Commit 300387c531 for bind

commit 300387c531d654a3bef4033f6632ef5e3cfdd720
Author: Nicki Křížek <nicki@isc.org>
Date:   Thu Sep 17 11:50:33 2026 +0000

    Fix expected ZRRSIG state timing in the ksr test

    check_keys() expected the ZRRSIG state to switch from rumoured to
    omnipresent within sign-delay (signatures-validity minus
    signatures-refresh) of key activation, but the offline keymgr keeps it
    rumoured for at least max-zone-ttl plus zone-propagation-delay. With
    the "fast" policy those are 4 seconds versus 80 minutes, so
    test_ksr_fast only passed when the key-state check ran within 4
    seconds of 'dnssec-ksr keygen' and failed on slow (TSAN) CI runs.

    Expect the full interval instead, adding sign-delay and retire-safety
    as the online keymgr does for rollovers. The offline keymgr only adds
    those with the next commit; until then, no check_keys() caller has a
    key activated within the difference, so the test passes either way.

    Assisted-by: Claude:claude-opus-5-5

diff --git a/bin/tests/system/ksr/tests_ksr.py b/bin/tests/system/ksr/tests_ksr.py
index 369d70fcdc..c9752b71b8 100644
--- a/bin/tests/system/ksr/tests_ksr.py
+++ b/bin/tests/system/ksr/tests_ksr.py
@@ -221,7 +221,13 @@ def check_keys(
         if retired is None or between(now, published, retired):
             goal = "omnipresent"
             pubdelay = published + pubtime
-            signdelay = active + sign_delay(config)
+            sigdelay = (
+                active
+                + sign_delay(config)
+                + config["max-zone-ttl"]
+                + config["zone-propagation-delay"]
+                + config["retire-safety"]
+            )

             if between(now, published, pubdelay):
                 state_dnskey = "rumoured"
@@ -233,7 +239,7 @@ def check_keys(
             if key.is_ksk():
                 state_ds = "hidden"
             else:
-                if between(now, active, signdelay):
+                if between(now, active, sigdelay):
                     state_zrrsig = "rumoured"
                 else:
                     state_zrrsig = "omnipresent"
@@ -1459,8 +1465,8 @@ def test_ksr_fast(ns1):
     isctest.kasp.check_dnssec_verify(ns1, zone)

     # - check keys
-    # named updates the state file asynchronously, so retry the state check
-    # until the rumoured -> omnipresent transition catches up.
+    # named writes the key states asynchronously after the SKR import, so
+    # retry until they appear in the state file.
     def check_keys_state():
         check_keys(zsks, lifetime, FASTCONFIG, with_state=True)
         return True