4 Resolved and Known Bugs

This chapter lists the resolved and known bugs for Oracle Communications Cloud Native Core release 3.25.1.2xx.0.

These lists are distributed to customers with a new software release at the time of General Availability (GA) and are updated for each maintenance release.

4.1 Severity Definitions

Service requests for supported Oracle programs may be submitted by you online through Oracle’s web-based customer support systems or by telephone. The service request severity level is selected by you and Oracle and should be based on the severity definitions specified below.

Severity 1

Your production use of the supported programs is stopped or so severely impacted that you cannot reasonably continue work. You experience a complete loss of service. The operation is mission critical to the business and the situation is an emergency. A Severity 1 service request has one or more of the following characteristics:
  • Data corrupted.
  • A critical documented function is not available.
  • System hangs indefinitely, causing unacceptable or indefinite delays for resources or response.
  • System crashes, and crashes repeatedly after restart attempts.

Reasonable efforts will be made to respond to Severity 1 service requests within one hour. For response efforts associated with Oracle Communications Network Software Premier Support and Oracle Communications Network Software Support & Sustaining Support, please see the Oracle Communications Network Premier & Sustaining Support and Oracle Communications Network Software Support & Sustaining Support sections above.

Except as otherwise specified, Oracle provides 24 hour support for Severity 1 service requests for supported programs (OSS will work 24x7 until the issue is resolved) when you remain actively engaged with OSS working toward resolution of your Severity 1 service request. You must provide OSS with a contact during this 24x7 period, either on site or by phone, to assist with data gathering, testing, and applying fixes. You are requested to propose this severity classification with great care, so that valid Severity 1 situations obtain the necessary resource allocation from Oracle.

Severity 2

You experience a severe loss of service. Important features are unavailable with no acceptable workaround; however, operations can continue in a restricted fashion.

Severity 3

You experience a minor loss of service. The impact is an inconvenience, which may require a workaround to restore functionality.

Severity 4

You request information, an enhancement, or documentation clarification regarding your software but there is no impact on the operation of the software. You experience no loss of service. The result does not impede the operation of a system.

4.2 Resolved Bug List

The following Resolved Bugs tables list the bugs that are resolved in Oracle Communications Cloud Native Core Release 3.25.1.2xx.0.

4.2.1 BSF Resolved Bugs

Release 26.1.201

Table 4-1 BSF 26.1.201 Resolved Bugs

Bug Number Title Description Severity Found In Release
39557457 NF discovery failed when PCF priority was not defined NF discovery failed with a NullPointerException when the NRF profile did not define a priority value for PCF. This disrupted discovery processing for profiles that omitted the priority field.

Doc Impact: No Doc Impact.

3 25.1.200
38830387 Alternate routing did not occur during PCF shutdown When a PCF was in controlled shutdown and its Diameter pod was scaled down, BSF did not attempt the configured alternate route.

Doc Impact: No Doc Impact.

2 25.1.200
38962335 Log event metric was unavailable after upgrade After an in-service BSF upgrade, the log4j2_events_total metric was unavailable from the monitoring service although it was available from the pod actuator endpoint. This prevented expected log event monitoring through Prometheus or Grafana.

Doc Impact: No Doc Impact.

2 25.2.200
38909575 BSF ingress gateway pod protection did not enable BSF ingress gateway pod protection did not enable in release 25.1.203, and the expected pod-protection behavior was unavailable for BSF ingress gateway.

Doc Impact: No Doc Impact.

3 25.1.202
38953320 NRF Agent configuration import did not update the configuration The NRF Agent configuration import REST API returned success for action=Create without updating the configuration, misleading users that imported configuration was applied.

Doc Impact: No Doc Impact.

3 25.2.200
38958909 Replication failed during new-site addition Replication failed while a site was upgraded during new-site addition. This disrupted site-addition or upgrade workflows that depended on successful replication.

Doc Impact: No Doc Impact.

3 25.2.200
39202393 Egress Diameter monitoring metrics failed Egress Diameter traffic monitoring metrics failed on some Diameter Gateway pods because meshMap entries were corrupted, reducing visibility into Diameter traffic across the affected pods.

Doc Impact: No Doc Impact.

