TITLE:
vyos-domain-resolver crashes on blank lines in remote-group threat lists (IndexError) — all remote-group firewall rules silently non-functional
PRIORITY:
High
DESCRIPTION:
Summary
The vyos-domain-resolver daemon crashes with an IndexError when parsing remote-group threat lists that contain blank lines. This leaves ALL remote-group nftables sets empty (0 elements), silently disabling every firewall rule that references a remote-group.
Affected Component
File: /usr/libexec/vyos/services/vyos-domain-resolver
Function: update_remote_group()
Line: 173
Root Cause
The parser iterates lines from downloaded list files. When a blank line is encountered, line_first_word resolves to an empty string. The else branch attempts to index it without checking for emptiness:
for line in read_file(list_file).splitlines():
line_first_word = line.strip().partition(' ')[0]
if is_valid_ipv4_address_or_range(line_first_word):
ip_list.append(line_first_word)
elif is_valid_ipv6_address_or_range(line_first_word):
ip6_list.append(line_first_word)
else:
if line_first_word[0].isalnum(): # IndexError on ""
invalid_list.append(line_first_word)Traceback
Traceback (most recent call last):
File "/usr/libexec/vyos/services/vyos-domain-resolver", line 174, in update_remote_group
if line_first_word[0].isalnum():
~~~~~~~~~~~~~~~^^^
IndexError: string index out of rangeImpact
- Daemon enters a crash loop — systemd restarts it, it crashes again on the same file, indefinitely.
- ALL remote-group sets in nftables remain empty (verified: 0 elements across all tables).
- ALL firewall rules referencing remote-groups have zero matches.
- This silently disables threat intel filtering (tor, emerging threats, binarydefense, blacklist.de, CINS, interserver) and bogon filtering.
- Users have no indication their remote-group rules are non-functional — the firewall loads cleanly, rules exist, counters just never increment.
Trigger
Any remote-group URL whose response contains blank lines. Confirmed with:
- https://www.binarydefense.com/banlist.txt (1 blank line)
- https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt (15 blank lines)
Blank lines in threat intel feeds are normal and expected.
Verification
After the crash loop, confirmed empty sets:
- nft list set ip vyos_filter R_full-bogon | grep -c '/' 0
- nft list set ip vyos_filter R_binarydefense | grep -c '/' 0
- nft list set ip vyos_filter R_emerging_threats | grep -c '/' 0
All forward filter rules referencing these sets showed 0 packets matched:
ip saddr @R_emerging_threats ... counter packets 0 bytes 0 drop ip saddr @R_binarydefense ... counter packets 0 bytes 0 drop ip daddr @R_full-bogon ... counter packets 0 bytes 0 drop
Suggested Fix
Change line 173 from:
else:
To:
elif line_first_word:
This skips empty strings before attempting to index line_first_word[0]. Verified working in production — daemon stays running, all sets populate correctly, threat intel rules begin matching traffic.