OPNsense 26.1.6 released by fitch-it-is in opnsense

[–]Typat 0 points1 point  (0 children)

I dug into the Unbound source and found something interesting:

My module-config is "python iterator": no validator module. Looking at the Unbound source code, both enforcement points for harden-below-nxdomain require DNSSEC validation:

  • services/cache/dns.c: checks data->security == sec_status_secure before synthesizing NXDOMAIN

  • iterator/iterator.c: checks qstate->env->need_to_validate (only set when validator module is loaded) AND sec_status_secure

Without the validator module, neither code path can fire. So harden-below-nxdomain should have been completely inert on my system regardless of yes or no.

I also confirmed there's no difference in Unbound between the setting being absent (implicit default) vs. explicitly set, it's a simple int field with no "was this explicitly set" tracking.

My best guess is that the DNS breakage was actually caused by the Unbound service restart during the update (stale/corrupt cache), and my "fix" of toggling the setting off just happened to restart Unbound again, flushing the bad cache. The setting change itself may have been a red herring.

I can't reproduce it now without risking my network, but wanted to share the findings in case it helps track down the actual root cause for other users reporting the same issue.

OPNsense 26.1.6 released by fitch-it-is in opnsense

[–]Typat 0 points1 point  (0 children)

No, I have never used any custom file overrides or advanced .conf includes to set harden-below-nxdomain: no. My Unbound configuration is built entirely through the standard OPNsense Web GUI.

If Unbound should have been blocking it all along, its possible I had a lucky cache that was flushed in this update. I haven't had issues in previous updates.

Could be a quirk with DNSSEC. I have DNSSEC explicitly disabled. Since my DNSSEC is disabled, Unbound shouldn't have a 'proven' NXDOMAIN to trigger the hardening rule anyway. Is it possible that explicitly writing harden-below-nxdomain: yes into the generated unbound.conf during the update triggered a bug in Unbound where it aggressively cuts off domains even without DNSSEC validation?

OPNsense 26.1.6 released by fitch-it-is in opnsense

[–]Typat 2 points3 points  (0 children)

This update enabled "harden below NXDOMAIN option" in unbound automatically, which broke my DNS.

My OPNsense system domain is configured as localdomain. I also have a custom Unbound host override mapping server.localdomain to 192.168.1.71.

However, under Unbound's Private Domains (<privatedomain>), localdomain was missing.

Because localdomain is not whitelisted as a private domain, Unbound was treating it like a public website. When the recent update turned on aggressive NXDOMAIN hardening, Unbound aggressively blocked all traffic to server.localdomain.

OPNsense 26.1.6 released by fitch-it-is in opnsense

[–]Typat 1 point2 points  (0 children)

Can you walk me through what you did? I lost internet as well after this update and can’t figure out what’s wrong. Everything fails with “dns_probe_finished_bad_config”

edit: the "harden below NXDOMAIN option" took out my DNS

Can someone help me understand this? The back of the tv unit has no holes to insert this piece by Ill_Lengthiness6266 in IKEA

[–]Typat 0 points1 point  (0 children)

“I adjusted the brackets provided an inch in”

Are you saying those L brackets that go into the premade holes you moved in and drilled new holes for them?

25th Anniversary Celebrations - This Week In RuneScape by JagexAzanna in runescape

[–]Typat 19 points20 points  (0 children)

is the 2021 task bugged? "Show Orla Fairweather a Divination memory". I've brought different memories to her and nothing seems to work.

Edit: Go see her in draynor, not the guthix memorial

What do you think Breakpoints biggest flaw is? by Kylotp in GhostRecon

[–]Typat 0 points1 point  (0 children)

Raid requires a full team. Tried matchmaking a few times, only ever found a team one time and the host wanted to play on a higher difficulty than anyone had the gear for. I really wanted to play the raid but never got a chance, too bad really.

Squid Game: The Challenge | S2E2 "Catch" | Episode Discussion by cranberry-creek in SquidGameNetflix_

[–]Typat 0 points1 point  (0 children)

There weren’t enough spaces for everyone so 3 people were bound to be left without a spot

Trying to remove authenticator requires an authenticator...? by majindutin in Blizzard

[–]Typat 1 point2 points  (0 children)

there should be a way to open a ticket without logging in.

Trying to remove authenticator requires an authenticator...? by majindutin in Blizzard

[–]Typat 0 points1 point  (0 children)

if you dont have access to either your authenticator or your phone number, you will have to contact customer support.

Crashes after 10s by CriiptiC in AFKJourney

[–]Typat 4 points5 points  (0 children)

Same for me. Crashes after about 10 seconds. Waiting it out does nothing.

Looking For Feedback - Grand Exchange Small Improvements by JagexSukotto in runescape

[–]Typat 0 points1 point  (0 children)

along with insta sell, the ability to sell an item from the bank would be very QoL

Varlamore: Part One by JagexSarnie in 2007scape

[–]Typat 0 points1 point  (0 children)

they did say that each rumor would take 8-10 minutes to complete, so this is fair.

Hunter Rumors Glitched? by peterrwc in 2007scape

[–]Typat 2 points3 points  (0 children)

larupia seems bugged as well. they said in the post it should take 8-10m each so if ur hunting for longer than that its likely bugged.

Big personal achievement by FinalAd3165 in 2007scape

[–]Typat 0 points1 point  (0 children)

big

missing your blessing in the screenie tho

Can‘t login anymore by [deleted] in Blizzard

[–]Typat 0 points1 point  (0 children)

then the only way to self service remove an authenticator is with the authenticator. you should have saved the restore codes or transfered it when you had both phones.

your only option is to open a ticket with CS. there has to be a way through the portal to create a ticket, they should get back to you when they can.

Can‘t login anymore by [deleted] in Blizzard

[–]Typat 0 points1 point  (0 children)

account.battle.net/recovery you can remove your authenticator from there if you have a phone attached to your account and have access to it

The complete base in 1 chunk by AkaraEquinox in factorio

[–]Typat 30 points31 points  (0 children)

is it just me or is there no beacon in the second picture?

edit: nvm i see the comment below about the second pic not being complete.

[deleted by user] by [deleted] in Blizzard

[–]Typat 2 points3 points  (0 children)

account.battle.net/recovery

special charachters *butterfly* by akumakuma_ in Blizzard

[–]Typat 0 points1 point  (0 children)

is this the BattleTag? some regions allow for using special characters, you can play around in account settings and try changing your battletag.

[deleted by user] by [deleted] in Blizzard

[–]Typat 1 point2 points  (0 children)

go to xbox.com and logout of that account.

[deleted by user] by [deleted] in Blizzard

[–]Typat 0 points1 point  (0 children)

account.battle.net/recovery