]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
style cleanups
authorEvan Hunt <each@isc.org>
Sun, 20 Jan 2019 18:13:07 +0000 (10:13 -0800)
committerEvan Hunt <each@isc.org>
Thu, 31 Jan 2019 19:57:16 +0000 (11:57 -0800)
lib/dns/dnssec.c
lib/dns/zone.c

index 420c93aa050d093f49e12d9d5efe87be6f8e585b..322a92d524f99e71c54574231f2836ee1424a20a 100644 (file)
@@ -2048,9 +2048,11 @@ dns_dnssec_updatekeys(dns_dnsseckeylist_t *keys, dns_dnsseckeylist_t *newkeys,
         */
        for (key = ISC_LIST_HEAD(*keys);
             key != NULL;
-            key = ISC_LIST_NEXT(key, link)) {
+            key = ISC_LIST_NEXT(key, link))
+       {
                if (key->source == dns_keysource_user &&
-                   (key->hint_publish || key->force_publish)) {
+                   (key->hint_publish || key->force_publish))
+               {
                        RETERR(publish_key(diff, key, origin, ttl,
                                           mctx, allzsk, report));
                }
@@ -2069,15 +2071,19 @@ dns_dnssec_updatekeys(dns_dnsseckeylist_t *keys, dns_dnsseckeylist_t *newkeys,
 
                for (key = ISC_LIST_HEAD(*newkeys);
                     key != NULL;
-                    key = ISC_LIST_NEXT(key, link)) {
+                    key = ISC_LIST_NEXT(key, link))
+               {
                        dns_ttl_t thisttl = dst_key_getttl(key->key);
                        if (thisttl != 0 &&
                            (shortest == 0 || thisttl < shortest))
+                       {
                                shortest = thisttl;
+                       }
                }
 
-               if (shortest != 0)
+               if (shortest != 0) {
                        ttl = shortest;
+               }
        }
 
        /*
@@ -2091,15 +2097,16 @@ dns_dnssec_updatekeys(dns_dnsseckeylist_t *keys, dns_dnsseckeylist_t *newkeys,
 
                for (key2 = ISC_LIST_HEAD(*keys);
                     key2 != NULL;
-                    key2 = ISC_LIST_NEXT(key2, link)) {
+                    key2 = ISC_LIST_NEXT(key2, link))
+               {
                        int f1 = dst_key_flags(key1->key);
                        int f2 = dst_key_flags(key2->key);
                        int nr1 = f1 & ~DNS_KEYFLAG_REVOKE;
                        int nr2 = f2 & ~DNS_KEYFLAG_REVOKE;
                        if (nr1 == nr2 &&
                            dst_key_alg(key1->key) == dst_key_alg(key2->key) &&
-                           dst_key_pubcompare(key1->key, key2->key,
-                                              true)) {
+                           dst_key_pubcompare(key1->key, key2->key, true))
+                       {
                                int r1, r2;
                                r1 = dst_key_flags(key1->key) &
                                        DNS_KEYFLAG_REVOKE;
@@ -2116,11 +2123,13 @@ dns_dnssec_updatekeys(dns_dnsseckeylist_t *keys, dns_dnsseckeylist_t *newkeys,
                        ISC_LIST_APPEND(*keys, key1, link);
 
                        if (key1->source != dns_keysource_zoneapex &&
-                           (key1->hint_publish || key1->force_publish)) {
+                           (key1->hint_publish || key1->force_publish))
+                       {
                                RETERR(publish_key(diff, key1, origin, ttl,
                                                   mctx, allzsk, report));
-                               if (key1->hint_sign || key1->force_sign)
+                               if (key1->hint_sign || key1->force_sign) {
                                        key1->first_sign = true;
+                               }
                        }
 
                        continue;
@@ -2131,12 +2140,14 @@ dns_dnssec_updatekeys(dns_dnsseckeylist_t *keys, dns_dnsseckeylist_t *newkeys,
                        RETERR(remove_key(diff, key2, origin, ttl, mctx,
                                          "expired", report));
                        ISC_LIST_UNLINK(*keys, key2, link);
-                       if (removed != NULL)
+                       if (removed != NULL) {
                                ISC_LIST_APPEND(*removed, key2, link);
-                       else
+                       } else {
                                dns_dnsseckey_destroy(mctx, &key2);
+                       }
                } else if (key_revoked &&
-                        (dst_key_flags(key1->key) & DNS_KEYFLAG_REVOKE) != 0) {
+                          (dst_key_flags(key1->key) & DNS_KEYFLAG_REVOKE) != 0)
+               {
 
                        /*
                         * A previously valid key has been revoked.
@@ -2146,10 +2157,11 @@ dns_dnssec_updatekeys(dns_dnsseckeylist_t *keys, dns_dnsseckeylist_t *newkeys,
                        RETERR(remove_key(diff, key2, origin, ttl, mctx,
                                          "revoked", report));
                        ISC_LIST_UNLINK(*keys, key2, link);
-                       if (removed != NULL)
+                       if (removed != NULL) {
                                ISC_LIST_APPEND(*removed, key2, link);
-                       else
+                       } else {
                                dns_dnsseckey_destroy(mctx, &key2);
+                       }
 
                        RETERR(publish_key(diff, key1, origin, ttl,
                                           mctx, allzsk, report));
@@ -2169,7 +2181,9 @@ dns_dnssec_updatekeys(dns_dnsseckeylist_t *keys, dns_dnsseckeylist_t *newkeys,
                } else {
                        if (!key2->is_active &&
                            (key1->hint_sign || key1->force_sign))
+                       {
                                key2->first_sign = true;
+                       }
                        key2->hint_sign = key1->hint_sign;
                        key2->hint_publish = key1->hint_publish;
                }
index 385ee316166562d3bcb999683a6d13b33fba602f..ed7c0925d1b4b6526398efdfe92121e2c9fad5e8 100644 (file)
@@ -3193,15 +3193,17 @@ zone_check_dnskeys(dns_zone_t *zone, dns_db_t *db) {
        const char *algorithm;
 
        result = dns_db_findnode(db, &zone->origin, false, &node);
-       if (result != ISC_R_SUCCESS)
+       if (result != ISC_R_SUCCESS) {
                goto cleanup;
+       }
 
        dns_db_currentversion(db, &version);
        dns_rdataset_init(&rdataset);
        result = dns_db_findrdataset(db, node, version, dns_rdatatype_dnskey,
                                     dns_rdatatype_none, 0, &rdataset, NULL);
-       if (result != ISC_R_SUCCESS)
+       if (result != ISC_R_SUCCESS) {
                goto cleanup;
+       }
 
        for (result = dns_rdataset_first(&rdataset);
             result == ISC_R_SUCCESS;
@@ -3248,10 +3250,12 @@ zone_check_dnskeys(dns_zone_t *zone, dns_db_t *db) {
        dns_rdataset_disassociate(&rdataset);
 
  cleanup:
-       if (node != NULL)
+       if (node != NULL) {
                dns_db_detachnode(db, &node);
-       if (version != NULL)
+       }
+       if (version != NULL) {
                dns_db_closeversion(db, &version, false);
+       }
 }
 
 static void
@@ -3264,15 +3268,18 @@ resume_signingwithkey(dns_zone_t *zone) {
        dns_db_t *db = NULL;
 
        ZONEDB_LOCK(&zone->dblock, isc_rwlocktype_read);
-       if (zone->db != NULL)
+       if (zone->db != NULL) {
                dns_db_attach(zone->db, &db);
+       }
        ZONEDB_UNLOCK(&zone->dblock, isc_rwlocktype_read);
-       if (db == NULL)
+       if (db == NULL) {
                goto cleanup;
+       }
 
        result = dns_db_findnode(db, &zone->origin, false, &node);
-       if (result != ISC_R_SUCCESS)
+       if (result != ISC_R_SUCCESS) {
                goto cleanup;
+       }
 
        dns_db_currentversion(db, &version);
        dns_rdataset_init(&rdataset);
@@ -3291,7 +3298,8 @@ resume_signingwithkey(dns_zone_t *zone) {
        {
                dns_rdataset_current(&rdataset, &rdata);
                if (rdata.length != 5 ||
-                   rdata.data[0] == 0 || rdata.data[4] != 0) {
+                   rdata.data[0] == 0 || rdata.data[4] != 0)
+               {
                        dns_rdata_reset(&rdata);
                        continue;
                }
@@ -3310,10 +3318,12 @@ resume_signingwithkey(dns_zone_t *zone) {
 
  cleanup:
        if (db != NULL) {
-               if (node != NULL)
+               if (node != NULL) {
                        dns_db_detachnode(db, &node);
-               if (version != NULL)
+               }
+               if (version != NULL) {
                        dns_db_closeversion(db, &version, false);
+               }
                dns_db_detach(&db);
        }
 }
@@ -3337,8 +3347,9 @@ zone_addnsec3chain(dns_zone_t *zone, dns_rdata_nsec3param_t *nsec3param) {
        dns_db_t *db = NULL;
 
        ZONEDB_LOCK(&zone->dblock, isc_rwlocktype_read);
-       if (zone->db != NULL)
+       if (zone->db != NULL) {
                dns_db_attach(zone->db, &db);
+       }
        ZONEDB_UNLOCK(&zone->dblock, isc_rwlocktype_read);
 
        if (db == NULL) {
@@ -3390,36 +3401,40 @@ zone_addnsec3chain(dns_zone_t *zone, dns_rdata_nsec3param_t *nsec3param) {
        /*
         * Log NSEC3 parameters defined by supplied NSEC3PARAM RDATA.
         */
-       if (nsec3param->flags == 0)
+       if (nsec3param->flags == 0) {
                strlcpy(flags, "NONE", sizeof(flags));
-       else {
+       else {
                flags[0] = '\0';
                if ((nsec3param->flags & DNS_NSEC3FLAG_REMOVE) != 0) {
                        strlcat(flags, "REMOVE", sizeof(flags));
                }
                if ((nsec3param->flags & DNS_NSEC3FLAG_INITIAL) != 0) {
-                       if (flags[0] == '\0')
+                       if (flags[0] == '\0') {
                                strlcpy(flags, "INITIAL", sizeof(flags));
-                       else
+                       } else {
                                strlcat(flags, "|INITIAL", sizeof(flags));
+                       }
                }
                if ((nsec3param->flags & DNS_NSEC3FLAG_CREATE) != 0) {
-                       if (flags[0] == '\0')
+                       if (flags[0] == '\0') {
                                strlcpy(flags, "CREATE", sizeof(flags));
-                       else
+                       } else {
                                strlcat(flags, "|CREATE", sizeof(flags));
+                       }
                }
                if ((nsec3param->flags & DNS_NSEC3FLAG_NONSEC) != 0) {
-                       if (flags[0] == '\0')
+                       if (flags[0] == '\0') {
                                strlcpy(flags, "NONSEC", sizeof(flags));
-                       else
+                       } else {
                                strlcat(flags, "|NONSEC", sizeof(flags));
+                       }
                }
                if ((nsec3param->flags & DNS_NSEC3FLAG_OPTOUT) != 0) {
-                       if (flags[0] == '\0')
+                       if (flags[0] == '\0') {
                                strlcpy(flags, "OPTOUT", sizeof(flags));
-                       else
+                       } else {
                                strlcat(flags, "|OPTOUT", sizeof(flags));
+                       }
                }
        }
        result = dns_nsec3param_salttotext(nsec3param, saltbuf,
@@ -3437,14 +3452,19 @@ zone_addnsec3chain(dns_zone_t *zone, dns_rdata_nsec3param_t *nsec3param) {
         */
        for (current = ISC_LIST_HEAD(zone->nsec3chain);
             current != NULL;
-            current = ISC_LIST_NEXT(current, link)) {
-               if (current->db == db &&
-                   current->nsec3param.hash == nsec3param->hash &&
-                   current->nsec3param.iterations == nsec3param->iterations &&
-                   current->nsec3param.salt_length == nsec3param->salt_length
-                   && !memcmp(current->nsec3param.salt, nsec3param->salt,
-                              nsec3param->salt_length))
+            current = ISC_LIST_NEXT(current, link))
+       {
+               if ((current->db == db) &&
+                   (current->nsec3param.hash == nsec3param->hash) &&
+                   (current->nsec3param.iterations ==
+                    nsec3param->iterations) &&
+                   (current->nsec3param.salt_length ==
+                    nsec3param->salt_length) &&
+                   memcmp(current->nsec3param.salt, nsec3param->salt,
+                          nsec3param->salt_length) == 0)
+               {
                        current->done = true;
+               }
        }
 