3 25.2.102
39225155 Common Services REST specification contained an incorrect resource URI The Common Services REST specification contained an incorrect resource URI for BSF/PCF.

Doc Impact: The Error Code section in Oracle Communications Cloud Native Core, Binding Support Function REST Specification Guide was updated with the correct resource URI.

3 25.1.201
38065064 Correlation-information header metric did not update The ocbsf_correlation_info_header_received metric did not update when requests included the 3gpp-sbi-correlation-info header.

Doc Impact: No Doc Impact.

3 25.1.200
38305515 Warnings appeared during BSF lifecycle operations Helm warnings appeared during BSF installation, uninstallation, or upgrade on a cluster.

Doc Impact: No Doc Impact.

3 25.2.100
38986750 Message Profile creation failed with filter conditions The REST API could not create a Message Profile when messageProfileFilterConditions was specified.

Doc Impact: No Doc Impact.

3 25.2.200
39003985 Configuration export omitted screens CM-UI export omitted some configuration screens though they were present in the UI.

Doc Impact: No Doc Impact.

3 25.2.200
39068631 BSF management reported database lock-wait timeouts BSF management frequently reported database lock-wait timeout errors.

Doc Impact: No Doc Impact.

3 25.2.200
39066970 BSF Management Service returned an incorrect error response BSF Management Service returned HTTP 500 for requests that should have returned a method-not-allowed response.

Doc Impact: No Doc Impact.

3 25.2.200
39096764 Egress Gateway did not generate an alert for DNS SRV resolution failures Egress Gateway did not generate the expected alert when DNS SRV resolution failed.

Doc Impact: No Doc Impact.

3 25.1.100
39407313 Database pod restarted during high traffic The ndbmysqld pod restarted during an overnight 63K TPS traffic run.

Doc Impact: No Doc Impact.

3 25.2.200
38735372 Data became inconsistent after rollback Data became inconsistent after rollback was completed.

Doc Impact: No Doc Impact.

3 25.2.200
38913231 BSF chart contained an unused parameter The BSF Helm chart contained an unused isIpv6Enabled parameter.

Doc Impact: No Doc Impact.

3 25.2.200
38751933 BSF Management and Query Service restart failed Restarting the BSF Management and Query Service deployment failed with a duplicate port definition error.

Doc Impact: No Doc Impact.

3 24.2.2
38962235 Ephemeral-storage settings were not applied BSF service ephemeral-storage requests and limits were not reflected in the deployed configuration, causing cluster resource-policy violations.

Doc Impact: No Doc Impact.

3 25.2.200
38726956 SCP alerts continued after monitoring was disabled SCP alerts continued even after the SCP Monitoring feature was disabled.

Doc Impact: No Doc Impact.

3 25.1.200
38834313 BSF management-service logs contained date-time parsing errors BSF management-service pod logs contained DateTimeParseException errors.

Doc Impact: No Doc Impact.

3 25.1.100
39096491 BSF custom YAML files contained obsolete references BSF custom YAML files contained obsolete references to timerSvc and database tables.

Doc Impact: No Doc Impact.

3 25.1.200
39326592 BSF upgrade failed during the pre-upgrade hook The BSF upgrade failed during the pre-upgrade hook phase when upgrading to 25.2.200.

Doc Impact: No Doc Impact.

3 25.2.200
39472592 BSF operational-state change failed in the CNCC GUI Changing the BSF operational state from controlled shutdown in the CNCC GUI returned an “Unable to switch the operational state” error.

Doc Impact: No Doc Impact.

3 25.2.100

4.2.2 CNC Console Resolved Bugs

Release 25.1.204

Table 4-2 CNC Console 25.1.204 Resolved Bugs

Bug Number Title Description Severity Found in Release
39622387 CNC Console error while changing the operational state. Operational-state changes from the CNCC GUI failed because requests were not sent with the required Content-Type: application/json header. GUI request handling was corrected so the header was sent.

Doc Impact:

There is no doc impact.

3 25.2.101
39702392 LDAP users were not authenticated after CNCC upgrade to 25.1.202 from 24.2.4. LDAP test connections and logins could fail in single-stack IPv6 environments because CNCC-IAM/Keycloak was not started with the required IPv6 preference settings. Custom-values support was updated to expose cncc-iam.kc.preferIpv6Stack.enabled, and the upgrade/rollback documentation was updated for IPv6 preference configuration and Unicode-safe backup and restore.

