diff --git a/bin/tests/system/rpz/tests.sh b/bin/tests/system/rpz/tests.sh index 575cac4cd7..2404c9f4ba 100644 --- a/bin/tests/system/rpz/tests.sh +++ b/bin/tests/system/rpz/tests.sh @@ -838,13 +838,13 @@ grep NXDOMAIN dig.out.${t} >/dev/null || setret "failed" t=$((t + 1)) echo_i "checking that "add-soa no" at rpz zone level works (${t})" $DIG z.x.servfail -p ${PORT} @$ns7 >dig.out.${t} || setret "failed" -grep SOA dig.out.${t} >/dev/null && setret "failed" +grep "SOA" dig.out.${t} >/dev/null && setret "failed" if [ native = "$MODE" ]; then t=$((t + 1)) echo_i "checking that "add-soa yes" at response-policy level works (${t})" $DIG walled.tld2 -p ${PORT} +noall +add @$ns3 >dig.out.${t} || setret "failed" - grep "^manual-update-rpz\..*SOA" dig.out.${t} >/dev/null || setret "failed" + grep "^manual-update-rpz\..*60.*SOA" dig.out.${t} >/dev/null || setret "failed" fi if [ native = "$MODE" ]; then @@ -862,7 +862,7 @@ if [ native = "$MODE" ]; then t=$((t + 1)) echo_i "checking that 'add-soa unset' works (${t})" $DIG walled.tld2 -p ${PORT} +noall +add @$ns8 >dig.out.${t} || setret "failed" - grep "^manual-update-rpz\..*SOA" dig.out.${t} >/dev/null || setret "failed" + grep "^manual-update-rpz\..*60.*SOA" dig.out.${t} >/dev/null || setret "failed" fi # dnsrps does not allow NS RRs in policy zones, so this check diff --git a/lib/ns/query.c b/lib/ns/query.c index 537d332a56..37b0d0ab0d 100644 --- a/lib/ns/query.c +++ b/lib/ns/query.c @@ -7359,9 +7359,7 @@ query_checkrpz(query_ctx_t *qctx, isc_result_t result) { * Add SOA record to additional section */ if (qctx->rpz_st->m.rpz->addsoa) { - bool override_ttl = - dns_rdataset_isassociated(qctx->rdataset); - rresult = query_addsoa(qctx, override_ttl, + rresult = query_addsoa(qctx, UINT32_MAX, DNS_SECTION_ADDITIONAL); if (rresult != ISC_R_SUCCESS) { QUERY_ERROR(qctx, result);