Hi, On Mon, 2026-09-28 at 15:16 +0700, Bagas Sanjaya wrote: > Hi, > > Since upgrading BIND on my Arch Linux system to 9.21.26 (compiled > myself > from source), it now shows resolver priming query failure every time > it
Thanks for the report and config/log details. Things indeed changed recently in the priming logic of the resolver, making some errors a bit more explicit. In this case, we can see that `dig . NS @dns.quad9.net` (which is essentially the query priming does) doesn't return any glues for the root NS names. BIND then (verbosely) just ignore those and says the priming fails since there were fundamentally nothing it can do from such priming answer. On a non-forwarder resolver, priming contact a root server directly. If we do `dig . NS @f.root-servers.net`, you'll see the glue are part of the additional section since the answer is a referral. (Glues are mandatory, since all the NS names are in a delegation of the root, or "in-domain glues", so a resolver would need to know how to contact the authoritative NS for such delegation.) Since the resolver is forward only in this case, you are essentially contacting a resolver for `./NS` and things are quite different. This is not a referral anymore (you are not asking for a name to a server making authority on a zone delegating this name) but just to resolve what's in the NS RR for `.`, so glues are not mandatory. I noticed that while quad9 resolver doesn't provide the glues for `./NS`, adguard resolver does. But I guess this could change in the future. Back to your case, I suspect priming was always broken then, but it doesn't matter and this is not a problem, since your resolver is in a forward only mode. (Although I'd expect priming to _not_ run on the latest BIND dev release in such case, especially because it's useless. I'll need to check this out.) -- Colin Vidal -- [email protected] Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list.

