Just an FYI as I am most likely simply abusing rebound as it's config is so simple I just tried it and should probably use relayd for this atleast at the moment but perhaps it is a corner case that *may* be desired to be handled somehow differently?
rebound appears to be working fine locally but I decided to enable it on my WIFI access point when switched to gaming mode by diverting all packets to port 53 to 127.0.0.1 as in this mode machines don't get DNS ID randomisation and also I guessed it would reduce the attack surface a little too. It seemed to work for one or a few requests but crash with "child died without HUP" and under debug mode I got a segfault line. I tried with a recent snapshot too in case it may have been the pledge bug and it crashed then too though I didn't try it in debug mode. I can run any tests on the access point machine quite easily, if it *is* of any help. -- KISSIS - Keep It Simple So It's Securable

