Commit 300387c531 for bind
commit 300387c531d654a3bef4033f6632ef5e3cfdd720
Author: Nicki Křížek <nicki@isc.org>
Date: Thu Sep 17 11:50:33 2026 +0000
Fix expected ZRRSIG state timing in the ksr test
check_keys() expected the ZRRSIG state to switch from rumoured to
omnipresent within sign-delay (signatures-validity minus
signatures-refresh) of key activation, but the offline keymgr keeps it
rumoured for at least max-zone-ttl plus zone-propagation-delay. With
the "fast" policy those are 4 seconds versus 80 minutes, so
test_ksr_fast only passed when the key-state check ran within 4
seconds of 'dnssec-ksr keygen' and failed on slow (TSAN) CI runs.
Expect the full interval instead, adding sign-delay and retire-safety
as the online keymgr does for rollovers. The offline keymgr only adds
those with the next commit; until then, no check_keys() caller has a
key activated within the difference, so the test passes either way.
Assisted-by: Claude:claude-opus-5-5
diff --git a/bin/tests/system/ksr/tests_ksr.py b/bin/tests/system/ksr/tests_ksr.py
index 369d70fcdc..c9752b71b8 100644
--- a/bin/tests/system/ksr/tests_ksr.py
+++ b/bin/tests/system/ksr/tests_ksr.py
@@ -221,7 +221,13 @@ def check_keys(
if retired is None or between(now, published, retired):
goal = "omnipresent"
pubdelay = published + pubtime
- signdelay = active + sign_delay(config)
+ sigdelay = (
+ active
+ + sign_delay(config)
+ + config["max-zone-ttl"]
+ + config["zone-propagation-delay"]
+ + config["retire-safety"]
+ )
if between(now, published, pubdelay):
state_dnskey = "rumoured"
@@ -233,7 +239,7 @@ def check_keys(
if key.is_ksk():
state_ds = "hidden"
else:
- if between(now, active, signdelay):
+ if between(now, active, sigdelay):
state_zrrsig = "rumoured"
else:
state_zrrsig = "omnipresent"
@@ -1459,8 +1465,8 @@ def test_ksr_fast(ns1):
isctest.kasp.check_dnssec_verify(ns1, zone)
# - check keys
- # named updates the state file asynchronously, so retry the state check
- # until the rumoured -> omnipresent transition catches up.
+ # named writes the key states asynchronously after the SKR import, so
+ # retry until they appear in the state file.
def check_keys_state():
check_keys(zsks, lifetime, FASTCONFIG, with_state=True)
return True