[DNSOP] Re: ordering of RRSets in the answer section of a DNS response
Ondřej Surý <ondrej@sury.org> Mon, 19 January 2026 03:56 UTC
Return-Path: <ondrej@sury.org>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id D538EA9AEA23 for <dnsop@mail2.ietf.org>; Sun, 18 Jan 2026 19:56:40 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.798
X-Spam-Level:
X-Spam-Status: No, score=-2.798 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=sury.org header.b="PXY24oYA"; dkim=pass (2048-bit key) header.d=messagingengine.com header.b="VXHi/+bF"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PTD9xGdfYIIj for <dnsop@mail2.ietf.org>; Sun, 18 Jan 2026 19:56:40 -0800 (PST)
Received: from fhigh-b6-smtp.messagingengine.com (fhigh-b6-smtp.messagingengine.com [202.12.124.157]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 338BEA9AEA12 for <dnsop@ietf.org>; Sun, 18 Jan 2026 19:56:40 -0800 (PST)
Received: from phl-compute-04.internal (phl-compute-04.internal [10.202.2.44]) by mailfhigh.stl.internal (Postfix) with ESMTP id 2082E7A0076; Sun, 18 Jan 2026 22:56:34 -0500 (EST)
Received: from phl-frontend-03 ([10.202.2.162]) by phl-compute-04.internal (MEProxy); Sun, 18 Jan 2026 22:56:34 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sury.org; h=cc :cc:content-type:content-type:date:date:from:from:in-reply-to :in-reply-to:message-id:mime-version:references:reply-to:subject :subject:to:to; s=fm3; t=1768794993; x=1768881393; bh=NhGNCehkZv 01UwtYE1S7iseCLKrN8q1x8Kl63p9z0KE=; b=PXY24oYAXUgYP88x4GYnf50/JS YJQ3oFSBvlH/b3tbB7Rpg4r+2ol35bvUWAgwojyFfGDMbbAxbl1xRVQS7tF+KVU0 W29dCEZ9E6mCF4+Viw8nRTmIszY84QpQQ2SCQF5kdFE+qYcbY4mqpV0nTFj+FYkz ukhMUv2Rrln9XY3B6U8q/LImQ4ZaIs+EGDNW1ZTJ1uy4IfES/iA5ulbqukriPKnI FXXlMpX8JOOuf62Of29RcNFbEh+/45zgEKMhJuEMC/zTOZ8YOfBWNkF2ovyBnAHj IVqJ8vESq9fyDZ13RvPws3R4bqglejS/b8eKRfdyaIZ02riJfmDkhmcLmUAg==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-type:content-type:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:subject:subject:to :to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t= 1768794993; x=1768881393; bh=NhGNCehkZv01UwtYE1S7iseCLKrN8q1x8Kl 63p9z0KE=; b=VXHi/+bF4r20EudanBI4HYwizqbKXS2JQqcH/Tlz7q+g09bnOad kz2UyxGj0I7pCZvHZt+5oKFCl3DiThi5W/ZO0Rt3Xd/NWKOKnvWQseOiKF/G020G 48VfljCwKlrR0b9pfJF7FMd0K8EqDkn5DKT5f2tolxrzfCHw8Pf+jaD0k38ybXtS 9gF1WbTO/rDrb+HMpeDxIxJQbeXEkY4nT8CwoSaeJTzuhfEZ44Yeyt99DaJTjpLc WHN6lpaEk4MQ7t8b90G6nF4Ahob/ry/sI+bqi9V7x5Gp4BmntT7k3ibg8Z7VsqAG 1SlFmQEVy+m/dtd82E0QDV94R6F5z42Ir3g==
X-ME-Sender: <xms:cattaS99RDQ4Z6Od1-SnzCNmPfSoPlg-7rKklGyUzksdFVztUYgYVA> <xme:cattaacKwNulg-ETArmXsPKf8i2BJ5Limm2IUF1xrQJ8_7MLtzWZHwj4rKOMO-qTv s2_9WpYYoH8GN4tj8K_tdxiBTiZecq2-DjhAPXEDZnfrGd96qZKYJk>
X-ME-Received: <xmr:cattabEOrCjLXKkTaaLeHzEciZeP-v4Yd7yt-PHM5W0DuRU6IqJ6gE2gKajObZCHYywr0SpmUUMet3Cyf5ZwW-jlj_Uz-lib7Dk2>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefgedrtddtgddufeeiheehucetufdoteggodetrf dotffvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfurfetoffkrfgpnffqhgenuceu rghilhhouhhtmecufedttdenucenucfjughrpefhkfgtggfuffgjvefvfhfosegrtdhmre hhtdejnecuhfhrohhmpefqnhgurhgvjhcuufhurhpuuceoohhnughrvghjsehsuhhrhidr ohhrgheqnecuggftrfgrthhtvghrnhephfehkeetvdekteekueevgffgvdfgveejheejvd eftefghfekgfelkeevkeffheffnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghm pehmrghilhhfrhhomhepohhnughrvghjsehsuhhrhidrohhrghdpnhgspghrtghpthhtoh epfedpmhhouggvpehsmhhtphhouhhtpdhrtghpthhtohepjhgrsghlvgihpeegtdhsthhr rghnughkihhprdhnlhesughmrghrtgdrihgvthhfrdhorhhgpdhrtghpthhtoheplhhisg horhdrphgvlhhtrghnpeegtdhnihgtrdgtiiesughmrghrtgdrihgvthhfrdhorhhgpdhr tghpthhtohepughnshhophesihgvthhfrdhorhhg
