Commit dabc9aa0bd for bind

commit dabc9aa0bde9d0d7dd8ce67d418647c383420e5a
Author: Jan-Piet Mens <jp@mens.de>
Date:   Sun Oct 4 07:13:14 2026 +0200

    Note for checkds that dnssec-validation is required

    I configured `dnssec-validation no` in named.conf on an authoritative server because I didn't think I'd need validation, and it avoids a `managed-keys` database on disk, which an auth server won't need, right?!

    A few hours later, I experimented with `parental-agent` and `checkds`, setting the latter first to `explicit` and then to `yes`, but I couldn't get past this diagnostic:

    ```
    Invalid NS RRset for 'example' trust level 7
    ```

    After looking at the BIND's source and finding a test case which uses trust anchors.  While typing `trust-anchors {}` into `named.conf`, the penny/cent/rupee/lira dropped: re-enabling `dnssec-validation auto` got the cogs oiled.

    I feel this should be added as a note to the ARM in the section with checkds reference, particularly as the reference for dnssec-validation doesn't mention checkds

diff --git a/doc/arm/reference.rst b/doc/arm/reference.rst
index a005163e05..d5eb06943d 100644
--- a/doc/arm/reference.rst
+++ b/doc/arm/reference.rst
@@ -6703,6 +6703,9 @@ The following options apply to DS queries sent to :any:`parental-agents`:
    :option:`rndc dnssec -checkds <rndc dnssec>` with the appropriate parameters,
    to signal that specific DS records are published and/or withdrawn.

+   Responses to DS queries are validated, so :any:`dnssec-validation` must be
+   enabled for the server.
+
 .. namedconf:statement:: parental-source
    :tags: dnssec
    :short: Specifies which local IPv4 source address is used to send parental DS queries.