        /*
@@ -3453,12 +3473,14 @@ zone_addnsec3chain(dns_zone_t *zone, dns_rdata_nsec3param_t *nsec3param) {
         * creating NSEC3 records for NSEC3 records.
         */
        dns_db_attach(db, &nsec3chain->db);
-       if ((nsec3chain->nsec3param.flags & DNS_NSEC3FLAG_CREATE) != 0)
+       if ((nsec3chain->nsec3param.flags & DNS_NSEC3FLAG_CREATE) != 0) {
                options = DNS_DB_NONSEC3;
+       }
        result = dns_db_createiterator(nsec3chain->db, options,
                                       &nsec3chain->dbiterator);
-       if (result == ISC_R_SUCCESS)
+       if (result == ISC_R_SUCCESS) {
                result = dns_dbiterator_first(nsec3chain->dbiterator);
+       }
        if (result == ISC_R_SUCCESS) {
                /*
                 * Database iterator initialization succeeded.  We are now
@@ -3475,22 +3497,26 @@ zone_addnsec3chain(dns_zone_t *zone, dns_rdata_nsec3param_t *nsec3param) {
                if (isc_time_isepoch(&zone->nsec3chaintime)) {
                        TIME_NOW(&now);
                        zone->nsec3chaintime = now;
-                       if (zone->task != NULL)
+                       if (zone->task != NULL) {
                                zone_settimer(zone, &now);
+                       }
                }
        }
 
        if (nsec3chain != NULL) {
-               if (nsec3chain->db != NULL)
+               if (nsec3chain->db != NULL) {
                        dns_db_detach(&nsec3chain->db);
-               if (nsec3chain->dbiterator != NULL)
+               }
+               if (nsec3chain->dbiterator != NULL) {
                        dns_dbiterator_destroy(&nsec3chain->dbiterator);
+               }
                isc_mem_put(zone->mctx, nsec3chain, sizeof *nsec3chain);
        }
 
  cleanup:
-       if (db != NULL)
+       if (db != NULL) {
                dns_db_detach(&db);
+       }
        return (result);
 }
 
@@ -3517,15 +3543,18 @@ resume_addnsec3chain(dns_zone_t *zone) {
                return;
 
        ZONEDB_LOCK(&zone->dblock, isc_rwlocktype_read);
-       if (zone->db != NULL)
+       if (zone->db != NULL) {
                dns_db_attach(zone->db, &db);
+       }
        ZONEDB_UNLOCK(&zone->dblock, isc_rwlocktype_read);
-       if (db == NULL)
+       if (db == NULL) {
                goto cleanup;
+       }
 
        result = dns_db_findnode(db, &zone->origin, false, &node);
-       if (result != ISC_R_SUCCESS)
+       if (result != ISC_R_SUCCESS) {
                goto cleanup;
+       }
 
        dns_db_currentversion(db, &version);
 
@@ -3564,7 +3593,9 @@ resume_addnsec3chain(dns_zone_t *zone) {
                 */
                if (!dns_nsec3param_fromprivate(&private, &rdata, buf,
                                                sizeof(buf)))
+               {
                        continue;
+               }
                result = dns_rdata_tostruct(&rdata, &nsec3param, NULL);
                RUNTIME_CHECK(result == ISC_R_SUCCESS);
                if (((nsec3param.flags & DNS_NSEC3FLAG_REMOVE) != 0) ||
@@ -3584,12 +3615,15 @@ resume_addnsec3chain(dns_zone_t *zone) {
                }
        }
        dns_rdataset_disassociate(&rdataset);
+
  cleanup:
        if (db != NULL) {
-               if (node != NULL)
+               if (node != NULL) {
                        dns_db_detachnode(db, &node);
-               if (version != NULL)
+               }
+               if (version != NULL) {
                        dns_db_closeversion(db, &version, false);
+               }
                dns_db_detach(&db);
        }
 }
@@ -3649,8 +3683,8 @@ check_nsec3param(dns_zone_t *zone, dns_db_t *db) {
        bool ok = false;
        isc_result_t result;
        dns_rdata_t rdata = DNS_RDATA_INIT;
-       bool dynamic = (zone->type == dns_zone_master) ?
-                               dns_zone_isdynamic(zone, false) : false;
+       bool dynamic = (zone->type == dns_zone_master)
+                       ? dns_zone_isdynamic(zone, false) : false;
 
        dns_rdataset_init(&rdataset);
        result = dns_db_findnode(db, &zone->origin, false, &node);
@@ -3712,11 +3746,13 @@ check_nsec3param(dns_zone_t *zone, dns_db_t *db) {
                                dns_zone_log(zone, ISC_LOG_WARNING,
                                     "unsupported nsec3 hash algorithm: %u",
                                             nsec3param.hash);
-               } else
+               } else {
                        ok = true;
+               }
        }
-       if (result == ISC_R_NOMORE)
+       if (result == ISC_R_NOMORE) {
                result = ISC_R_SUCCESS;
+       }
 
        if (!ok) {
                result = DNS_R_BADZONE;
@@ -3725,8 +3761,9 @@ check_nsec3param(dns_zone_t *zone, dns_db_t *db) {
        }
 
  cleanup:
-       if (dns_rdataset_isassociated(&rdataset))
+       if (dns_rdataset_isassociated(&rdataset)) {
                dns_rdataset_disassociate(&rdataset);
+       }
        dns_db_closeversion(db, &version, false);
        dns_db_detachnode(db, &node);
        return (result);
@@ -3979,14 +4016,16 @@ load_secroots(dns_zone_t *zone, dns_name_t *name, dns_rdataset_t *rdataset) {
        /* Now insert all the accepted trust anchors from this keydata set. */
        for (result = dns_rdataset_first(rdataset);
             result == ISC_R_SUCCESS;
-            result = dns_rdataset_next(rdataset)) {
+            result = dns_rdataset_next(rdataset))
+       {
                dns_rdata_reset(&rdata);
                dns_rdataset_current(rdataset, &rdata);
 
                /* Convert rdata to keydata. */
                result = dns_rdata_tostruct(&rdata, &keydata, NULL);
-               if (result == ISC_R_UNEXPECTEDEND)
+               if (result == ISC_R_UNEXPECTEDEND) {
                        continue;
+               }
                RUNTIME_CHECK(result == ISC_R_SUCCESS);
 
                /* Set the key refresh timer to force a fast refresh. */
@@ -4012,8 +4051,7 @@ load_secroots(dns_zone_t *zone, dns_name_t *name, dns_rdataset_t *rdataset) {
 
                /* Add to keytables. */
                trusted++;
-               trust_key(zone, name, &dnskey,
-                         (keydata.addhd == 0), mctx);
+               trust_key(zone, name, &dnskey, (keydata.addhd == 0), mctx);
        }
 
        if (trusted == 0 && pending != 0) {
@@ -4285,7 +4323,8 @@ sync_keyzone(dns_zone_t *zone, dns_db_t *db) {
        dns_rriterator_init(&rrit, db, ver, 0);
        for (result = dns_rriterator_first(&rrit);
             result == ISC_R_SUCCESS;
-            result = dns_rriterator_nextrrset(&rrit)) {
+            result = dns_rriterator_nextrrset(&rrit))
+       {
                dns_rdataset_t *rdataset = NULL;
                dns_name_t *rrname = NULL;
                uint32_t ttl;
@@ -4296,8 +4335,9 @@ sync_keyzone(dns_zone_t *zone, dns_db_t *db) {
                        goto failure;
                }
 
-               if (rdataset->type != dns_rdatatype_keydata)
+               if (rdataset->type != dns_rdatatype_keydata) {
                        continue;
+               }
 
                result = dns_keytable_find(sr, rrname, &keynode);
                if ((result != ISC_R_SUCCESS &&
@@ -4311,8 +4351,9 @@ sync_keyzone(dns_zone_t *zone, dns_db_t *db) {
                        load_secroots(zone, rrname, rdataset);
                }
 
-               if (keynode != NULL)
+               if (keynode != NULL) {
                        dns_keytable_detachkeynode(sr, &keynode);
+               }
        }
        dns_rriterator_destroy(&rrit);
 
@@ -4341,18 +4382,22 @@ sync_keyzone(dns_zone_t *zone, dns_db_t *db) {
 
  failure:
        if (result != ISC_R_SUCCESS &&
-           !DNS_ZONE_FLAG(zone, DNS_ZONEFLG_LOADED)) {
+           !DNS_ZONE_FLAG(zone, DNS_ZONEFLG_LOADED))
+       {
                dns_zone_log(zone, ISC_LOG_ERROR,
                             "unable to synchronize managed keys: %s",
                             dns_result_totext(result));
                isc_time_settoepoch(&zone->refreshkeytime);
        }
-       if (keynode != NULL)
+       if (keynode != NULL) {
                dns_keytable_detachkeynode(sr, &keynode);
-       if (sr != NULL)
+       }
+       if (sr != NULL) {
                dns_keytable_detach(&sr);
-       if (ver != NULL)
+       }
+       if (ver != NULL) {
                dns_db_closeversion(db, &ver, commit);
+       }
        dns_diff_clear(&diff);
 
        INSIST(ver == NULL);
@@ -4365,8 +4410,9 @@ dns_zone_synckeyzone(dns_zone_t *zone) {
        isc_result_t result;
        dns_db_t *db = NULL;
 
-       if (zone->type != dns_zone_key)
+       if (zone->type != dns_zone_key) {
                return (DNS_R_BADZONE);
+       }
 
        CHECK(dns_zone_getdb(zone, &db));
 
@@ -4375,8 +4421,9 @@ dns_zone_synckeyzone(dns_zone_t *zone) {
        UNLOCK_ZONE(zone);
 
  failure:
-       if (db != NULL)
+       if (db != NULL) {
                dns_db_detach(&db);
+       }
        return (result);
 }
 
@@ -4399,8 +4446,8 @@ maybe_send_secure(dns_zone_t *zone) {
                        unsigned int soacount;
 
                        result = zone_get_from_db(zone->raw, zone->raw->db,
-                                                 NULL, &soacount, &serial, NULL,
-                                                 NULL, NULL, NULL, NULL);
+                                                 NULL, &soacount, &serial,
+                                                 NULL, NULL, NULL, NULL, NULL);
                        if (result == ISC_R_SUCCESS && soacount > 0U)
                                zone_send_secureserial(zone->raw, serial);
                } else
@@ -4445,8 +4492,9 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
        dns_include_t *inc;
 
        INSIST(LOCKED_ZONE(zone));
-       if (inline_raw(zone))
+       if (inline_raw(zone)) {
                INSIST(LOCKED_ZONE(zone->secure));
+       }
 
        TIME_NOW(&now);
 
@@ -4460,18 +4508,20 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
                    zone->type == dns_zone_mirror ||
                    zone->type == dns_zone_stub ||
                    (zone->type == dns_zone_redirect &&
-                    zone->masters == NULL)) {
-                       if (result == ISC_R_FILENOTFOUND)
+                    zone->masters == NULL))
+               {
+                       if (result == ISC_R_FILENOTFOUND) {
                                dns_zone_logc(zone, DNS_LOGCATEGORY_ZONELOAD,
                                              ISC_LOG_DEBUG(1),
                                             "no master file");
-                       else if (result != DNS_R_NOMASTERFILE)
+                       } else if (result != DNS_R_NOMASTERFILE) {
                                dns_zone_logc(zone, DNS_LOGCATEGORY_ZONELOAD,
                                              ISC_LOG_ERROR,
                                             "loading from master file %s "
                                             "failed: %s",
                                             zone->masterfile,
                                             dns_result_totext(result));
+                       }
                } else if (zone->type == dns_zone_master &&
                           inline_secure(zone) && result == ISC_R_FILENOTFOUND)
                {
@@ -4491,18 +4541,20 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
                        nomaster = true;
                }
 
-               if (zone->type != dns_zone_key)
+               if (zone->type != dns_zone_key) {
                        goto cleanup;
+               }
        }
 
        dns_zone_logc(zone, DNS_LOGCATEGORY_ZONELOAD, ISC_LOG_DEBUG(2),
                     "number of nodes in database: %u",
                     dns_db_nodecount(db));
 
-       if (result == DNS_R_SEENINCLUDE)
+       if (result == DNS_R_SEENINCLUDE) {
                DNS_ZONE_SETFLAG(zone, DNS_ZONEFLG_HASINCLUDE);
-       else
+       } else {
                DNS_ZONE_CLRFLAG(zone, DNS_ZONEFLG_HASINCLUDE);
+       }
 
        /*
         * If there's no master file for a key zone, then the zone is new:
@@ -4512,8 +4564,9 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
         */
        if (nomaster && zone->type == dns_zone_key) {
                result = add_soa(zone, db);
-               if (result != ISC_R_SUCCESS)
+               if (result != ISC_R_SUCCESS) {
                        goto cleanup;
+               }
        }
 
        /*
@@ -4555,8 +4608,9 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
                             "journal rollforward completed "
                             "successfully: %s",
                             dns_result_totext(result));
-               if (result == ISC_R_SUCCESS)
+               if (result == ISC_R_SUCCESS) {
                        needdump = true;
+               }
        }
 
        /*
@@ -4577,7 +4631,8 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
         * updates otherwise.
         */
        if (zone->journal != NULL && dns_zone_isdynamic(zone, true) &&
-           ! DNS_ZONE_OPTION(zone, DNS_ZONEOPT_IXFRFROMDIFFS)) {
+           ! DNS_ZONE_OPTION(zone, DNS_ZONEOPT_IXFRFROMDIFFS))
+       {
                uint32_t jserial;
                dns_journal_t *journal = NULL;
                bool empty = false;
@@ -4594,11 +4649,12 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
                }
 
                if (jserial != serial) {
-                       if (!empty)
+                       if (!empty) {
                                dns_zone_logc(zone, DNS_LOGCATEGORY_ZONELOAD,
                                              ISC_LOG_INFO,
                                             "journal file is out of date: "
                                             "removing journal file");
+                       }
                        if (remove(zone->journal) < 0 && errno != ENOENT) {
                                char strbuf[ISC_STRERRORSIZE];
                                strerror_r(errno, strbuf, sizeof(strbuf));
@@ -4640,27 +4696,31 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
                                     "has no NS records");
                        result = DNS_R_BADZONE;
                }
-               if (result != ISC_R_SUCCESS)
+               if (result != ISC_R_SUCCESS) {
                        goto cleanup;
+               }
                if (zone->type == dns_zone_master && errors != 0) {
                        result = DNS_R_BADZONE;
                        goto cleanup;
                }
                if (zone->type != dns_zone_stub &&
-                   zone->type != dns_zone_redirect) {
+                   zone->type != dns_zone_redirect)
+               {
                        result = check_nsec3param(zone, db);
                        if (result != ISC_R_SUCCESS)
                                goto cleanup;
                }
                if (zone->type == dns_zone_master &&
                    DNS_ZONE_OPTION(zone, DNS_ZONEOPT_CHECKINTEGRITY) &&
-                   !integrity_checks(zone, db)) {
+                   !integrity_checks(zone, db))
+               {
                        result = DNS_R_BADZONE;
                        goto cleanup;
                }
                if (zone->type == dns_zone_master &&
                    DNS_ZONE_OPTION(zone, DNS_ZONEOPT_CHECKDUPRR) &&
-                   !zone_check_dup(zone, db)) {
+                   !zone_check_dup(zone, db))
+               {
                        result = DNS_R_BADZONE;
                        goto cleanup;
                }
@@ -4712,20 +4772,22 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
                                              serialmax);
                                result = DNS_R_BADZONE;
                                goto cleanup;
-                       } else if (!isc_serial_ge(serial, oldserial))
+                       } else if (!isc_serial_ge(serial, oldserial)) {
                                dns_zone_logc(zone,
                                              DNS_LOGCATEGORY_ZONELOAD,
                                              ISC_LOG_ERROR,
                                              "zone serial (%u/%u) has gone "
                                              "backwards", serial, oldserial);
-                       else if (serial == oldserial && !hasinclude &&
-                                strcmp(zone->db_argv[0], "_builtin") != 0)
+                       } else if (serial == oldserial && !hasinclude &&
+                                  strcmp(zone->db_argv[0], "_builtin") != 0)
+                       {
                                dns_zone_logc(zone,
                                              DNS_LOGCATEGORY_ZONELOAD,
                                              ISC_LOG_ERROR,
                                              "zone serial (%u) unchanged. "
                                              "zone may fail to transfer "
                                              "to slaves.", serial);
+                       }
                }
 
                if (zone->type == dns_zone_master &&
@@ -4752,26 +4814,32 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
                    zone->type == dns_zone_mirror ||
                    zone->type == dns_zone_stub ||
                    (zone->type == dns_zone_redirect &&
-                    zone->masters != NULL)) {
+                    zone->masters != NULL))
+               {
                        isc_time_t t;
                        uint32_t delay;
 
                        result = isc_file_getmodtime(zone->journal, &t);
-                       if (result != ISC_R_SUCCESS)
+                       if (result != ISC_R_SUCCESS) {
                                result = isc_file_getmodtime(zone->masterfile,
                                                             &t);
-                       if (result == ISC_R_SUCCESS)
+                       }
+                       if (result == ISC_R_SUCCESS) {
                                DNS_ZONE_TIME_ADD(&t, zone->expire,
                                                  &zone->expiretime);
-                       else
+                       } else {
                                DNS_ZONE_TIME_ADD(&now, zone->retry,
                                                  &zone->expiretime);
+                       }
 
-                       delay = zone->retry - isc_random_uniform((zone->retry * 3) / 4);
+                       delay = (zone->retry -
+                                isc_random_uniform((zone->retry * 3) / 4));
                        DNS_ZONE_TIME_ADD(&now, delay, &zone->refreshtime);
                        if (isc_time_compare(&zone->refreshtime,
                                             &zone->expiretime) >= 0)
+                       {
                                zone->refreshtime = now;
+                       }
                }
 
                break;
@@ -4793,23 +4861,27 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
        /*
         * Check for weak DNSKEY's.
         */
-       if (zone->type == dns_zone_master)
+       if (zone->type == dns_zone_master) {
                zone_check_dnskeys(zone, db);
+       }
 
        /*
         * Schedule DNSSEC key refresh.
         */
        if (zone->type == dns_zone_master &&
            DNS_ZONEKEY_OPTION(zone, DNS_ZONEKEY_MAINTAIN))
+       {
                zone->refreshkeytime = now;
+       }
 
        ZONEDB_LOCK(&zone->dblock, isc_rwlocktype_write);
        if (zone->db != NULL) {
                had_db = true;
                result = zone_replacedb(zone, db, false);
                ZONEDB_UNLOCK(&zone->dblock, isc_rwlocktype_write);
-               if (result != ISC_R_SUCCESS)
+               if (result != ISC_R_SUCCESS) {
                        goto cleanup;
+               }
        } else {
                zone_attachdb(zone, db);
                ZONEDB_UNLOCK(&zone->dblock, isc_rwlocktype_write);
@@ -4819,10 +4891,11 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
                if (DNS_ZONE_FLAG(zone, DNS_ZONEFLG_SENDSECURE) &&
                    inline_raw(zone))
                {
-                       if (zone->secure->db == NULL)
+                       if (zone->secure->db == NULL) {
                                zone_send_securedb(zone, db);
-                       else
+                       } else {
                                zone_send_secureserial(zone, serial);
+                       }
                }
        }
 
@@ -4830,17 +4903,18 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
         * Finished loading inline-signing zone; need to get status
         * from the raw side now.
         */
-       if (zone->type == dns_zone_master && inline_secure(zone))
+       if (zone->type == dns_zone_master && inline_secure(zone)) {
                maybe_send_secure(zone);
-
+       }
 
        result = ISC_R_SUCCESS;
 
        if (needdump) {
-               if (zone->type == dns_zone_key)
+               if (zone->type == dns_zone_key) {
                        zone_needdump(zone, 30);
-               else
+               } else {
                        zone_needdump(zone, DNS_DUMP_DELAY);
+               }
        }
 
        if (zone->task != NULL) {
@@ -4853,7 +4927,8 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
                if (zone->type == dns_zone_master &&
                    !DNS_ZONEKEY_OPTION(zone, DNS_ZONEKEY_NORESIGN) &&
                    dns_zone_isdynamic(zone, false) &&
-                   dns_db_issecure(db)) {
+                   dns_db_issecure(db))
+               {
                        dns_name_t *name;
                        dns_fixedname_t fixed;
                        dns_rdataset_t next;
@@ -4878,11 +4953,12 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
                                              next.resign - timenow -
                                               zone->sigresigninginterval);
                                dns_rdataset_disassociate(&next);
-                       } else
+                       } else {
                                dns_zone_logc(zone, DNS_LOGCATEGORY_ZONELOAD,
                                              ISC_LOG_WARNING,
                                              "signed dynamic zone has no "
                                              "resign event scheduled");
+                       }
                }
 
                zone_settimer(zone, &now);
@@ -4893,7 +4969,8 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
         */
        for (inc = ISC_LIST_HEAD(zone->includes);
             inc != NULL;
-            inc = ISC_LIST_HEAD(zone->includes)) {
+            inc = ISC_LIST_HEAD(zone->includes))
+       {
                ISC_LIST_UNLINK(zone->includes, inc, link);
                isc_mem_free(zone->mctx, inc->name);
                isc_mem_put(zone->mctx, inc, sizeof(*inc));
@@ -4905,7 +4982,8 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
         */
        for (inc = ISC_LIST_HEAD(zone->newincludes);
             inc != NULL;
-            inc = ISC_LIST_HEAD(zone->newincludes)) {
+            inc = ISC_LIST_HEAD(zone->newincludes))
+       {
                ISC_LIST_UNLINK(zone->newincludes, inc, link);
                ISC_LIST_APPEND(zone->includes, inc, link);
                zone->nincludes++;
@@ -4945,29 +5023,35 @@ zone_postload(dns_zone_t *zone, dns_db_t *db, isc_time_t loadtime,
            zone->type == dns_zone_mirror ||
            zone->type == dns_zone_stub ||
            zone->type == dns_zone_key ||
-           (zone->type == dns_zone_redirect && zone->masters != NULL)) {
+           (zone->type == dns_zone_redirect && zone->masters != NULL))
+       {
                if (result != ISC_R_NOMEMORY) {
-                       if (zone->journal != NULL)
+                       if (zone->journal != NULL) {
                                zone_saveunique(zone, zone->journal,
                                                "jn-XXXXXXXX");
-                       if (zone->masterfile != NULL)
+                       }
+                       if (zone->masterfile != NULL) {
                                zone_saveunique(zone, zone->masterfile,
                                                "db-XXXXXXXX");
+                       }
                }
 
                /* Mark the zone for immediate refresh. */
                zone->refreshtime = now;
-               if (zone->task != NULL)
+               if (zone->task != NULL) {
                        zone_settimer(zone, &now);
+               }
                result = ISC_R_SUCCESS;
        } else if (zone->type == dns_zone_master ||
-                  zone->type == dns_zone_redirect) {
-               if (!(inline_secure(zone) && result == ISC_R_FILENOTFOUND))
+                  zone->type == dns_zone_redirect)
+       {
+               if (! (inline_secure(zone) && result == ISC_R_FILENOTFOUND)) {
                        dns_zone_logc(zone, DNS_LOGCATEGORY_ZONELOAD,
                                      ISC_LOG_ERROR,
                                      "not loaded due to errors.");
-               else if (zone->type == dns_zone_master)
+               } else if (zone->type == dns_zone_master) {
                        result = ISC_R_SUCCESS;
+               }
        }
 
  done:
@@ -7653,8 +7737,9 @@ zone_nsec3chain(dns_zone_t *zone) {
        UNLOCK_ZONE(zone);
        first = true;
 
-       if (nsec3chain != NULL)
+       if (nsec3chain != NULL) {
                nsec3chain->save_delete_nsec = nsec3chain->delete_nsec;
+       }
        /*
         * Generate new NSEC3 chains first.
         *
@@ -7740,40 +7825,47 @@ zone_nsec3chain(dns_zone_t *zone) {
                 * Check to see if this is a bottom of zone node.
                 */
                result = dns_db_allrdatasets(db, node, version, 0, &iterator);
-               if (result == ISC_R_NOTFOUND)   /* Empty node? */
+               if (result == ISC_R_NOTFOUND) {
+                       /* Empty node? */
                        goto next_addnode;
-               if (result != ISC_R_SUCCESS)
+               }
+               if (result != ISC_R_SUCCESS) {
                        goto failure;
+               }
 
-               seen_soa = seen_ns = seen_dname = seen_ds = seen_nsec =
-                       false;
+               seen_soa = seen_ns = seen_dname = seen_ds = seen_nsec = false;
                for (result = dns_rdatasetiter_first(iterator);
                     result == ISC_R_SUCCESS;
-                    result = dns_rdatasetiter_next(iterator)) {
+                    result = dns_rdatasetiter_next(iterator))
+               {
                        dns_rdatasetiter_current(iterator, &rdataset);
                        INSIST(rdataset.type != dns_rdatatype_nsec3);
-                       if (rdataset.type == dns_rdatatype_soa)
+                       if (rdataset.type == dns_rdatatype_soa) {
                                seen_soa = true;
-                       else if (rdataset.type == dns_rdatatype_ns)
+                       } else if (rdataset.type == dns_rdatatype_ns) {
                                seen_ns = true;
-                       else if (rdataset.type == dns_rdatatype_dname)
+                       } else if (rdataset.type == dns_rdatatype_dname) {
                                seen_dname = true;
-                       else if (rdataset.type == dns_rdatatype_ds)
+                       } else if (rdataset.type == dns_rdatatype_ds) {
                                seen_ds = true;
-                       else if (rdataset.type == dns_rdatatype_nsec)
+                       } else if (rdataset.type == dns_rdatatype_nsec) {
                                seen_nsec = true;
+                       }
                        dns_rdataset_disassociate(&rdataset);
                }
                dns_rdatasetiter_destroy(&iterator);
                /*
                 * Is there a NSEC chain than needs to be cleaned up?
                 */
-               if (seen_nsec)
+               if (seen_nsec) {
                        nsec3chain->seen_nsec = true;
-               if (seen_ns && !seen_soa && !seen_ds)
+               }
+               if (seen_ns && !seen_soa && !seen_ds) {
                        unsecure = true;
-               if ((seen_ns && !seen_soa) || seen_dname)
+               }
+               if ((seen_ns && !seen_soa) || seen_dname) {
                        delegation = true;
+               }
 
                /*
                 * Process one node.
@@ -7853,8 +7945,9 @@ zone_nsec3chain(dns_zone_t *zone) {
                                dns_db_detachnode(db, &node);
                                if (!dns_name_issubdomain(nextname, name))
                                        break;
-                       } else
+                       } else {
                                break;
+                       }
                } while (1);
                continue;
 
@@ -7867,12 +7960,14 @@ zone_nsec3chain(dns_zone_t *zone) {
                dns_dbiterator_pause(nsec3chain->dbiterator);
                nsec3chain = nextnsec3chain;
                first = true;
-               if (nsec3chain != NULL)
+               if (nsec3chain != NULL) {
                        nsec3chain->save_delete_nsec = nsec3chain->delete_nsec;
+               }
        }
 
-       if (nsec3chain != NULL)
+       if (nsec3chain != NULL) {
                goto skip_removals;
+       }
 
        /*
         * Process removals.
@@ -7897,11 +7992,13 @@ zone_nsec3chain(dns_zone_t *zone) {
                nextnsec3chain = ISC_LIST_NEXT(nsec3chain, link);
                UNLOCK_ZONE(zone);
 
-               if (nsec3chain->db != db)
+               if (nsec3chain->db != db) {
                        goto next_removechain;
+               }
 
-               if (!NSEC3REMOVE(nsec3chain->nsec3param.flags))
+               if (!NSEC3REMOVE(nsec3chain->nsec3param.flags)) {
                        goto next_removechain;
+               }
 
                /*
                 * Work out if we need to build a NSEC chain as a consequence
@@ -7922,9 +8019,10 @@ zone_nsec3chain(dns_zone_t *zone) {
                        }
                }
 
-               if (first)
+               if (first) {
                        dns_zone_log(zone, ISC_LOG_DEBUG(3), "zone_nsec3chain:"
                                     "buildnsecchain = %u\n", buildnsecchain);
+               }
 
                dns_dbiterator_current(nsec3chain->dbiterator, &node, name);
                delegation = false;
@@ -7973,7 +8071,8 @@ zone_nsec3chain(dns_zone_t *zone) {
                                             NULL, NULL);
                        if ((result == DNS_R_DELEGATION ||
                             result == DNS_R_DNAME) &&
-                           !dns_name_equal(name, found)) {
+                           !dns_name_equal(name, found))
+                       {
                                /*
                                 * Remember the obscuring name so that
                                 * we skip all obscured names.
@@ -7988,37 +8087,44 @@ zone_nsec3chain(dns_zone_t *zone) {
                 * Check to see if this is a bottom of zone node.
                 */
                result = dns_db_allrdatasets(db, node, version, 0, &iterator);
-               if (result == ISC_R_NOTFOUND)   /* Empty node? */
+               if (result == ISC_R_NOTFOUND) {
+                       /* Empty node? */
                        goto next_removenode;
-               if (result != ISC_R_SUCCESS)
+               }
+               if (result != ISC_R_SUCCESS) {
                        goto failure;
+               }
 
-               seen_soa = seen_ns = seen_dname = seen_nsec3 = seen_nsec =
-                       seen_rr = false;
+               seen_soa = seen_ns = seen_dname = seen_nsec3 =
+                          seen_nsec = seen_rr = false;
                for (result = dns_rdatasetiter_first(iterator);
                     result == ISC_R_SUCCESS;
-                    result = dns_rdatasetiter_next(iterator)) {
+                    result = dns_rdatasetiter_next(iterator))
+               {
                        dns_rdatasetiter_current(iterator, &rdataset);
-                       if (rdataset.type == dns_rdatatype_soa)
+                       if (rdataset.type == dns_rdatatype_soa) {
                                seen_soa = true;
-                       else if (rdataset.type == dns_rdatatype_ns)
+                       } else if (rdataset.type == dns_rdatatype_ns) {
                                seen_ns = true;
-                       else if (rdataset.type == dns_rdatatype_dname)
+                       } else if (rdataset.type == dns_rdatatype_dname) {
                                seen_dname = true;
-                       else if (rdataset.type == dns_rdatatype_nsec)
+                       } else if (rdataset.type == dns_rdatatype_nsec) {
                                seen_nsec = true;
-                       else if (rdataset.type == dns_rdatatype_nsec3)
+                       } else if (rdataset.type == dns_rdatatype_nsec3) {
                                seen_nsec3 = true;
-                       if (rdataset.type != dns_rdatatype_rrsig)
+                       } else if (rdataset.type != dns_rdatatype_rrsig) {
                                seen_rr = true;
+                       }
                        dns_rdataset_disassociate(&rdataset);
                }
                dns_rdatasetiter_destroy(&iterator);
 
-               if (!seen_rr || seen_nsec3 || seen_nsec)
+               if (!seen_rr || seen_nsec3 || seen_nsec) {
                        goto next_removenode;
-               if ((seen_ns && !seen_soa) || seen_dname)
+               }
+               if ((seen_ns && !seen_soa) || seen_dname) {
                        delegation = true;
+               }
 
                /*
                 * Add a NSEC record except at the origin.
@@ -8073,9 +8179,12 @@ zone_nsec3chain(dns_zone_t *zone) {
                                                       &node, nextname);
                                dns_db_detachnode(db, &node);
                                if (!dns_name_issubdomain(nextname, name))
+                                       {
                                        break;
-                       } else
+                                       }
+                       } else {
                                break;
+                       }
                } while (1);
                continue;
 
@@ -8109,20 +8218,23 @@ zone_nsec3chain(dns_zone_t *zone) {
                }
                for (result = dns_rdatasetiter_first(iterator);
                     result == ISC_R_SUCCESS;
-                    result = dns_rdatasetiter_next(iterator)) {
+                    result = dns_rdatasetiter_next(iterator))
+               {
                        dns_rdatasetiter_current(iterator, &rdataset);
-                       if (rdataset.type == dns_rdatatype_nsec)
+                       if (rdataset.type == dns_rdatatype_nsec) {
                                rebuild_nsec = true;
-                       if (rdataset.type == dns_rdatatype_nsec3param)
+                       } else if (rdataset.type == dns_rdatatype_nsec3param) {
                                rebuild_nsec3 = true;
+                       }
                        dns_rdataset_disassociate(&rdataset);
                }
                dns_rdatasetiter_destroy(&iterator);
                dns_db_detachnode(db, &node);
 
                if (rebuild_nsec) {
-                       if (nsec3chain != NULL)
+                       if (nsec3chain != NULL) {
                                dns_dbiterator_pause(nsec3chain->dbiterator);
+                       }
 
                        result = updatesecure(db, version, &zone->origin,
                                              zone->minimum, true,
@@ -8137,8 +8249,9 @@ zone_nsec3chain(dns_zone_t *zone) {
                }
 
                if (rebuild_nsec3) {
-                       if (nsec3chain != NULL)
+                       if (nsec3chain != NULL) {
                                dns_dbiterator_pause(nsec3chain->dbiterator);
+                       }
 
                        result = dns_nsec3_addnsec3s(db, version,
                                                     dns_db_origin(db),
@@ -8157,8 +8270,9 @@ zone_nsec3chain(dns_zone_t *zone) {
        /*
         * Add / update signatures for the NSEC3 records.
         */
-       if (nsec3chain != NULL)
+       if (nsec3chain != NULL) {
                dns_dbiterator_pause(nsec3chain->dbiterator);
+       }
        result = dns__zone_updatesigs(&nsec3_diff, db, version, zone_keys,
                                      nkeys, zone, inception, expire, 0, now,
                                      check_ksk, keyset_kskonly, &zonediff);
@@ -8258,7 +8372,9 @@ zone_nsec3chain(dns_zone_t *zone) {
        for (nsec3chain = ISC_LIST_HEAD(zone->nsec3chain);
             nsec3chain != NULL;
             nsec3chain = ISC_LIST_NEXT(nsec3chain, link))
+       {
                dns_dbiterator_pause(nsec3chain->dbiterator);
+       }
        UNLOCK_ZONE(zone);
 
        /*
@@ -8282,9 +8398,11 @@ zone_nsec3chain(dns_zone_t *zone) {
        set_resigntime(zone);
 
  failure:
-       if (result != ISC_R_SUCCESS)
+       if (result != ISC_R_SUCCESS) {
                dns_zone_log(zone, ISC_LOG_ERROR, "zone_nsec3chain: %s",
                             dns_result_totext(result));
+       }
+
        /*
         * On error roll back the current nsec3chain.
         */
@@ -8327,7 +8445,9 @@ zone_nsec3chain(dns_zone_t *zone) {
        for (nsec3chain = ISC_LIST_HEAD(zone->nsec3chain);
             nsec3chain != NULL;
             nsec3chain = ISC_LIST_NEXT(nsec3chain, link))
+       {
                dns_dbiterator_pause(nsec3chain->dbiterator);
+       }
        UNLOCK_ZONE(zone);
 
        dns_diff_clear(&param_diff);
@@ -8335,30 +8455,36 @@ zone_nsec3chain(dns_zone_t *zone) {
        dns_diff_clear(&nsec_diff);
        dns_diff_clear(&_sig_diff);
 
-       if (iterator != NULL)
+       if (iterator != NULL) {
                dns_rdatasetiter_destroy(&iterator);
+       }
 
-       for (i = 0; i < nkeys; i++)
+       for (i = 0; i < nkeys; i++) {
                dst_key_free(&zone_keys[i]);
+       }
 
-       if (node != NULL)
+       if (node != NULL) {
                dns_db_detachnode(db, &node);
+       }
        if (version != NULL) {
                dns_db_closeversion(db, &version, false);
                dns_db_detach(&db);
-       } else if (db != NULL)
+       } else if (db != NULL) {
                dns_db_detach(&db);
+       }
 
        LOCK_ZONE(zone);
        if (ISC_LIST_HEAD(zone->nsec3chain) != NULL) {
                isc_interval_t interval;
-               if (zone->update_disabled || result != ISC_R_SUCCESS)
+               if (zone->update_disabled || result != ISC_R_SUCCESS) {
                        isc_interval_set(&interval, 60, 0);       /* 1 minute */
-               else
+               } else {
                        isc_interval_set(&interval, 0, 10000000); /* 10 ms */
+               }
                isc_time_nowplusinterval(&zone->nsec3chaintime, &interval);
-       } else
+       } else {
                isc_time_settoepoch(&zone->nsec3chaintime);
+       }
        UNLOCK_ZONE(zone);
 
        INSIST(version == NULL);
@@ -8520,8 +8646,9 @@ zone_sign(dns_zone_t *zone) {
        }
 
        ZONEDB_LOCK(&zone->dblock, isc_rwlocktype_read);
-       if (zone->db != NULL)
+       if (zone->db != NULL) {
                dns_db_attach(zone->db, &db);
+       }
        ZONEDB_UNLOCK(&zone->dblock, isc_rwlocktype_read);
        if (db == NULL) {
                result = ISC_R_FAILURE;
@@ -8591,8 +8718,9 @@ zone_sign(dns_zone_t *zone) {
                                 &build_nsec, &build_nsec3));
 
        /* If neither chain is found, default to NSEC */
-       if (!build_nsec && !build_nsec3)
+       if (!build_nsec && !build_nsec3) {
                build_nsec = true;
+       }
 
        while (signing != NULL && nodes-- > 0 && signatures > 0) {
                bool has_alg = false;
@@ -8612,8 +8740,9 @@ zone_sign(dns_zone_t *zone) {
                }
                ZONEDB_UNLOCK(&zone->dblock, isc_rwlocktype_read);
 
-               if (signing->db != db)
+               if (signing->db != db) {
                        goto next_signing;
+               }
 
                is_bottom_of_zone = false;
 
@@ -8664,7 +8793,8 @@ zone_sign(dns_zone_t *zone) {
                                             NULL, NULL);
                        if ((result == DNS_R_DELEGATION ||
                             result == DNS_R_DNAME) &&
-                           !dns_name_equal(name, found)) {
+                           !dns_name_equal(name, found))
+                       {
                                /*
                                 * Remember the obscuring name so that
                                 * we skip all obscured names.
@@ -8691,13 +8821,15 @@ zone_sign(dns_zone_t *zone) {
                        /*
                         * Find the keys we want to sign with.
                         */
-                       if (!dst_key_isprivate(zone_keys[i]))
+                       if (!dst_key_isprivate(zone_keys[i])) {
                                continue;
+                       }
                        /*
                         * Should be redundant.
                         */
-                       if (dst_key_inactive(zone_keys[i]))
+                       if (dst_key_inactive(zone_keys[i])) {
                                continue;
+                       }
 
                        /*
                         * When adding look for the specific key.
@@ -8705,7 +8837,9 @@ zone_sign(dns_zone_t *zone) {
                        if (!signing->deleteit &&
                            (dst_key_alg(zone_keys[i]) != signing->algorithm ||
                             dst_key_id(zone_keys[i]) != signing->keyid))
+                       {
                                continue;
+                       }
 
                        /*
                         * When deleting make sure we are properly signed
@@ -8713,7 +8847,9 @@ zone_sign(dns_zone_t *zone) {
                         */
                        if (signing->deleteit &&
                            ALG(zone_keys[i]) != signing->algorithm)
+                       {
                                continue;
+                       }
 
                        /*
                         * Do we do KSK processing?
@@ -8729,31 +8865,39 @@ zone_sign(dns_zone_t *zone) {
                                }
                                for (j = 0; j < nkeys; j++) {
                                        if (j == i ||
-                                           ALG(zone_keys[i]) !=
-                                           ALG(zone_keys[j]))
+                                           (ALG(zone_keys[i]) !=
+                                            ALG(zone_keys[j])))
+                                       {
                                                continue;
-                                       if (!dst_key_isprivate(zone_keys[j]))
+                                       }
+                                       if (!dst_key_isprivate(zone_keys[j])) {
                                                continue;
+                                       }
                                        /*
                                         * Should be redundant.
                                         */
-                                       if (dst_key_inactive(zone_keys[j]))
+                                       if (dst_key_inactive(zone_keys[j])) {
                                                continue;
-                                       if (REVOKE(zone_keys[j]))
+                                       }
+                                       if (REVOKE(zone_keys[j])) {
                                                continue;
-                                       if (KSK(zone_keys[j]))
+                                       }
+                                       if (KSK(zone_keys[j])) {
                                                have_ksk = true;
-                                       else
+                                       } else {
                                                have_nonksk = true;
+                                       }
                                        both = have_ksk && have_nonksk;
-                                       if (both)
+                                       if (both) {
                                                break;
+                                       }
                                }
                        }
-                       if (both || REVOKE(zone_keys[i]))
+                       if (both || REVOKE(zone_keys[i])) {
                                is_ksk = KSK(zone_keys[i]);
-                       else
+                       } else {
                                is_ksk = false;
+                       }
 
                        /*
                         * If deleting signatures, we need to ensure that
@@ -8845,10 +8989,12 @@ zone_sign(dns_zone_t *zone) {
                                dns_dbiterator_current(signing->dbiterator,
                                                       &node, nextname);
                                dns_db_detachnode(db, &node);
-                               if (!dns_name_issubdomain(nextname, name))
+                               if (!dns_name_issubdomain(nextname, name)) {
                                        break;
-                       } else
+                               }
+                       } else {
                                break;
+                       }
                } while (1);
                continue;
 
@@ -8876,8 +9022,9 @@ zone_sign(dns_zone_t *zone) {
         * Have we changed anything?
         */
        if (ISC_LIST_EMPTY(zonediff.diff->tuples)) {
-               if (zonediff.offline)
+               if (zonediff.offline) {
                        commit = true;
+               }
                result = ISC_R_SUCCESS;
                goto pauseall;
        }
@@ -8928,12 +9075,16 @@ zone_sign(dns_zone_t *zone) {
        for (signing = ISC_LIST_HEAD(zone->signing);
             signing != NULL;
             signing = ISC_LIST_NEXT(signing, link))
+       {
                dns_dbiterator_pause(signing->dbiterator);
+       }
 
        for (signing = ISC_LIST_HEAD(cleanup);
             signing != NULL;
             signing = ISC_LIST_NEXT(signing, link))
+       {
                dns_dbiterator_pause(signing->dbiterator);
+       }
 
        /*
         * Everything has succeeded. Commit the changes.
@@ -8974,7 +9125,9 @@ zone_sign(dns_zone_t *zone) {
        for (signing = ISC_LIST_HEAD(zone->signing);
             signing != NULL;
             signing = ISC_LIST_NEXT(signing, link))
+       {
                dns_dbiterator_pause(signing->dbiterator);
+       }
 
        /*
         * Rollback the cleanup list.
@@ -8990,27 +9143,32 @@ zone_sign(dns_zone_t *zone) {
 
        dns_diff_clear(&_sig_diff);
 
-       for (i = 0; i < nkeys; i++)
+       for (i = 0; i < nkeys; i++) {
                dst_key_free(&zone_keys[i]);
+       }
 
-       if (node != NULL)
+       if (node != NULL) {
                dns_db_detachnode(db, &node);
+       }
 
        if (version != NULL) {
                dns_db_closeversion(db, &version, false);
                dns_db_detach(&db);
-       } else if (db != NULL)
+       } else if (db != NULL) {
                dns_db_detach(&db);
+       }
 
        if (ISC_LIST_HEAD(zone->signing) != NULL) {
                isc_interval_t interval;
-               if (zone->update_disabled || result != ISC_R_SUCCESS)
+               if (zone->update_disabled || result != ISC_R_SUCCESS) {
                        isc_interval_set(&interval, 60, 0);       /* 1 minute */
-               else
+               } else {
                        isc_interval_set(&interval, 0, 10000000); /* 10 ms */
+               }
                isc_time_nowplusinterval(&zone->signingtime, &interval);
-       } else
+       } else {
                isc_time_settoepoch(&zone->signingtime);
+       }
 
