[DNSOP] Re: ordering of RRSets in the answer section of a DNS response

John R Levine <johnl@taugh.com> Fri, 16 January 2026 15:32 UTC

Return-Path: <johnl@taugh.com>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 75E7FA8A540A for <dnsop@mail2.ietf.org>; Fri, 16 Jan 2026 07:32:09 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.401
X-Spam-Level:
X-Spam-Status: No, score=-4.401 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=iecc.com header.b="W3sSrtFD"; dkim=pass (2048-bit key) header.d=taugh.com header.b="UcVXxd7p"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8lB51RUBUfIz for <dnsop@mail2.ietf.org>; Fri, 16 Jan 2026 07:32:09 -0800 (PST)
Received: from gal.iecc.com (gal.iecc.com [IPv6:2001:470:1f07:1126:0:43:6f73:7461]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id ED927A8A5404 for <dnsop@ietf.org>; Fri, 16 Jan 2026 07:32:08 -0800 (PST)
Received: (qmail 69881 invoked from network); 16 Jan 2026 15:32:02 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=iecc.com; h=date:message-id:from:to:cc:subject:in-reply-to:references:mime-version:content-type; s=110f7696a59f2.k2601; t=1768577512; x=1768923112; bh=cqejXBljRaulASKfbB0ZUbEllUdG0A9Ek/z72tomSfg=; b=W3sSrtFDB4+CC+RTzNee5EnU3RXCFJ9XKtdL9mWjel93A9y0YX/XBVUdr7NVpD4y3UHsoOV6w7e3S5OCp8Mfj8085oMTRsGsmPM+v9kC9N/bySOctz+vyJE4SiF2OmOEeANvZx69EvbeaL+cd5SA4hq7kiDiYy2G1hfFWJH6Y6y2iXnMWRI8CK8MT0FPZhTQ6lysWZRGs1Ll9AZtDLr218Ocmpxe7ZdIj9/IsMhTK367CbTPNTslm4xtchOiLKvZoN0608C+yQL5GCFZc7bf5lzLMf3jypfo8A+6lu+wR/EPjXnDzZsBxTozVPL6g6cyrCL6WdkRv8mfyVZ1QUyasQ==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=taugh.com; h=date:message-id:from:to:cc:subject:in-reply-to:references:mime-version:content-type; s=110f7696a59f2.k2601; bh=cqejXBljRaulASKfbB0ZUbEllUdG0A9Ek/z72tomSfg=; b=UcVXxd7ptgNR9cDU/i+xDpdEuQYjCiaZgicttWkS54ZLmq7OX9I6o/Rwg2+IO0OP4ignCq8c62vy/0oZ0cWZh5rSrzjU/wRyKe0eSa6q7l3BdSOFMWM03bNx4Gga+ds6q/o02aON/D26GfHBlz5hFObOESf8RQCwmTy917ny/SS6yNjVBbSRdSjN/shww7jQwEkRE3MWOybFqix+TwRkBwPro6EDp7Bar0la7Tx8OQdQOTqIxJrL1G7PHfVRvNyQEHi15UsOR8CbtfXs/WljKFKTHqRZ1YuFyBGbeYBJhTB8WFuO3xljnUNIkv5GHJPEW55wO6pKMNT/n50lACSG8Q==
Received: from ary.qy ([IPv6:2001:470:1f07:1126:0:78:696d:6170]) by imap.iecc.com ([IPv6:2001:470:1f07:1126:0:78:696d:6170]) with ESMTPS (TLS1.3 ECDHE-RSA CHACHA20-POLY1305 AEAD) via TCP6; 16 Jan 2026 15:32:02 -0000
Received: by ary.qy (Postfix, from userid 501) id B7C85F1695DB; Fri, 16 Jan 2026 10:32:01 -0500 (EST)
Received: from localhost (localhost [127.0.0.1]) by ary.qy (Postfix) with ESMTP id 84467F1695BD; Fri, 16 Jan 2026 10:32:01 -0500 (EST)
Date: Fri, 16 Jan 2026 10:32:01 -0500
Message-ID: <b07a269a-ed1b-8bed-8d99-52619f4f5e14@taugh.com>
From: John R Levine <johnl@taugh.com>
To: Florian Weimer <fw@deneb.enyo.de>
In-Reply-To: <877bth4z9c.fsf@mid.deneb.enyo.de>
References: <9175DF63-77F9-4B4C-9EA9-76B30F941F84@strandkip.nl> <e48c41c3-86cf-4e1f-a9ab-195426bdea17@nic.cz> <20260115022930.C70F4F11E0CD@ary.qy> <877bth4z9c.fsf@mid.deneb.enyo.de>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Message-ID-Hash: OXT3TLXVPLCMNFGNYH5EI2AQCBKMOK4I
X-Message-ID-Hash: OXT3TLXVPLCMNFGNYH5EI2AQCBKMOK4I
X-MailFrom: johnl@taugh.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: dnsop@ietf.org, libor.peltan@nic.cz
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: ordering of RRSets in the answer section of a DNS response
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/dh9zntMQ_eXTPb169C0gplr9nMY>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

On Fri, 16 Jan 2026, Florian Weimer wrote:
>> It seems to me that if we are going to say anything, we should both say that
>> caches and forwarders have to emit the records in chain order so that badly
>> written stubs won't break, and stubs have to accept records in any order so
>> badly written caches won't break them.
>
> Can stubs just ignore CNAMEs and just extract addresses from A and AAAA
> records found in the answer section?

My impression is that's pretty common and it's not obvious to me what the 
point of the stub following the CNAME chain is.  If it doesn't trust the 
cache to provide the right results, there are a lot wronger things than 
funky CNAMEs and stray A records.

Regards,
John Levine, johnl@taugh.com, Taughannock Networks, Trumansburg NY
Please consider the environment before reading this e-mail. https://jl.ly