[DNSOP] Re: ordering of RRSets in the answer section of a DNS response
Mark Andrews <marka@isc.org> Sun, 18 January 2026 22:55 UTC
Return-Path: <marka@isc.org>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 0A85BA96FBF1 for <dnsop@mail2.ietf.org>; Sun, 18 Jan 2026 14:55:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.399
X-Spam-Level:
X-Spam-Status: No, score=-4.399 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=isc.org header.b="Iql7Rh9+"; dkim=pass (1024-bit key) header.d=isc.org header.b="QB57zSKi"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1gN1btiF6bHP for <dnsop@mail2.ietf.org>; Sun, 18 Jan 2026 14:55:13 -0800 (PST)
Received: from mx.pao1.isc.org (mx.pao1.isc.org [149.20.2.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 4253FA96FBE7 for <dnsop@ietf.org>; Sun, 18 Jan 2026 14:55:13 -0800 (PST)
Received: from zimbra10.isc.org (zimbra10.isc.org [149.20.2.90]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mx.pao1.isc.org (Postfix) with ESMTPS id BDF6B4E43A1; Sun, 18 Jan 2026 22:55:05 +0000 (UTC)
ARC-Filter: OpenARC Filter v1.0.0 mx.pao1.isc.org BDF6B4E43A1
Authentication-Results: mx.pao1.isc.org; arc=none smtp.remote-ip=149.20.2.90
ARC-Seal: i=1; a=rsa-sha256; d=isc.org; s=ostpay; t=1768776905; cv=none; b=QbSnh0UIA9JS3iokHZxj5cMLW8BIOjIgkJT+TljVdaEPir49K6t6CwZwJ84zKa1/vWopwREyYcRw+l0ELqaw0sJH6kOjhMQOCmcia9AM106kSgU0EQcamTo+9n2wIMp63zu86oPQodLpxMycbeLznJcdwchQUoNBDw9OqhmxLhs=
ARC-Message-Signature: i=1; a=rsa-sha256; d=isc.org; s=ostpay; t=1768776905; c=relaxed/relaxed; bh=NNZYC86GyzRzoafYM0hAPZk6DpwTpeCdlyv4cCP3Gas=; h=DKIM-Signature:DKIM-Signature:Mime-Version:Subject:From:Date: Message-Id:To; b=O0bnB2d061j5IGFu+/4Y1TvtdpOuH+WTtDqggQ6USJlmxukqUyG+yR4vHWfVUIARDK6MH2EilcMQxiJxNVDhFZWlaihLG30ca7XTxVvlQv0MwalZKhgWq5BYNvYVyle+mPNZM6/y61dgPPHejNNn7/VYPvEAFAaVRhpA91EEtgM=
ARC-Authentication-Results: i=1; mx.pao1.isc.org
DKIM-Filter: OpenDKIM Filter v2.10.3 mx.pao1.isc.org BDF6B4E43A1
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=isc.org; s=ostpay; t=1768776905; bh=1TEzAMTzt2AgYo/j6JW6FPWDXBIvpJNC76T+FWhSFFM=; h=Subject:From:In-Reply-To:Date:Cc:References:To; b=Iql7Rh9+M2r1zHrvUhstqCT10bh7r2iOm0JWzSGdAOCA1z36jbnRLszl7OtCjIIdA ZMmKMx4RpDgZeYJeAfI5Dy/b1nmx7Tn2ze/iT3Luo0ZDklxG9+/gkhIgEZt+3cCCp+ UtySkPLLQNAJqT0Sxrv64dJYc56tKQvF6xtVfrwM=
Received: from zimbra10.isc.org (localhost [127.0.0.1]) by zimbra10.isc.org (Postfix) with ESMTPS id B898E2E602A0; Sun, 18 Jan 2026 22:55:05 +0000 (UTC)
Received: from zimbra10.isc.org (localhost [127.0.0.1]) by zimbra10.isc.org (Postfix) with ESMTPS id B4CA42E602C5; Sun, 18 Jan 2026 22:55:05 +0000 (UTC)
DKIM-Filter: OpenDKIM Filter v2.10.3 zimbra10.isc.org B4CA42E602C5
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=isc.org; s=05DFB016-56A2-11EB-AEC0-15368D323330; t=1768776905; bh=NNZYC86GyzRzoafYM0hAPZk6DpwTpeCdlyv4cCP3Gas=; h=Mime-Version:From:Date:Message-Id:To; b=QB57zSKiAyjM9gf9xKmT/aAYQ0cbIo5f5LLiSw1F73Dqzb03XO67VWErwaH+Urp03 XfGJ9tdrp23+PA0hIoTN9oFAsVKrw1KnOcv7HPUcf9GjQ4fqMkAbD66K3zskpIXYOx 5YY1RwAGULsGE9yyd6iERb5M4FOBMjakuzSwlXxY=