        INSIST(version == NULL);
 }
@@ -9242,8 +9400,9 @@ revocable(dns_keyfetch_t *kfetch, dns_rdata_keydata_t *keydata) {
        dns_rdata_fromstruct(&rr, keydata->common.rdclass,
                             dns_rdatatype_dnskey, &dnskey, &keyb);
        result = dns_dnssec_keyfromrdata(keyname, &rr, mctx, &dstkey);
-       if (result != ISC_R_SUCCESS)
+       if (result != ISC_R_SUCCESS) {
                return (false);
+       }
 
        /* See if that key generated any of the signatures */
        for (result = dns_rdataset_first(&kfetch->dnskeysigset);
@@ -9329,16 +9488,19 @@ keyfetch_done(isc_task_t *task, isc_event_t *event) {
        eresult = devent->result;
 
        /* Free resources which are not of interest */
-       if (devent->node != NULL)
+       if (devent->node != NULL) {
                dns_db_detachnode(devent->db, &devent->node);
-       if (devent->db != NULL)
+       }
+       if (devent->db != NULL) {
                dns_db_detach(&devent->db);
+       }
        isc_event_free(&event);
        dns_resolver_destroyfetch(&kfetch->fetch);
 
        LOCK_ZONE(zone);
-       if (DNS_ZONE_FLAG(zone, DNS_ZONEFLG_EXITING) || zone->view == NULL)
+       if (DNS_ZONE_FLAG(zone, DNS_ZONEFLG_EXITING) || zone->view == NULL) {
                goto cleanup;
+       }
 
        isc_stdtime_get(&now);
        dns_name_format(keyname, namebuf, sizeof(namebuf));
@@ -9353,8 +9515,9 @@ keyfetch_done(isc_task_t *task, isc_event_t *event) {
        zone->refreshkeycount--;
        alldone = (zone->refreshkeycount == 0);
 
-       if (alldone)
+       if (alldone) {
                DNS_ZONE_CLRFLAG(zone, DNS_ZONEFLG_REFRESHING);
+       }
 
        dns_zone_log(zone, ISC_LOG_DEBUG(3),
                     "Returned from key fetch in keyfetch_done() for "
@@ -9362,7 +9525,8 @@ keyfetch_done(isc_task_t *task, isc_event_t *event) {
 
        /* Fetch failed */
        if (eresult != ISC_R_SUCCESS ||
-           !dns_rdataset_isassociated(&kfetch->dnskeyset)) {
+           !dns_rdataset_isassociated(&kfetch->dnskeyset))
+       {
                dns_zone_log(zone, ISC_LOG_WARNING,
                             "Unable to fetch DNSKEY set "
                             "'%s': %s", namebuf, dns_result_totext(eresult));
@@ -9406,8 +9570,10 @@ keyfetch_done(isc_task_t *task, isc_event_t *event) {
                        dns_fixedname_init(&fixed);
 
                        dstkey = dns_keynode_key(keynode);
-                       if (dstkey == NULL) /* fail_secure() was called */
+                       if (dstkey == NULL) {
+                               /* fail_secure() was called */
                                break;
+                       }
 
                        if (dst_key_alg(dstkey) == sig.algorithm &&
                            dst_key_id(dstkey) == sig.keyid)
@@ -9506,7 +9672,8 @@ keyfetch_done(isc_task_t *task, isc_event_t *event) {
 
                        if (!secure) {
                                if (keydata.removehd != 0 &&
-                                   keydata.removehd <= now) {
+                                   keydata.removehd <= now)
+                               {
                                        deletekey = true;
                                }
                        } else if (keydata.addhd == 0) {
@@ -9517,11 +9684,11 @@ keyfetch_done(isc_task_t *task, isc_event_t *event) {
                                             "unexpectedly missing "
                                             "restarting 30-day acceptance "
                                             "timer", keytag, namebuf);
-                               if (keydata.addhd < now + dns_zone_mkey_month)
+                               if (keydata.addhd < now + dns_zone_mkey_month) {
                                        keydata.addhd =
                                                now + dns_zone_mkey_month;
-                               keydata.refresh = refresh_time(kfetch,
-                                                              false);
+                               }
+                               keydata.refresh = refresh_time(kfetch, false);
                        } else if (keydata.removehd == 0) {
                                dns_zone_log(zone, ISC_LOG_DEBUG(3),
                                             "Active key %d for zone %s "
@@ -9536,8 +9703,7 @@ keyfetch_done(isc_task_t *task, isc_event_t *event) {
                                             "managed keys database",
                                             keytag, namebuf);
                        } else {
-                               keydata.refresh = refresh_time(kfetch,
-                                                              false);
+                               keydata.refresh = refresh_time(kfetch, false);
                        }
 
                        if (secure || deletekey) {
@@ -9547,8 +9713,9 @@ keyfetch_done(isc_task_t *task, isc_event_t *event) {
                                                    &keydatarr));
                        }
 
-                       if (!secure || deletekey)
+                       if (!secure || deletekey) {
                                continue;
+                       }
 
                        dns_rdata_reset(&keydatarr);
                        isc_buffer_init(&keyb, key_buf, sizeof(key_buf));
@@ -9635,9 +9802,9 @@ keyfetch_done(isc_task_t *task, isc_event_t *event) {
                                                         &dnskey, mctx);
 
                                        /* If initializing, delete now */
-                                       if (keydata.addhd == 0)
+                                       if (keydata.addhd == 0) {
                                                deletekey = true;
-                                       else {
+                                       else {
                                                keydata.removehd = now +
                                                        dns_zone_mkey_month;
                                                keydata.flags |=
@@ -9689,10 +9856,11 @@ keyfetch_done(isc_task_t *task, isc_event_t *event) {
                                                     "has returned: starting "
                                                     "30-day acceptance timer",
                                                     keytag, namebuf);
-                               } else if (keydata.addhd > now)
+                               } else if (keydata.addhd > now) {
                                        pending++;
-                               else if (keydata.addhd == 0)
+                               } else if (keydata.addhd == 0) {
                                        keydata.addhd = now;
+                               }
 
                                if (keydata.addhd <= now) {
                                        trustkey = true;
@@ -9721,15 +9889,17 @@ keyfetch_done(isc_task_t *task, isc_event_t *event) {
                                             keytag, namebuf);
                        }
 
-                       if (!deletekey && !newkey)
+                       if (!deletekey && !newkey) {
                                updatekey = true;
+                       }
                } else if (secure) {
                        /*
                         * Key wasn't in the key zone but it's
                         * revoked now anyway, so just skip it
                         */
-                       if (revoked)
+                       if (revoked) {
                                continue;
+                       }
 
                        /* Key wasn't in the key zone: add it */
                        newkey = true;
@@ -9760,10 +9930,11 @@ keyfetch_done(isc_task_t *task, isc_event_t *event) {
                }
 
                /* Delete old version */
-               if (deletekey || !newkey)
+               if (deletekey || !newkey) {
                        CHECK(update_one_rr(kfetch->db, ver, &diff,
                                            DNS_DIFFOP_DEL, keyname, 0,
                                            &keydatarr));
+               }
 
                if (updatekey) {
                        /* Set refresh timer */
@@ -9821,8 +9992,9 @@ keyfetch_done(isc_task_t *task, isc_event_t *event) {
         * see if there's pending keydata.  If so, we put a null key in
         * the security roots; then all queries to the zone will fail.
         */
-       if (pending != 0)
+       if (pending != 0) {
                fail_secure(zone, keyname);
+       }
 
  done:
        if (!ISC_LIST_EMPTY(diff.tuples)) {
@@ -9855,8 +10027,9 @@ keyfetch_done(isc_task_t *task, isc_event_t *event) {
                             isc_result_totext(result));
        }
        dns_diff_clear(&diff);
-       if (ver != NULL)
+       if (ver != NULL) {
                dns_db_closeversion(kfetch->db, &ver, commit);
+       }
 
  cleanup:
        dns_db_detach(&kfetch->db);
@@ -9865,24 +10038,29 @@ keyfetch_done(isc_task_t *task, isc_event_t *event) {
        zone->irefs--;
        kfetch->zone = NULL;
 
-       if (dns_rdataset_isassociated(&kfetch->keydataset))
+       if (dns_rdataset_isassociated(&kfetch->keydataset)) {
                dns_rdataset_disassociate(&kfetch->keydataset);
-       if (dns_rdataset_isassociated(&kfetch->dnskeyset))
+       }
+       if (dns_rdataset_isassociated(&kfetch->dnskeyset)) {
                dns_rdataset_disassociate(&kfetch->dnskeyset);
-       if (dns_rdataset_isassociated(&kfetch->dnskeysigset))
+       }
+       if (dns_rdataset_isassociated(&kfetch->dnskeysigset)) {
                dns_rdataset_disassociate(&kfetch->dnskeysigset);
+       }
 
        dns_name_free(keyname, mctx);
        isc_mem_put(mctx, kfetch, sizeof(dns_keyfetch_t));
        isc_mem_detach(&mctx);
 
-       if (secroots != NULL)
+       if (secroots != NULL) {
                dns_keytable_detach(&secroots);
+       }
 
        free_needed = exit_check(zone);
        UNLOCK_ZONE(zone);
-       if (free_needed)
+       if (free_needed) {
                zone_free(zone);
+       }
 
        INSIST(ver == NULL);
 }
@@ -9931,7 +10109,8 @@ zone_refreshkeys(dns_zone_t *zone) {
        dns_rriterator_init(&rrit, db, ver, 0);
        for (result = dns_rriterator_first(&rrit);
             result == ISC_R_SUCCESS;
-            result = dns_rriterator_nextrrset(&rrit)) {
+            result = dns_rriterator_nextrrset(&rrit))
+       {
                isc_stdtime_t timer = 0xffffffff;
                dns_name_t *name = NULL, *kname = NULL;
                dns_rdataset_t *kdset = NULL;
@@ -9941,7 +10120,9 @@ zone_refreshkeys(dns_zone_t *zone) {
                dns_rriterator_current(&rrit, &name, &ttl, &kdset, NULL);
                if (kdset == NULL || kdset->type != dns_rdatatype_keydata ||
                    !dns_rdataset_isassociated(kdset))
+               {
                        continue;
+               }
 
                /*
                 * Scan the stored keys looking for ones that need
@@ -9949,7 +10130,8 @@ zone_refreshkeys(dns_zone_t *zone) {
                 */
                for (result = dns_rdataset_first(kdset);
                     result == ISC_R_SUCCESS;
-                    result = dns_rdataset_next(kdset)) {
+                    result = dns_rdataset_next(kdset))
+               {
                        dns_rdata_reset(&rdata);
                        dns_rdataset_current(kdset, &rdata);
                        result = dns_rdata_tostruct(&rdata, &kd, NULL);
@@ -9964,19 +10146,22 @@ zone_refreshkeys(dns_zone_t *zone) {
                        }
 
                        /* Acceptance timer expired? */
-                       if (kd.addhd <= now)
+                       if (kd.addhd <= now) {
                                timer = kd.addhd;
+                       }
 
                        /* Or do we just need to refresh the keyset? */
-                       if (timer > kd.refresh)
+                       if (timer > kd.refresh) {
                                timer = kd.refresh;
+                       }
 
                        set_refreshkeytimer(zone, &kd, now, false);
                        timerset = true;
                }
 
