef5-7c909171f4aa@ipfire.org \
--to=matthias.fischer@ipfire.org \
--cc=development@lists.ipfire.org \
--cc=michael.tremer@ipfire.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox