Commit f4b3b2c8da for bind

commit f4b3b2c8da3ee3409d39df758f44f76ddf6c6693
Author: Evan Hunt <each@isc.org>
Date:   Tue Sep 22 15:39:52 2026 -0700

    apply ACLs to both raw and signed zones

    In inline-signed zones, ACLs such as allow-query, allow-update, etc,
    were previously set only in the public, signed zone and not in the
    internal raw zone. Updates apply to the raw zone, but the allow-query
    ACL (which is needed for prerequisite checks) was not set there.

    This has been corrected by setting zone ACLs in both the raw and signed
    zones.

diff --git a/lib/dns/zoneproperties.c b/lib/dns/zoneproperties.c
index 56a6a3f99c..0f086a4f05 100644
--- a/lib/dns/zoneproperties.c
+++ b/lib/dns/zoneproperties.c
@@ -1028,6 +1028,11 @@ dns_zone_setnotifyacl(dns_zone_t *zone, dns_acl_t *acl) {
 	LOCK_ZONE(zone);
 	dns_acl_attach(acl, &zone->notifysoa.notify_acl);
 	dns_acl_attach(acl, &zone->notifycds.notify_acl);
+
+	if (dns__zone_inline_secure(zone)) {
+		dns_acl_attach(acl, &zone->raw->notifysoa.notify_acl);
+		dns_acl_attach(acl, &zone->raw->notifycds.notify_acl);
+	}
 	UNLOCK_ZONE(zone);
 }

@@ -1039,6 +1044,10 @@ dns_zone_setqueryacl(dns_zone_t *zone, dns_acl_t *acl) {

 	LOCK_ZONE(zone);
 	dns_acl_attach(acl, &zone->query_acl);
+
+	if (dns__zone_inline_secure(zone)) {
+		dns_acl_attach(acl, &zone->raw->query_acl);
+	}
 	UNLOCK_ZONE(zone);
 }

@@ -1050,6 +1059,10 @@ dns_zone_setqueryonacl(dns_zone_t *zone, dns_acl_t *acl) {

 	LOCK_ZONE(zone);
 	dns_acl_attach(acl, &zone->queryon_acl);
+
+	if (dns__zone_inline_secure(zone)) {
+		dns_acl_attach(acl, &zone->raw->queryon_acl);
+	}
 	UNLOCK_ZONE(zone);
 }

@@ -1061,6 +1074,10 @@ dns_zone_setupdateacl(dns_zone_t *zone, dns_acl_t *acl) {

 	LOCK_ZONE(zone);
 	dns_acl_attach(acl, &zone->update_acl);
+
+	if (dns__zone_inline_secure(zone)) {
+		dns_acl_attach(acl, &zone->raw->update_acl);
+	}
 	UNLOCK_ZONE(zone);
 }

@@ -1072,6 +1089,10 @@ dns_zone_setforwardacl(dns_zone_t *zone, dns_acl_t *acl) {

 	LOCK_ZONE(zone);
 	dns_acl_attach(acl, &zone->forward_acl);
+
+	if (dns__zone_inline_secure(zone)) {
+		dns_acl_attach(acl, &zone->raw->forward_acl);
+	}
 	UNLOCK_ZONE(zone);
 }

@@ -1083,6 +1104,10 @@ dns_zone_setxfracl(dns_zone_t *zone, dns_acl_t *acl) {

 	LOCK_ZONE(zone);
 	dns_acl_attach(acl, &zone->xfr_acl);
+
+	if (dns__zone_inline_secure(zone)) {
+		dns_acl_attach(acl, &zone->raw->xfr_acl);
+	}
 	UNLOCK_ZONE(zone);
 }

@@ -1129,6 +1154,9 @@ dns_zone_clearupdateacl(dns_zone_t *zone) {
 	if (zone->update_acl != NULL) {
 		dns_acl_detach(&zone->update_acl);
 	}
+	if (dns__zone_inline_secure(zone) && zone->raw->update_acl != NULL) {
+		dns_acl_detach(&zone->raw->update_acl);
+	}
 	UNLOCK_ZONE(zone);
 }

@@ -1140,6 +1168,9 @@ dns_zone_clearforwardacl(dns_zone_t *zone) {
 	if (zone->forward_acl != NULL) {
 		dns_acl_detach(&zone->forward_acl);
 	}
+	if (dns__zone_inline_secure(zone) && zone->raw->forward_acl != NULL) {
+		dns_acl_detach(&zone->raw->forward_acl);
+	}
 	UNLOCK_ZONE(zone);
 }

@@ -1154,6 +1185,15 @@ dns_zone_clearnotifyacl(dns_zone_t *zone) {
 	if (zone->notifycds.notify_acl != NULL) {
 		dns_acl_detach(&zone->notifycds.notify_acl);
 	}
+
+	if (dns__zone_inline_secure(zone)) {
+		if (zone->raw->notifysoa.notify_acl != NULL) {
+			dns_acl_detach(&zone->raw->notifysoa.notify_acl);
+		}
+		if (zone->raw->notifycds.notify_acl != NULL) {
+			dns_acl_detach(&zone->raw->notifycds.notify_acl);
+		}
+	}
 	UNLOCK_ZONE(zone);
 }

@@ -1165,6 +1205,9 @@ dns_zone_clearqueryacl(dns_zone_t *zone) {
 	if (zone->query_acl != NULL) {
 		dns_acl_detach(&zone->query_acl);
 	}
+	if (dns__zone_inline_secure(zone) && zone->raw->query_acl != NULL) {
+		dns_acl_detach(&zone->raw->query_acl);
+	}
 	UNLOCK_ZONE(zone);
 }

@@ -1176,6 +1219,9 @@ dns_zone_clearqueryonacl(dns_zone_t *zone) {
 	if (zone->queryon_acl != NULL) {
 		dns_acl_detach(&zone->queryon_acl);
 	}
+	if (dns__zone_inline_secure(zone) && zone->raw->queryon_acl != NULL) {
+		dns_acl_detach(&zone->raw->queryon_acl);
+	}
 	UNLOCK_ZONE(zone);
 }

@@ -1187,6 +1233,9 @@ dns_zone_clearxfracl(dns_zone_t *zone) {
 	if (zone->xfr_acl != NULL) {
 		dns_acl_detach(&zone->xfr_acl);
 	}
+	if (dns__zone_inline_secure(zone) && zone->raw->xfr_acl != NULL) {
+		dns_acl_detach(&zone->raw->xfr_acl);
+	}
 	UNLOCK_ZONE(zone);
 }