Commit 1d382d1082 for bind
commit 1d382d1082ac1e6491286080535267b23e3b95a4
Author: Nicki Křížek <nicki@isc.org>
Date: Fri Oct 2 10:03:42 2026 +0000
Look for the deleted key in the autosign delzsk test
zsk_is_gone() waited for the DNSKEY RRset of delzsk.example to no
longer hold a key with the tag in $oldid, which was left over from the
root zone ZSK rollover test, instead of the tag of the deleted key. So
it never checked the deletion. And if one of the remaining
delzsk.example keys happened to share the root ZSK's key tag, that key
never went away, and the check timed out.
Assisted-by: Claude:claude-opus-5-5
diff --git a/bin/tests/system/autosign/tests.sh b/bin/tests/system/autosign/tests.sh
index dc7175e131..fa463461e3 100755
--- a/bin/tests/system/autosign/tests.sh
+++ b/bin/tests/system/autosign/tests.sh
@@ -1196,6 +1196,7 @@ echo_i "checking for out-of-zone NSEC3 records after ZSK removal ($n)"
ret=0
# Delete the ZSK
file="ns3/inactive/$(cat delzsk.key).key"
+id=$(keyfile_to_key_id "$(cat delzsk.key)")
$NSUPDATE >nsupdate.out.test$n 2>&1 <<END
server 10.53.0.3 ${PORT}
zone delzsk.example.
@@ -1205,7 +1206,7 @@ END
zsk_is_gone() {
$DIG $DIGOPTS +noall +multi +answer dnskey delzsk.example. @10.53.0.3 >dig.out.ns3.test$n || return 1
- grep '; key id = '"$oldid"'$' dig.out.ns3.test$n >/dev/null && return 1
+ grep '; key id = '"$id"'$' dig.out.ns3.test$n >/dev/null && return 1
return 0
}
retry_quiet 5 zsk_is_gone || ret=1