Commit 14ecb465bb for bind

commit 14ecb465bb567c7319b5d19dfe3b4c7b288e9869
Author: Nicki Křížek <nicki@isc.org>
Date:   Fri Oct 2 10:03:32 2026 +0000

    Match key tags exactly in key tag checks

    A key tag searched for as a plain substring also matches longer tags
    that contain it, so these checks could pass on the wrong key.

    Assisted-by: Claude:claude-opus-5-5

diff --git a/bin/tests/system/isctest/kasp.py b/bin/tests/system/isctest/kasp.py
index 83b7ba5064..da9292b4c9 100644
--- a/bin/tests/system/isctest/kasp.py
+++ b/bin/tests/system/isctest/kasp.py
@@ -920,7 +920,7 @@ def check_dnssecstatus(server, zone, keys, policy=None, view=None, verbose=False

     for key in keys:
         if not key.external:
-            assert f"{key.role()} {key.tag}" in response.out
+            assert Re(rf"^{key.role()} {key.tag} \(") in response.out


 def _signed_by(rrset, rrsig, dnskey) -> bool:
diff --git a/bin/tests/system/mkeys/tests.sh b/bin/tests/system/mkeys/tests.sh
index fe99fe2f60..6df1041a36 100644
--- a/bin/tests/system/mkeys/tests.sh
+++ b/bin/tests/system/mkeys/tests.sh
@@ -551,7 +551,7 @@ count=$(grep -c "keyid: " rndc.out.$n) || true
   ret=1
 }
 # it's the original key id
-count=$(grep -c "keyid: $originalid" rndc.out.$n) || true
+count=$(grep -c "keyid: $originalid\$" rndc.out.$n) || true
 [ "$count" -eq 1 ] || {
   echo_i "'keyid: $originalid' count ($count) != 1"
   ret=1
@@ -631,7 +631,7 @@ mkeys_status_on 2 >rndc.out.2.$n 2>&1 || ret=1
 count=$(grep -c "keyid: " rndc.out.2.$n) || true
 [ "$count" -eq 1 ] || ret=1
 # it's the original key id
-count=$(grep -c "keyid: $originalid" rndc.out.2.$n) || true
+count=$(grep -c "keyid: $originalid\$" rndc.out.2.$n) || true
 [ "$count" -eq 1 ] || ret=1
 # not revoked
 count=$(grep -c "REVOKE" rndc.out.2.$n) || true
@@ -669,7 +669,7 @@ mkeys_status_on 2 >rndc.out.2.$n 2>&1 || ret=1
 count=$(grep -c "keyid: " rndc.out.2.$n) || true
 [ "$count" -eq 1 ] || ret=1
 # it's the original key id
-count=$(grep -c "keyid: $originalid" rndc.out.2.$n) || true
+count=$(grep -c "keyid: $originalid\$" rndc.out.2.$n) || true
 [ "$count" -eq 1 ] || ret=1
 # not revoked
 count=$(grep -c "REVOKE" rndc.out.2.$n) || true
diff --git a/bin/tests/system/smartsign/tests.sh b/bin/tests/system/smartsign/tests.sh
index 70a4dc7990..2ba276b698 100644
--- a/bin/tests/system/smartsign/tests.sh
+++ b/bin/tests/system/smartsign/tests.sh
@@ -120,11 +120,11 @@ status=$((status + ret))

 echo_i "checking parent zone DNSKEY set"
 ret=0
-grep "key id = $pzid" $pfile.signed >/dev/null || {
+grep "key id = $pzid\$" $pfile.signed >/dev/null || {
   ret=1
   echo_i "missing expected parent ZSK id = $pzid"
 }
-grep "key id = $pkid" $pfile.signed >/dev/null || {
+grep "key id = $pkid\$" $pfile.signed >/dev/null || {
   ret=1
   echo_i "missing expected parent KSK id = $pkid"
 }