Doc Impact:

Updated the CNC Console custom-values and upgrade and rollback documentation are updated with the IPv6 preference configuration and Unicode-safe backup/restore guidance in the Communications Cloud Native Configuration Console Installation, Upgrade, Fault Recovery Guide.

3 25.1.202
39595232 Clarification on API prefix required for PCF and BSF API calls through CNCC The CNC Console User Guide section “Accessing NF Configurations Through Curl and Postman” was updated with Policy and BSF curl-request examples.

Doc Impact:

Examples of Policy and BSF curl requests are added in Oracle Communications Cloud Native Configuration Console User Guide.

4 25.1.200
39622373 CNCC LDAP server binding credentials through API The CNC Console REST API documentation was updated with additional endpoints for updating LDAP server binding credentials through REST APIs, using curl or Postman. Documentation impact: The CNC Console REST API documentation was updated with the additional APIs.

Doc Impact:

Additional APIs are added in Oracle Communications Cloud Native Configuration Console REST API Guide.
4 24.2.3

Release 25.1.203

CNC Console 25.1.203 is a Critical Patch Update. Critical Patch Updates provide security patches for supported Oracle on-premises products. They are available to customers with valid support contracts. For more information, see Critical Patch Updates, Security Alerts, and Bulletins.

There are no resolved bugs in this release.

Release 25.1.202

Table 4-3 CNC Console 25.1.202 Resolved Bugs

Bug Number Title Description Severity Found in Release
38916016 POLICY_READ Role enabled but user is also able to edit the parameters

Users who only had the POLICY_READ role assigned were able to edit parameters on some Policy screens. The "General Configurations" screen correctly blocked write operations with a "403 FORBIDDEN" error, but the "policy-project" screen allowed users to save changes. This happened because the Policy API prefix was not added on certain screens.

Doc Impact:

There is no doc impact.

3 24.2.3

Resolved bugs from 24.2.4 have been forward ported to Release 25.1.202.

Release 25.1.201

There are no resolved bugs in this release.

Note:

Resolved bugs from 24.2.6 have been forward ported to Release 25.1.201.

Release 25.1.200

Table 4-4 CNC Console 25.1.200 Resolved Bugs

Bug Number Title Description Severity Found in Release
37427171 PreProd: Policy CNCC 24.2.1 WARNINGS/ERRORS list of log messages

The public.dynamic.datamodel error/warning log messages were printed in cmservice pod logs.

Doc Impact:

There is no doc impact.

3 25.1.100
37899676 NF Selector not appearing in CNCC GUI

Occasionally, upon logging into the CNC Console Core, the NF instance selector dropdown fails to appear. This prevents users from accessing their desired NF Instance configuration. Instead, the cnPCF instance is displayed by default.

Doc Impact:

There is no doc impact.

3 24.2.1
38165407 Request to add check for golang version to CNCC Release Notes and Installation Guide

The CNC Console Installation, Upgrade, and Fault Recovery Guide needs to be updated with a note that informs the user that they must remove ec_point_formats from clientDisabledExtensions and serverDisabledExtensions to prevent deployment failure if they want to deploy CNC Console on a system with an older Kubernetes/Go version (for example, v1.23.10/go1.17.13).

Doc Impact:

Updated the note in the "Preupgrade Tasks" and "Customizing CNC Console" sections in Oracle Communications, Cloud Native Configuration Console Installation, Upgrade, and Fault Recovery Guide.

3 25.1.100

Note:

Resolved bugs from 25.2.4 have been forward ported to Release 25.1.200.

4.2.3 cnDBTier Resolved Bugs

Release 25.1.201-6

Bug Number Title Description Severity Found In Release
39789596 cnDBTier 25.1.201-4 ndbmysqld pods PVC utilization levels between 85% and 90% The ndbmysqld pods' PVC utilization levels were observed between 85% and 90%.

Doc impact:

There is no doc impact.
2 25.1.201

Release 25.1.201-5

Table 4-5 cnDBTier 25.1.201-5 Resolved Bugs

Bug Number Title Description Severity Found In Release
38692787 Replication breaks after ndbmysqld pod restart — cnDBTier throws false Duplicate entry '2000' error During a switchover, an ndbmysqld pod restarted, after which replication broke. The mysql-cluster-one-two-c1-replication-svc logged duplicate primary-key violations while updating and persisting replication channel information.

