missing mandatory glue for root nameservers in BIND 9.21.26 global forwarding configuration
Colin Vidal
colin at isc.org
Mon Sep 28 08:57:11 UTC 2026
Hi,
On Mon, 2026-09-28 at 15:16 +0700, Bagas Sanjaya wrote:
> Hi,
>
> Since upgrading BIND on my Arch Linux system to 9.21.26 (compiled
> myself
> from source), it now shows resolver priming query failure every time
> it
Thanks for the report and config/log details. Things indeed changed
recently in the priming logic of the resolver, making some errors a bit
more explicit.
In this case, we can see that `dig . NS @dns.quad9.net` (which is
essentially the query priming does) doesn't return any glues for the
root NS names. BIND then (verbosely) just ignore those and says the
priming fails since there were fundamentally nothing it can do from
such priming answer.
On a non-forwarder resolver, priming contact a root server directly. If
we do `dig . NS @f.root-servers.net`, you'll see the glue are part of
the additional section since the answer is a referral. (Glues are
mandatory, since all the NS names are in a delegation of the root, or
"in-domain glues", so a resolver would need to know how to contact the
authoritative NS for such delegation.)
Since the resolver is forward only in this case, you are essentially
contacting a resolver for `./NS` and things are quite different. This
is not a referral anymore (you are not asking for a name to a server
making authority on a zone delegating this name) but just to resolve
what's in the NS RR for `.`, so glues are not mandatory.
I noticed that while quad9 resolver doesn't provide the glues for
`./NS`, adguard resolver does. But I guess this could change in the
future.
Back to your case, I suspect priming was always broken then, but it
doesn't matter and this is not a problem, since your resolver is in a
forward only mode. (Although I'd expect priming to _not_ run on the
latest BIND dev release in such case, especially because it's useless.
I'll need to check this out.)
--
Colin Vidal -- colin at isc.org
Internet Systems Consortium
More information about the bind-users
mailing list