Received: from smtpclient.apple (unknown [49.187.18.238]) by zimbra10.isc.org (Postfix) with ESMTPSA id 093872E602A0; Sun, 18 Jan 2026 22:55:04 +0000 (UTC)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.700.6.1.21\))
From: Mark Andrews <marka@isc.org>
In-Reply-To: <875x94rufa.fsf@mid.deneb.enyo.de>
Date: Mon, 19 Jan 2026 09:54:51 +1100
Content-Transfer-Encoding: quoted-printable
Message-Id: <97F160C2-31CB-4611-A39A-0B81F49E934D@isc.org>
References: <9175DF63-77F9-4B4C-9EA9-76B30F941F84@strandkip.nl> <875x94rufa.fsf@mid.deneb.enyo.de>
To: Florian Weimer <fw@deneb.enyo.de>
X-Mailer: Apple Mail (2.3731.700.6.1.21)
Message-ID-Hash: 7NJP63KP6B45BLMNGHYD4MJRGCJXHV4E
X-Message-ID-Hash: 7NJP63KP6B45BLMNGHYD4MJRGCJXHV4E
X-MailFrom: marka@isc.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Joe Abley <jabley=40strandkip.nl@dmarc.ietf.org>, dnsop <dnsop@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: ordering of RRSets in the answer section of a DNS response
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/hvPHgVBK3ZMYqx7RiXo46zLycDQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
> On 15 Jan 2026, at 04:11, Florian Weimer <fw@deneb.enyo.de> wrote: > > * Joe Abley: > >> https://datatracker.ietf.org/doc/draft-jabley-dnsop-ordered-answer-section/ >> >> The new draft is essentially the old draft plus references to last >> week's observed impact with reference to Cloudflare's comments above >> and a description of the impact from cisco (whose ethernet switches >> were the ones rebooting). > > I think it's been previously observed that compression is not actually > optional in practice, that is, the first answer record needs to start > with 0xc0 0x0c. It's not really related to ordering, but it fits > the underlying theme of producing maximally compatible responses. > > _______________________________________________ > DNSOP mailing list -- dnsop@ietf.org > To unsubscribe send an email to dnsop-leave@ietf.org Requiring 0xc0 0xc0 indicates that the developers reverse engineered the DNS protocol. When you reverse engineer the protocol you get things WRONG! STD 13 requires that servers be case preserving (as entered in the zone file or equivalent) which implies that 0xc0 0xc0 is not guaranteed to be the first octets of the answer section. Additionally with QUERY responses with DNAMEs the answer section does not start with 0xc0 0xc0 as the DNAME is supposed to come first so even if the server is not case preserving the compression pointer isn’t to the start of the question section. Devices that require that the answer section starts with 0xc0 0xc0 are just plain broken should be upgraded / returned to the manufacture as not fit for purpose. There are very few devices with this fault. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: marka@isc.org
- [DNSOP] ordering of RRSets in the answer section … Joe Abley
- [DNSOP] Re: ordering of RRSets in the answer sect… Petr Špaček
- [DNSOP] Re: ordering of RRSets in the answer sect… Robert Edmonds
