Page MenuHomeVyOS Platform

The vyos-domain-resolver daemon crashes with an IndexError when processing remote-group threat lists that contain blank lines, leaving ALL remote-group nftables sets empty and all associated firewall rules non-functional.
Closed, ResolvedPublicBUG

Description

TITLE:
vyos-domain-resolver crashes on blank lines in remote-group threat lists (IndexError) — all remote-group firewall rules silently non-functional

PRIORITY:
High

DESCRIPTION:

Summary

The vyos-domain-resolver daemon crashes with an IndexError when parsing remote-group threat lists that contain blank lines. This leaves ALL remote-group nftables sets empty (0 elements), silently disabling every firewall rule that references a remote-group.

Affected Component

File: /usr/libexec/vyos/services/vyos-domain-resolver
Function: update_remote_group()
Line: 173

Root Cause

The parser iterates lines from downloaded list files. When a blank line is encountered, line_first_word resolves to an empty string. The else branch attempts to index it without checking for emptiness:

for line in read_file(list_file).splitlines():
    line_first_word = line.strip().partition(' ')[0]

    if is_valid_ipv4_address_or_range(line_first_word):
        ip_list.append(line_first_word)
    elif is_valid_ipv6_address_or_range(line_first_word):
        ip6_list.append(line_first_word)
    else:
        if line_first_word[0].isalnum():  # IndexError on ""
            invalid_list.append(line_first_word)

Traceback

Traceback (most recent call last):
  File "/usr/libexec/vyos/services/vyos-domain-resolver", line 174, in update_remote_group
    if line_first_word[0].isalnum():
       ~~~~~~~~~~~~~~~^^^
IndexError: string index out of range

Impact

  • Daemon enters a crash loop — systemd restarts it, it crashes again on the same file, indefinitely.
  • ALL remote-group sets in nftables remain empty (verified: 0 elements across all tables).
  • ALL firewall rules referencing remote-groups have zero matches.
  • This silently disables threat intel filtering (tor, emerging threats, binarydefense, blacklist.de, CINS, interserver) and bogon filtering.
  • Users have no indication their remote-group rules are non-functional — the firewall loads cleanly, rules exist, counters just never increment.

Trigger

Any remote-group URL whose response contains blank lines. Confirmed with:

Blank lines in threat intel feeds are normal and expected.

Verification

After the crash loop, confirmed empty sets:

  1. nft list set ip vyos_filter R_full-bogon | grep -c '/' 0
  2. nft list set ip vyos_filter R_binarydefense | grep -c '/' 0
  3. nft list set ip vyos_filter R_emerging_threats | grep -c '/' 0

All forward filter rules referencing these sets showed 0 packets matched:

ip saddr @R_emerging_threats ... counter packets 0 bytes 0 drop
ip saddr @R_binarydefense ... counter packets 0 bytes 0 drop
ip daddr @R_full-bogon ... counter packets 0 bytes 0 drop

Suggested Fix

Change line 173 from:

else:

To:

elif line_first_word:

This skips empty strings before attempting to index line_first_word[0]. Verified working in production — daemon stays running, all sets populate correctly, threat intel rules begin matching traffic.

Details

Version
2026.06.15-0056-rolling
Is it a breaking change?
Perfectly compatible
Issue type
Bug (incorrect behavior)

Event Timeline

sarthurdev changed the task status from Open to In progress.Jun 15 2026, 3:51 PM
sarthurdev claimed this task.
sarthurdev triaged this task as Normal priority.
sarthurdev changed Is it a breaking change? from Unspecified (possibly destroys the router) to Perfectly compatible.
sarthurdev moved this task from Need Triage to Completed on the VyOS Rolling board.