Doc impact:

There is no doc impact.

2 25.1.201

Release 25.1.201-5

Table 4-6 cnDBTier 25.1.201-5 Resolved Bugs

Bug Number Title Description Severity Found In Release
38692787 Replication breaks after ndbmysqld pod restart — cnDBTier throws false Duplicate entry '2000' error During a switchover, an ndbmysqld pod restarted, after which replication broke. The mysql-cluster-one-two-c1-replication-svc logged duplicate primary-key violations while updating and persisting replication channel information.

Doc impact:

There is no doc impact.

2 25.1.201

Release 25.1.201-4

Table 4-7 cnDBTier 25.1.201-4 Resolved Bugs

Bug Number Title Description Severity Found In Release
38758595 GRR Parallel Restore Feature not working

The Geo Replication Recovery (GRR) process was failing due to a premature shutdown of the thread pools responsible for transferring backup parts and their corresponding checksum files between sites. This issue was due to an incorrect query used to verify transfer completion: the query inaccurately determines that both the checksum files for the backup parts have been fully transferred to the remote (failed) site.

Doc impact:

There is no doc impact.

2 25.1.203
38677062 SLF dbtremovesite is restarting the application pods When running the dbtremovesite script as part of the site migration process, it was observed that the monitor-service and backup-manager-svc for the corresponding site would unexpectedly restart, which in turn triggered a restart of associated application pods. This occurred even when the site was still active and processing live traffic, causing an unnecessary and unintended disruption to ongoing services.

Doc impact:

There is no doc impact.

3 25.1.100
38865774 Metrics are getting missed on site-3 on a 3 site GR Setup - 6 replication group The incorrect MySQL host resolution due to partial hostname matching caused Grafana dashboard to intermittently miss metrics reporting despite active replication traffic.

Doc impact:

There is no doc impact.

3 25.1.201

Release 25.1.201-3

Table 4-8 cnDBTier 25.1.201-3 Resolved Bugs

Bug Number Title Description Severity Found In Release
38679777 Backup Manager on Site3 Fails to Initiate GRR Backup After Site2 Recovery, Causing GRR Failure; HTTPS TLS setup; Network policy enabled When HTTPS and network policy are enabled, the non-leader replication service cannot initiate backups because its network policy egress rules do not include the BackupManager service port. This prevented necessary communication and lead to backup failures.

Doc impact:

There is no doc impact.

2 25.1.201
38678258 Replication channels are not established post fresh install of 25.1.201-2 The replication-svc pod traffic was being blocked by the ASM Istio sidecar. This occured because the required IPv6 addresses were not added to the Istio ServiceEntry (SE) and DestinationRule (DR) objects.

As a result, the Istio sidecar returned a 502 Bad Gateway error and blocked all traffic directed towards the remote site.

Doc impact:

There is no doc impact.

2 25.1.201
38584415 IPv6 address is not getting assigned to cnDBTier replication service When deployed in a dual stack configuration, the cnDBTier replication pods continued to receive IPv4 addresses and communicated over IPv4 instead of preferring IPv6.

The behaviour is observed even after configuring the pod to prefer IPv6 using the /etc/gai.conf file.

Doc impact:

Following updates are made in documentation:
  • Added a verification step in the "Support for Dual Stack" section in Oracle Communications Cloud Native Core, cnDBTier User Guide.
  • Updated the supported values for the global parameter /serviceMode/external/connectivityService in Oracle Communications Cloud Native Core, cnDBTier Installation, Upgrade, and Fault Recovery Guide.
3 25.1.200
38646497 Observing outbound traffic on ipv4.

The DB replication services were using IPv4 despite IPv6 being preferred in configuration.

Doc impact:

There is no doc impact.

3 25.1.201
38651597 cnDBtier Replication Service leader Pod is not coming up and taking some time

During the fresh installation of cnDBtier across three sites, the leader pod for the replication service at one site experienced a significant startup delay, and the remaining pods were inactive until cnDBTier was installed on another site.