-               if (timer > now)
+               if (timer > now) {
                        continue;
+               }
 
                kfetch = isc_mem_get(zone->mctx, sizeof(dns_keyfetch_t));
                if (kfetch == NULL) {
@@ -10037,9 +10222,9 @@ zone_refreshkeys(dns_zone_t *zone) {
                        result = ISC_R_FAILURE;
                }
 #endif
-               if (result == ISC_R_SUCCESS)
+               if (result == ISC_R_SUCCESS) {
                        fetching = true;
-               else {
+               else {
                        zone->refreshkeycount--;
                        zone->irefs--;
                        dns_db_detach(&kfetch->db);
@@ -10081,8 +10266,9 @@ zone_refreshkeys(dns_zone_t *zone) {
                isc_time_settoepoch(&zone->refreshkeytime);
        }
 
-       if (!fetching)
+       if (!fetching) {
                DNS_ZONE_CLRFLAG(zone, DNS_ZONEFLG_REFRESHING);
+       }
 
        dns_diff_clear(&diff);
        if (ver != NULL) {
@@ -17869,10 +18055,13 @@ sign_apex(dns_zone_t *zone, dns_db_t *db, dns_dbversion_t *ver,
         */
        for (tuple = ISC_LIST_HEAD(diff->tuples);
             tuple != NULL;
-            tuple = ISC_LIST_NEXT(tuple, link)) {
+            tuple = ISC_LIST_NEXT(tuple, link))
+       {
                if (tuple->rdata.type == dns_rdatatype_dnskey &&
                    dns_name_equal(&tuple->name, &zone->origin))
+               {
                        break;
+               }
        }
 
        if (tuple == NULL) {
@@ -17909,8 +18098,9 @@ sign_apex(dns_zone_t *zone, dns_db_t *db, dns_dbversion_t *ver,
        }
 
  failure:
-       for (i = 0; i < nkeys; i++)
+       for (i = 0; i < nkeys; i++) {
                dst_key_free(&zone_keys[i]);
+       }
        return (result);
 }
 
@@ -17931,11 +18121,14 @@ dnskey_sane(dns_zone_t *zone, dns_db_t *db, dns_dbversion_t *ver,
        /* Scan the tuples for an NSEC-only DNSKEY */
        for (tuple = ISC_LIST_HEAD(diff->tuples);
             tuple != NULL;
-            tuple = ISC_LIST_NEXT(tuple, link)) {
+            tuple = ISC_LIST_NEXT(tuple, link))
+       {
                uint8_t alg;
                if (tuple->rdata.type != dns_rdatatype_dnskey ||
                    tuple->op != DNS_DIFFOP_ADD)
+               {
                        continue;
+               }
 
                alg = tuple->rdata.data[3];
                if (alg == DST_ALG_RSASHA1) {
@@ -17947,15 +18140,17 @@ dnskey_sane(dns_zone_t *zone, dns_db_t *db, dns_dbversion_t *ver,
        /* Check existing DB for NSEC-only DNSKEY */
        if (!nseconly) {
                result = dns_nsec_nseconly(db, ver, &nseconly);
-               if (result == ISC_R_NOTFOUND)
+               if (result == ISC_R_NOTFOUND) {
                        result = ISC_R_SUCCESS;
+               }
                CHECK(result);
        }
 
        /* Check existing DB for NSEC3 */
-       if (!nsec3)
+       if (!nsec3) {
                CHECK(dns_nsec3_activex(db, ver, false,
                                        privatetype, &nsec3));
+       }
 
        /* Refuse to allow NSEC3 with NSEC-only keys */
        if (nseconly && nsec3) {
@@ -18054,15 +18249,15 @@ zone_rekey(dns_zone_t *zone) {
        dns_dbversion_t *ver = NULL;
        dns_rdataset_t cdsset, soaset, soasigs, keyset, keysigs, cdnskeyset;
        dns_dnsseckeylist_t dnskeys, keys, rmkeys;
-       dns_dnsseckey_t *key;
+       dns_dnsseckey_t *key = NULL;
        dns_diff_t diff, _sig_diff;
        dns__zonediff_t zonediff;
        bool commit = false, newactive = false;
        bool newalg = false;
        bool fullsign;
        dns_ttl_t ttl = 3600;
-       const char *dir;
-       isc_mem_t *mctx;
+       const char *dir = NULL;
+       isc_mem_t *mctx = NULL;
        isc_stdtime_t now;
        isc_time_t timenow;
        isc_interval_t ival;
@@ -18110,8 +18305,9 @@ zone_rekey(dns_zone_t *zone) {
                                                     &keysigs, &soasigs,
                                                     false, false,
                                                     &dnskeys));
-       } else if (result != ISC_R_NOTFOUND)
+       } else if (result != ISC_R_NOTFOUND) {
                goto failure;
+       }
 
 
        /* Get the CDS rdataset */
@@ -18124,7 +18320,9 @@ zone_rekey(dns_zone_t *zone) {
        result = dns_db_findrdataset(db, node, ver, dns_rdatatype_cdnskey,
                                     dns_rdatatype_none, 0, &cdnskeyset, NULL);
        if (result != ISC_R_SUCCESS && dns_rdataset_isassociated(&cdnskeyset))
+       {
                dns_rdataset_disassociate(&cdnskeyset);
+       }
 
        /*
         * True when called from "rndc sign".  Indicates the zone should be
@@ -18175,9 +18373,11 @@ zone_rekey(dns_zone_t *zone) {
                 */
                for (key = ISC_LIST_HEAD(dnskeys);
                     key != NULL;
-                    key = ISC_LIST_NEXT(key, link)) {
-                       if (!key->first_sign)
+                    key = ISC_LIST_NEXT(key, link))
+               {
+                       if (!key->first_sign) {
                                continue;
+                       }
 
                        newactive = true;
 
@@ -18200,7 +18400,8 @@ zone_rekey(dns_zone_t *zone) {
                }
 
                if ((newactive || fullsign || !ISC_LIST_EMPTY(diff.tuples)) &&
-                   dnskey_sane(zone, db, ver, &diff)) {
+                   dnskey_sane(zone, db, ver, &diff))
+               {
                        CHECK(dns_diff_apply(&diff, db, ver));
                        CHECK(clean_nsec3param(zone, db, ver, &diff));
                        CHECK(add_signing_records(db, zone->privatetype,
@@ -18232,7 +18433,8 @@ zone_rekey(dns_zone_t *zone) {
                if (!ISC_LIST_EMPTY(rmkeys)) {
                        for (key = ISC_LIST_HEAD(rmkeys);
                             key != NULL;
-                            key = ISC_LIST_NEXT(key, link)) {
+                            key = ISC_LIST_NEXT(key, link))
+                       {
                                result = zone_signwithkey(zone,
                                                          dst_key_alg(key->key),
                                                          dst_key_id(key->key),
@@ -18252,9 +18454,11 @@ zone_rekey(dns_zone_t *zone) {
                         */
                        for (key = ISC_LIST_HEAD(dnskeys);
                             key != NULL;
-                            key = ISC_LIST_NEXT(key, link)) {
-                               if (!key->force_sign && !key->hint_sign)
+                            key = ISC_LIST_NEXT(key, link))
+                       {
+                               if (!key->force_sign && !key->hint_sign) {
                                        continue;
+                               }
 
                                result = zone_signwithkey(zone,
                                                          dst_key_alg(key->key),
@@ -18275,9 +18479,11 @@ zone_rekey(dns_zone_t *zone) {
                         */
                        for (key = ISC_LIST_HEAD(dnskeys);
                             key != NULL;
-                            key = ISC_LIST_NEXT(key, link)) {
-                               if (!key->first_sign)
+                            key = ISC_LIST_NEXT(key, link))
+                       {
+                               if (!key->first_sign) {
                                        continue;
+                               }
 
                                result = zone_signwithkey(zone,
                                                          dst_key_alg(key->key),
@@ -18303,22 +18509,29 @@ zone_rekey(dns_zone_t *zone) {
                 */
                for (tuple = ISC_LIST_HEAD(zonediff.diff->tuples);
                     tuple != NULL;
-                    tuple = ISC_LIST_NEXT(tuple, link)) {
+                    tuple = ISC_LIST_NEXT(tuple, link))
+               {
                        unsigned char buf[DNS_NSEC3PARAM_BUFFERSIZE];
                        dns_rdata_t rdata = DNS_RDATA_INIT;
                        dns_rdata_nsec3param_t nsec3param;
 
                        if (tuple->rdata.type != zone->privatetype ||
                            tuple->op != DNS_DIFFOP_ADD)
+                       {
                                continue;
+                       }
 
                        if (!dns_nsec3param_fromprivate(&tuple->rdata, &rdata,
                                                        buf, sizeof(buf)))
+                       {
                                continue;
+                       }
+
                        result = dns_rdata_tostruct(&rdata, &nsec3param, NULL);
                        RUNTIME_CHECK(result == ISC_R_SUCCESS);
-                       if (nsec3param.flags == 0)
+                       if (nsec3param.flags == 0) {
                                continue;
+                       }
 
                        result = zone_addnsec3chain(zone, &nsec3param);
                        if (result != ISC_R_SUCCESS) {
@@ -18332,8 +18545,9 @@ zone_rekey(dns_zone_t *zone) {
                 * Activate any NSEC3 chain updates that may have
                 * been scheduled before this rekey.
                 */
-               if (fullsign || newalg)
+               if (fullsign || newalg) {
                        resume_addnsec3chain(zone);
+               }
 
                /*
                 * Schedule the next resigning event
@@ -18361,16 +18575,19 @@ zone_rekey(dns_zone_t *zone) {
 
                for (key = ISC_LIST_HEAD(dnskeys);
                     key != NULL;
-                    key = ISC_LIST_NEXT(key, link)) {
+                    key = ISC_LIST_NEXT(key, link))
+               {
                        then = now;
                        result = next_keyevent(key->key, &then);
-                       if (result != ISC_R_SUCCESS)
+                       if (result != ISC_R_SUCCESS) {
                                continue;
+                       }
 
                        DNS_ZONE_TIME_ADD(&timenow, then - now, &timethen);
                        LOCK_ZONE(zone);
                        if (isc_time_compare(&timethen,
-                                            &zone->refreshkeytime) < 0) {
+                                            &zone->refreshkeytime) < 0)
+                       {
                                zone->refreshkeytime = timethen;
                        }
                        UNLOCK_ZONE(zone);
@@ -18382,7 +18599,19 @@ zone_rekey(dns_zone_t *zone) {
                dns_zone_log(zone, ISC_LOG_INFO, "next key event: %s", timebuf);
        }
 
- done:
+       result = ISC_R_SUCCESS;
+
+ failure:
+       if (result != ISC_R_SUCCESS) {
+               /*
+                * Something went wrong; try again in ten minutes or
+                * after a key refresh interval, whichever is shorter.
+                */
+               isc_interval_set(&ival,
+                                ISC_MIN(zone->refreshkeyinterval, 600), 0);
+               isc_time_nowplusinterval(&zone->refreshkeytime, &ival);
+       }
+
        dns_diff_clear(&diff);
        dns_diff_clear(&_sig_diff);
 
@@ -18390,34 +18619,32 @@ zone_rekey(dns_zone_t *zone) {
        clear_keylist(&keys, mctx);
        clear_keylist(&rmkeys, mctx);
 