X-ME-Proxy: <xmx:cattaYfIMvpbpY3TwMoS4aFkoglucXtKoyicF5DZWB8rqobMf686cg> <xmx:cattaVG1D4RthGhQ_mZBk555piPNTbSU5GZw5eobOewDnwVNzr6i-g> <xmx:cattaRW6cR8vElpJaXNiCZnXUzeSHAjRgPGnWByEISliTTzI9efyTA> <xmx:cattacIm4b9Hx9HnH6coa69LlwqrPS_sYoUCd2_03OD5CxGhJpntXA> <xmx:cattaRSHv9Yp81zVy9_o23_Q9eQrDsE1YyuAcGBe4Hwi0Aij-BQ58SC2>
Feedback-ID: ida81469e:Fastmail
Received: by mail.messagingengine.com (Postfix) with ESMTPA; Sun, 18 Jan 2026 22:56:33 -0500 (EST)
From: Ondřej Surý <ondrej@sury.org>
Message-Id: <8FBA6895-AADD-42F7-AF33-543A079F4934@sury.org>
Content-Type: multipart/alternative; boundary="Apple-Mail=_FCE7C1A2-336F-4452-9FAB-79995015163F"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3864.400.12\))
Date: Mon, 19 Jan 2026 04:56:23 +0100
In-Reply-To: <8DDA7DF4-85D7-41BC-A39B-0C125474EDD9@strandkip.nl>
To: Joe Abley <jabley=40strandkip.nl@dmarc.ietf.org>
References: <102fa8f6-4c04-4c5c-b49d-c31ff812817d@nic.cz> <8DDA7DF4-85D7-41BC-A39B-0C125474EDD9@strandkip.nl>
X-Mailer: Apple Mail (2.3864.400.12)
Message-ID-Hash: ZBO5VUF62YIAJLP2NEN6SV5Y5JF3NCVX
X-Message-ID-Hash: ZBO5VUF62YIAJLP2NEN6SV5Y5JF3NCVX
X-MailFrom: ondrej@sury.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Libor Peltan <libor.peltan=40nic.cz@dmarc.ietf.org>, dnsop <dnsop@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: ordering of RRSets in the answer section of a DNS response
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/GLWBYtmIkvgYWytu2j573SFxkFE>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
> On 15. 1. 2026, at 12:41, Joe Abley <jabley=40strandkip.nl@dmarc.ietf.org> wrote: > >> I think that you are motivated by the scale how the broken clients are wide-spread, and how crippled upgrade policies prevent upgrading them in reasonable time. However, writing and publishing an RFC also doesn't happen in a short time. > > Yes, that's totally the motivation. > > I think of this as an investment in the future; if we can avoid future disasters (even small ones) by making a decision now, I think the return on investment is reasonable. The last time we used the "scale" as a motivation, we got serve-stale, a DNS protocol breaking bandaid, and we all still suffer from that. > On 15. 1. 2026, at 3:29, John Levine <johnl@taugh.com> wrote: > > It appears that Libor Peltan <libor.peltan@nic.cz> said: >> Anyway, shouldn't we rather go the opposite way of declaring that any >> section of DNS response is unordered (why should the answer section be >> special?) and the receiver MUST be able to find all the wanted info >> regardless -- even in ridiculous cases when the CNAME target is put >> first and the CNAME itself afterwards...? > > It seems to me that if we are going to say anything, we should both say that > caches and forwarders have to emit the records in chain order so that badly > written stubs won't break, and stubs have to accept records in any order so > badly written caches won't break them. If anything, I would say that the language should be: - caches and forwarders SHOULD emit the records in chain order so that badly written stubs won't break - stubs resolvers MUST accept records in any order so badly written caches won't break them Ondrej -- Ondřej Surý (He/Him) ondrej@sury.org