Doc impact:

There is no doc impact.

3 25.1.201

Release 25.1.201-2

Table 4-9 cnDBTier 25.1.201-2 Resolved Bugs

Bug Number Title Description Severity Found In Release
38584415 IPv6 address is not getting assigned to cnDBTier replication service When deployed in a dual stack configuration, the cnDBTier replication pods continued to receive IPv4 addresses and communicated over IPv4 instead of preferring IPv6.

The behavious is observed even after configuring the pod to prefer IPv6 using the /etc/gai.conf file.

Doc impact:

Following updates are made in documentation:
  • Added a verification step in the "Support for Dual Stack" section in Oracle Communications Cloud Native Core, cnDBTier User Guide.
  • Updated the supported values for the global parameter /serviceMode/external/connectivityService in Oracle Communications Cloud Native Core, cnDBTier Installation, Upgrade, and Fault Recovery Guide.
3 25.1.200
38646497 Observing outbound traffic on ipv4.

The DB replication services were using IPv4 despite IPv6 being preferred in configuration.

Doc impact:

There is no doc impact.

3 25.1.201
38651597 cnDBtier Replication Service leader Pod is not coming up and taking some time

During the fresh installation of cnDBtier across three sites, the leader pod for the replication service at one site experienced a significant startup delay, and the remaining pods were inactive until cnDBTier was installed on another site.

Doc impact:

There is no doc impact.

3 25.1.201

Release 25.1.201-1

Table 4-10 cnDBTier 25.1.201-1 Resolved Bugs

Bug Number Title Description Severity Found In Release
38584415 IPv6 address is not getting assigned to cnDBTier replication service When deployed in a dual-stack configuration, cnDBTier replication pods were still receiving IPv4 addresses and communicating over IPv4, rather than preferring IPv6 as expected.

Doc impact:

Following updates are made in documentation:
  • Added a verification step in the "Support for Dual Stack" section in Oracle Communications Cloud Native Core, cnDBTier User Guide.
  • Updated the supported values for the global parameter /serviceMode/external/connectivityService in Oracle Communications Cloud Native Core, cnDBTier Installation, Upgrade, and Fault Recovery Guide.
3 25.1.200

Release 25.1.201

Table 4-11 cnDBTier 25.1.201 Resolved Bugs

Bug Number Title Description Severity Found In Release
38236749 Binlog cleanup command missing in example section of Restore DB procedure using local backup

While restoring ndb database, binlogs were not cleaned. The command DELETE FROM replication_info.DBTIER_INITIAL_BINLOG_POSTION was missing in the Restore procedure.

Doc impact:

Updated the sample output to include DELETE FROM replication_info.DBTIER_INITIAL_BINLOG_POSTION command in the "Downloading the Latest DB Backup Before Restoration" section in Oracle Communications Cloud Native Core, cnDBTier Installation, Upgrade, and Fault Recovery Guide.

2 25.1.100
37864092 dbtscale_ndbmtd_pods script exited with 'Create Nodegroup FAILED' for wrong nodegroup In a four site, ASM enabled, backup encrypted and password encrypted setup, the horizontal data pod scaling failed while using the dbtscale_ndbmtd_pods script and exited with 'Create Nodegroup FAILED" error. Wait for the new ndbmtd pods to start and assigned with the "no nodegroup" state before creating the node groups.

Doc Impact:

There is no doc impact.

2 24.2.5
38204318 Site removal script dbtremovesite is failing with error of script version mismatch on CNDB While running the dbtremovesite site removal script, the script was failing due to the version mismatch. The cnDBTier library version was updated per the script version.

Doc impact:

There is no doc impact.

2 25.1.102
38204306 dbtremovesite script exits with ERROR - DBTIER_SCRIPT_VERSION (<25.1.100>) does not match DBTIER_LIBRARY_VERSION Version of the dbtremovesite script did not match with the cnDBTier library version which resulted in an error. The cnDBTier library version was updated per the script version.

Doc impact:

There is no doc impact.

2 25.1.201
38224168 Update georeplication recovery procedure to remove duplicate steps Updated the georeplication recovery procedure to remove the duplicated steps.

