Commit 35a4cf3953 for bind

commit 35a4cf3953eeafaf4a8cb56ce1b9e7a184d5cde4
Author: Nicki Křížek <nicki@isc.org>
Date:   Fri Oct 2 10:03:42 2026 +0000

    Pass the algorithm to rndc dnssec -checkds in rollover steps

    During an algorithm rollover, the KSKs of the two algorithms may share
    a key tag. named then refuses to pick one of them, the DS is never
    marked as published or withdrawn, and the rollover step times out.

    Assisted-by: Claude:claude-opus-5-5

diff --git a/bin/tests/system/isctest/kasp.py b/bin/tests/system/isctest/kasp.py
index da9292b4c9..050de2a384 100644
--- a/bin/tests/system/isctest/kasp.py
+++ b/bin/tests/system/isctest/kasp.py
@@ -1366,12 +1366,14 @@ def check_rollover_step(server, config, policy, step):

             # The DS can be introduced. We ignore any parent registration delay,
             # so set the DS publish time to now.
-            server.rndc(f"dnssec -checkds -key {key.tag} published {zone}")
+            alg = key.algorithm.name
+            server.rndc(f"dnssec -checkds -key {key.tag} -alg {alg} published {zone}")

         if ds_swap and kp.metadata["DSState"] == "unretentive":
             # The DS can be withdrawn. We ignore any parent registration
             # delay, so set the DS withdraw time to now.
-            server.rndc(f"dnssec -checkds -key {key.tag} withdrawn {zone}")
+            alg = key.algorithm.name
+            server.rndc(f"dnssec -checkds -key {key.tag} -alg {alg} withdrawn {zone}")

     if check_keytimes_flag:
         check_keytimes(keys, expected)