The method used to generate a test zone with multiple NSEC and NSEC3 chains was incorrect. Multiple calls to dnssec-signzone with multiple parameters is not additive. Extract the chain on each run then add them to the final signed zone instance.