- [DNSOP] ordering of RRSets in the answer section … Joe Abley
- [DNSOP] Re: ordering of RRSets in the answer sect… Petr Špaček
- [DNSOP] Re: ordering of RRSets in the answer sect… Robert Edmonds
- [DNSOP] Re: ordering of RRSets in the answer sect… Paul Wouters
- [DNSOP] Re: ordering of RRSets in the answer sect… Robert Edmonds
- [DNSOP] Re: ordering of RRSets in the answer sect… Peter Thomassen
- [DNSOP] Re: ordering of RRSets in the answer sect… Petr Špaček
- [DNSOP] Re: ordering of RRSets in the answer sect… Petr Špaček
- [DNSOP] Re: ordering of RRSets in the answer sect… Joe Abley
- [DNSOP] Re: ordering of RRSets in the answer sect… Florian Weimer
- [DNSOP] Re: ordering of RRSets in the answer sect… Joe Abley
- [DNSOP] Re: ordering of RRSets in the answer sect… Florian Weimer
- [DNSOP] Re: ordering of RRSets in the answer sect… Dave Lawrence
- [DNSOP] Re: ordering of RRSets in the answer sect… Florian Weimer
- [DNSOP] Re: ordering of RRSets in the answer sect… Mark Andrews
- [DNSOP] Re: ordering of RRSets in the answer sect… Libor Peltan
- [DNSOP] Re: ordering of RRSets in the answer sect… Warren Kumari
- [DNSOP] Re: ordering of RRSets in the answer sect… Philip Homburg
- [DNSOP] Re: ordering of RRSets in the answer sect… Ondřej Surý
- [DNSOP] Re: ordering of RRSets in the answer sect… Paul Wouters
- [DNSOP] Re: ordering of RRSets in the answer sect… John Levine
- [DNSOP] Re: ordering of RRSets in the answer sect… Manu Bretelle
- [DNSOP] Re: ordering of RRSets in the answer sect… Joe Abley
- [DNSOP] Re: ordering of RRSets in the answer sect… Manu Bretelle
- [DNSOP] Re: ordering of RRSets in the answer sect… Florian Weimer
- [DNSOP] Re: ordering of RRSets in the answer sect… Philip Homburg
- [DNSOP] Re: ordering of RRSets in the answer sect… Petr Špaček
- [DNSOP] Re: ordering of RRSets in the answer sect… Philip Homburg
- [DNSOP] Re: ordering of RRSets in the answer sect… Mark Andrews
- [DNSOP] Re: ordering of RRSets in the answer sect… Philip Homburg
- [DNSOP] Re: ordering of RRSets in the answer sect… Mark Andrews
- [DNSOP] Re: ordering of RRSets in the answer sect… Philip Homburg
- [DNSOP] Re: ordering of RRSets in the answer sect… John R Levine
- [DNSOP] Re: ordering of RRSets in the answer sect… Ángel
- [DNSOP] Re: ordering of RRSets in the answer sect… John Levine
- [DNSOP] Re: ordering of RRSets in the answer sect… Florian Weimer
- [DNSOP] Re: ordering of RRSets in the answer sect… Ángel
- [DNSOP] Re: ordering of RRSets in the answer sect… Joe Abley
- [DNSOP] Re: ordering of RRSets in the answer sect… Libor Peltan
- [DNSOP] Re: ordering of RRSets in the answer sect… Kevin P. Fleming
- [DNSOP] Re: ordering of RRSets in the answer sect… Joe Abley
- [DNSOP] Re: ordering of RRSets in the answer sect… Ondřej Surý
- [DNSOP] Re: ordering of RRSets in the answer sect… Ángel
- [DNSOP] Re: ordering of RRSets in the answer sect… Joe Abley
- [DNSOP] Re: ordering of RRSets in the answer sect… John Levine
- [DNSOP] Re: ordering of RRSets in the answer sect… Ángel
- [DNSOP] Re: ordering of RRSets in the answer sect… X L
- [DNSOP] Re: ordering of RRSets in the answer sect… Mark Andrews
- [DNSOP] Re: ordering of RRSets in the answer sect… Paul Wouters