- [DNSOP] Re: ordering of RRSets in the answer sect… Paul Wouters
- [DNSOP] Re: ordering of RRSets in the answer sect… Robert Edmonds
- [DNSOP] Re: ordering of RRSets in the answer sect… Peter Thomassen
- [DNSOP] Re: ordering of RRSets in the answer sect… Petr Špaček
- [DNSOP] Re: ordering of RRSets in the answer sect… Petr Špaček
- [DNSOP] Re: ordering of RRSets in the answer sect… Joe Abley
- [DNSOP] Re: ordering of RRSets in the answer sect… Florian Weimer
- [DNSOP] Re: ordering of RRSets in the answer sect… Joe Abley
- [DNSOP] Re: ordering of RRSets in the answer sect… Florian Weimer
- [DNSOP] Re: ordering of RRSets in the answer sect… Dave Lawrence
- [DNSOP] Re: ordering of RRSets in the answer sect… Florian Weimer
- [DNSOP] Re: ordering of RRSets in the answer sect… Mark Andrews
- [DNSOP] Re: ordering of RRSets in the answer sect… Libor Peltan
- [DNSOP] Re: ordering of RRSets in the answer sect… Warren Kumari
- [DNSOP] Re: ordering of RRSets in the answer sect… Philip Homburg
- [DNSOP] Re: ordering of RRSets in the answer sect… Ondřej Surý
- [DNSOP] Re: ordering of RRSets in the answer sect… Paul Wouters
- [DNSOP] Re: ordering of RRSets in the answer sect… John Levine
- [DNSOP] Re: ordering of RRSets in the answer sect… Manu Bretelle
- [DNSOP] Re: ordering of RRSets in the answer sect… Joe Abley
- [DNSOP] Re: ordering of RRSets in the answer sect… Manu Bretelle
- [DNSOP] Re: ordering of RRSets in the answer sect… Florian Weimer
- [DNSOP] Re: ordering of RRSets in the answer sect… Philip Homburg
- [DNSOP] Re: ordering of RRSets in the answer sect… Petr Špaček
- [DNSOP] Re: ordering of RRSets in the answer sect… Philip Homburg
- [DNSOP] Re: ordering of RRSets in the answer sect… Mark Andrews
- [DNSOP] Re: ordering of RRSets in the answer sect… Philip Homburg
- [DNSOP] Re: ordering of RRSets in the answer sect… Mark Andrews
- [DNSOP] Re: ordering of RRSets in the answer sect… Philip Homburg
- [DNSOP] Re: ordering of RRSets in the answer sect… John R Levine
- [DNSOP] Re: ordering of RRSets in the answer sect… Ángel
- [DNSOP] Re: ordering of RRSets in the answer sect… John Levine
- [DNSOP] Re: ordering of RRSets in the answer sect… Florian Weimer
- [DNSOP] Re: ordering of RRSets in the answer sect… Ángel
- [DNSOP] Re: ordering of RRSets in the answer sect… Joe Abley
- [DNSOP] Re: ordering of RRSets in the answer sect… Libor Peltan
- [DNSOP] Re: ordering of RRSets in the answer sect… Kevin P. Fleming
- [DNSOP] Re: ordering of RRSets in the answer sect… Joe Abley
- [DNSOP] Re: ordering of RRSets in the answer sect… Ondřej Surý
- [DNSOP] Re: ordering of RRSets in the answer sect… Ángel
- [DNSOP] Re: ordering of RRSets in the answer sect… Joe Abley
- [DNSOP] Re: ordering of RRSets in the answer sect… John Levine
- [DNSOP] Re: ordering of RRSets in the answer sect… Ángel
- [DNSOP] Re: ordering of RRSets in the answer sect… X L
- [DNSOP] Re: ordering of RRSets in the answer sect… Mark Andrews
- [DNSOP] Re: ordering of RRSets in the answer sect… Paul Wouters