-       if (ver != NULL)
+       if (ver != NULL) {
                dns_db_closeversion(db, &ver, false);
-       if (dns_rdataset_isassociated(&cdsset))
+       }
+       if (dns_rdataset_isassociated(&cdsset)) {
                dns_rdataset_disassociate(&cdsset);
-       if (dns_rdataset_isassociated(&keyset))
+       }
+       if (dns_rdataset_isassociated(&keyset)) {
                dns_rdataset_disassociate(&keyset);
-       if (dns_rdataset_isassociated(&keysigs))
+       }
+       if (dns_rdataset_isassociated(&keysigs)) {
                dns_rdataset_disassociate(&keysigs);
-       if (dns_rdataset_isassociated(&soasigs))
+       }
+       if (dns_rdataset_isassociated(&soasigs)) {
                dns_rdataset_disassociate(&soasigs);
-       if (dns_rdataset_isassociated(&cdnskeyset))
+       }
+       if (dns_rdataset_isassociated(&cdnskeyset)) {
                dns_rdataset_disassociate(&cdnskeyset);
-       if (node != NULL)
+       }
+       if (node != NULL) {
                dns_db_detachnode(db, &node);
-       if (db != NULL)
+       }
+       if (db != NULL) {
                dns_db_detach(&db);
+       }
 
        INSIST(ver == NULL);
-       return;
-
- failure:
-       /*
-        * Something went wrong; try again in ten minutes or
-        * after a key refresh interval, whichever is shorter.
-        */
-       isc_interval_set(&ival, ISC_MIN(zone->refreshkeyinterval, 600), 0);
-       isc_time_nowplusinterval(&zone->refreshkeytime, &ival);
-       goto done;
 }
 
 void
@@ -18825,11 +19052,13 @@ keydone(isc_task_t *task, isc_event_t *event) {
        dns_diff_init(zone->mctx, &diff);
 
        ZONEDB_LOCK(&zone->dblock, isc_rwlocktype_read);
-       if (zone->db != NULL)
+       if (zone->db != NULL) {
                dns_db_attach(zone->db, &db);
+       }
        ZONEDB_UNLOCK(&zone->dblock, isc_rwlocktype_read);
-       if (db == NULL)
+       if (db == NULL) {
                goto failure;
+       }
 
        dns_db_currentversion(db, &oldver);
        result = dns_db_newversion(db, &newver);
@@ -18841,8 +19070,9 @@ keydone(isc_task_t *task, isc_event_t *event) {
        }
 
        result = dns_db_getoriginnode(db, &node);
-       if (result != ISC_R_SUCCESS)
+       if (result != ISC_R_SUCCESS) {
                goto failure;
+       }
 
        result = dns_db_findrdataset(db, node, newver, zone->privatetype,
                                     dns_rdatatype_none, 0, &rdataset, NULL);
@@ -18857,7 +19087,8 @@ keydone(isc_task_t *task, isc_event_t *event) {
 
        for (result = dns_rdataset_first(&rdataset);
             result == ISC_R_SUCCESS;
-            result = dns_rdataset_next(&rdataset)) {
+            result = dns_rdataset_next(&rdataset))
+       {
                bool found = false;
 
                dns_rdataset_current(&rdataset, &rdata);
@@ -18865,20 +19096,25 @@ keydone(isc_task_t *task, isc_event_t *event) {
                if (kd->all) {
                        if (rdata.length == 5 && rdata.data[0] != 0 &&
                               rdata.data[3] == 0 && rdata.data[4] == 1)
+                       {
                                found = true;
-                       else if (rdata.data[0] == 0 &&
-                                (rdata.data[2] & PENDINGFLAGS) != 0) {
+                       } else if (rdata.data[0] == 0 &&
+                                  (rdata.data[2] & PENDINGFLAGS) != 0)
+                       {
                                found = true;
                                clear_pending = true;
                        }
                } else if (rdata.length == 5 &&
                           memcmp(rdata.data, kd->data, 5) == 0)
+               {
                        found = true;
+               }
 
-               if (found)
+               if (found) {
                        CHECK(update_one_rr(db, newver, &diff, DNS_DIFFOP_DEL,
                                            &zone->origin, rdataset.ttl,
                                            &rdata));
+               }
                dns_rdata_reset(&rdata);
        }
 
@@ -18890,8 +19126,9 @@ keydone(isc_task_t *task, isc_event_t *event) {
                result = dns_update_signatures(&log, zone, db,
                                               oldver, newver, &diff,
                                               zone->sigvalidityinterval);
-               if (!clear_pending)
+               if (!clear_pending) {
                        CHECK(result);
+               }
 
                CHECK(zone_journal(zone, &diff, NULL, "keydone"));
                commit = true;
@@ -18903,15 +19140,19 @@ keydone(isc_task_t *task, isc_event_t *event) {
        }
 
  failure:
-       if (dns_rdataset_isassociated(&rdataset))
+       if (dns_rdataset_isassociated(&rdataset)) {
                dns_rdataset_disassociate(&rdataset);
+       }
        if (db != NULL) {
-               if (node != NULL)
+               if (node != NULL) {
                        dns_db_detachnode(db, &node);
-               if (oldver != NULL)
+               }
+               if (oldver != NULL) {
                        dns_db_closeversion(db, &oldver, false);
-               if (newver != NULL)
+               }
+               if (newver != NULL) {
                        dns_db_closeversion(db, &newver, commit);
+               }
                dns_db_detach(&db);
        }
        dns_diff_clear(&diff);
@@ -18942,9 +19183,9 @@ dns_zone_keydone(dns_zone_t *zone, const char *keystr) {
        }
 
        kd = (struct keydone *) e;
-       if (strcasecmp(keystr, "all") == 0)
+       if (strcasecmp(keystr, "all") == 0) {
                kd->all = true;
-       else {
+       else {
                isc_textregion_t r;
                const char *algstr;
                dns_keytag_t keyid;
@@ -18954,14 +19195,16 @@ dns_zone_keydone(dns_zone_t *zone, const char *keystr) {
                kd->all = false;
 
                n = sscanf(keystr, "%hu/", &keyid);
-               if (n == 0U)
+               if (n == 0U) {
                        CHECK(ISC_R_FAILURE);
+               }
 
                algstr = strchr(keystr, '/');
-               if (algstr != NULL)
+               if (algstr != NULL) {
                        algstr++;
-               else
+               } else {
                        CHECK(ISC_R_FAILURE);
+               }
 
                n = sscanf(algstr, "%hhu", &alg);
                if (n == 0U) {
@@ -18983,8 +19226,9 @@ dns_zone_keydone(dns_zone_t *zone, const char *keystr) {
        isc_task_send(zone->task, &e);
 
  failure:
-       if (e != NULL)
+       if (e != NULL) {
                isc_event_free(&e);
+       }
        UNLOCK_ZONE(zone);
        return (result);
 }
@@ -19030,11 +19274,13 @@ setnsec3param(isc_task_t *task, isc_event_t *event) {
        dns_diff_init(zone->mctx, &diff);
 
        ZONEDB_LOCK(&zone->dblock, isc_rwlocktype_read);
-       if (zone->db != NULL)
+       if (zone->db != NULL) {
                dns_db_attach(zone->db, &db);
+       }
        ZONEDB_UNLOCK(&zone->dblock, isc_rwlocktype_read);
-       if (db == NULL)
+       if (db == NULL) {
                goto failure;
+       }
 
        dns_db_currentversion(db, &oldver);
        result = dns_db_newversion(db, &newver);
@@ -19056,12 +19302,14 @@ setnsec3param(isc_task_t *task, isc_event_t *event) {
        if (result == ISC_R_SUCCESS) {
                for (result = dns_rdataset_first(&prdataset);
                     result == ISC_R_SUCCESS;
-                    result = dns_rdataset_next(&prdataset)) {
+                    result = dns_rdataset_next(&prdataset))
+               {
                        dns_rdata_init(&rdata);
                        dns_rdataset_current(&prdataset, &rdata);
 
                        if (np->length == rdata.length &&
-                           memcmp(rdata.data, np->data, np->length) == 0) {
+                           memcmp(rdata.data, np->data, np->length) == 0)
+                       {
                                exists = true;
                                break;
                        }
@@ -19080,7 +19328,8 @@ setnsec3param(isc_task_t *task, isc_event_t *event) {
        if (result == ISC_R_SUCCESS) {
                for (result = dns_rdataset_first(&nrdataset);
                     result == ISC_R_SUCCESS;
-                    result = dns_rdataset_next(&nrdataset)) {
+                    result = dns_rdataset_next(&nrdataset))
+               {
                        dns_rdata_init(&rdata);
                        dns_rdataset_current(&nrdataset, &rdata);
 
@@ -19103,9 +19352,10 @@ setnsec3param(isc_task_t *task, isc_event_t *event) {
         * parameters are supposed to replace the current ones or if we are
         * switching to NSEC.
         */
-       if (!exists && np->replace && (np->length != 0 || np->nsec))
+       if (!exists && np->replace && (np->length != 0 || np->nsec)) {
                CHECK(dns_nsec3param_deletechains(db, newver, zone,
                                                  !np->nsec, &diff));
+       }
 
        if (!exists && np->length != 0) {
                /*
@@ -19122,8 +19372,9 @@ setnsec3param(isc_task_t *task, isc_event_t *event) {
 
                np->data[2] |= DNS_NSEC3FLAG_CREATE;
                result = dns_nsec_nseconly(db, newver, &nseconly);
-               if (result == ISC_R_NOTFOUND || nseconly)
+               if (result == ISC_R_NOTFOUND || nseconly) {
                        np->data[2] |= DNS_NSEC3FLAG_INITIAL;
+               }
 
                rdata.length = np->length;
                rdata.data = np->data;
@@ -19145,8 +19396,9 @@ setnsec3param(isc_task_t *task, isc_event_t *event) {
                result = dns_update_signatures(&log, zone, db,
                                               oldver, newver, &diff,
                                               zone->sigvalidityinterval);
-               if (result != ISC_R_NOTFOUND)
+               if (result != ISC_R_NOTFOUND) {
                        CHECK(result);
+               }
                CHECK(zone_journal(zone, &diff, NULL, "setnsec3param"));
                commit = true;
 
@@ -19157,18 +19409,24 @@ setnsec3param(isc_task_t *task, isc_event_t *event) {
        }
 
  failure:
-       if (dns_rdataset_isassociated(&prdataset))
+       if (dns_rdataset_isassociated(&prdataset)) {
                dns_rdataset_disassociate(&prdataset);
-       if (dns_rdataset_isassociated(&nrdataset))
+       }
+       if (dns_rdataset_isassociated(&nrdataset)) {
                dns_rdataset_disassociate(&nrdataset);
-       if (node != NULL)
+       }
+       if (node != NULL) {
                dns_db_detachnode(db, &node);
-       if (oldver != NULL)
+       }
+       if (oldver != NULL) {
                dns_db_closeversion(db, &oldver, false);
-       if (newver != NULL)
+       }
+       if (newver != NULL) {
                dns_db_closeversion(db, &newver, commit);
-       if (db != NULL)
+       }
+       if (db != NULL) {
                dns_db_detach(&db);
+       }
        if (commit) {
                LOCK_ZONE(zone);
                resume_addnsec3chain(zone);
@@ -19274,8 +19532,9 @@ dns_zone_setnsec3param(dns_zone_t *zone, uint8_t hash, uint8_t flags,
        ZONEDB_UNLOCK(&zone->dblock, isc_rwlocktype_read);
 
  failure:
-       if (e != NULL)
+       if (e != NULL) {
                isc_event_free(&e);
+       }
        UNLOCK_ZONE(zone);
        return (result);
 }