Doc impact:

Removed the steps that mention about the creation of NFs during georeplication failure recovery. For more information see the "Restoring Georeplication (GR) Failure" section in Oracle Communications Cloud Native Core cnDBTier Installation, Upgrade, and Fault Recovery Guide.

2 25.1.102
38200832 Schema change distribution is slowing down replication causing data discrepancy across 2 sites In a multi-site Policy Control Function (PCF) setup, where site 1 (policy1) was completed a PCF application upgrade that included a schema upgrade, and site 2 (policy3) had fallen behind in replication, resulting in data discrepancies.

Doc impact:

There is no doc impact.

2 25.1.200
37668951 information_schema and table schema is seen to be inconsistent when policy upgrade was performed After a policy upgrade, the metadata in information_schema did not reflect the actual table schema.

Doc impact:

There is no doc impact.

2 25.1.200
37978500 Incorrect key file for table 'SmPolicyAssociation'; try to repair it

The Incorrect key file for table error was encountered for specific tables like Smservice and common configuration tables. It is recommended to always reopen the table with the missing index.

Doc impact:

There is no doc impact.

2 23.4.6
37975847 All data nodes experienced a simultaneous restart following the cnDBTier upgrade A simultaneous restart of all data nodes (that is, all ndbmtd pods) following a cnDBTier upgrade was observed.

Doc impact:

There is no doc impact.

2 25.1.200
38278713 Document update required "DB Tier Stop Replica API" in User Guide cnDBTier User Guide did not provide a reference in the "DBTier Stop Replica API" section to the procedure that explained the steps to gracefully start and stop georeplication between sites.

Doc impact

Added a reference to the "Stopping cnDBTier Georeplication Between Sites" section in the "DBTier Stop Replica API" section in Oracle Communications Cloud Native Core cnDBTier User Guide.

2 25.1.201
38220013 dbtrecover Script is affecting db-monitor-svc A deadlock occurred in the db-monitor-svc during SQL pod restarts that caused connection assignment failure, as the monitoring service was unable to assign connections correctly.

Doc impact:

There is no doc impact.

3 25.1.100
38268348 Communication between db-monitor-svc and NF backend pods breaks during the ndbapp scaled down negative scenario While implementing the following negative scenario in which a full traffic of SLF ( 50K lookup and 1.44K prov on site1 ), scaling the ndbapp pods from 7 to 0 for 15min. 2) after 15min again scaled up the ndbapp pods from 0 to 7.

Fixed the deadlock in db-monitor-svc during SQL pod restart which caused connection assignment failure.

Doc impact:

There is no doc impact.

3 25.1.100
37859265 dbtscale_ndbmtd_pods disrupted by ndbmtd pod restart When dbtscale_ndbmtd_pods are run to scale data nodes (ndbmtd pods) on site1 from 8 to 14. The script was due to a ndbmtd pod restart during the scale operation is disrupted.

Doc impact:

There is no doc impact.

3 25.1.100
37859029 dbtscale_ndbmtd_pods failed when ndb backup triggered while scaling in progress While scaling ndbmtd pods from 8 to 12 using the dbtscale_ndbmtd_pods script, thepods were scaled up, and REORGANIZE PARTITION had started. However, the script terminated with an error.

Doc impact:

There is no doc impact.

3 25.1.100
38129271 Upgrade from 23.4.0 to 25.1.100 broke replication between sites Added the following new error numbers to the list of replication errors:
  • 1091 (Can't DROP – column/key doesn't exist)
  • 1826 (Duplicate foreign key constraint name)

Removed the error "1094 - Unknown command" from the list.

Doc Impact:

There is no doc impact.

3 23.4.6
38144181 Add additional replication errors(1091, 1826) in the replication skip error section and remove 1094 replication erro from list Added the following new error numbers to the list of replication errors:
  • 1091 (Can't DROP – column/key doesn't exist)
  • 1826 (Duplicate foreign key constraint name)

Removed the error "1094 - Unknown command" from the list.

Doc impact:

There is no doc impact.

3 23.4.6
37942052 dbtscale_ndbmtd_pods not working when release name contains prefix When a single-site setup was deployed with a prefix used in the release name, and when the dbtscale_ndbmtd_pods script was run on this setup, the script was failing with the following error: "Error: UPGRADE FAILED: "mysql-cluster" has no deployed releases". This was because DBTIER_RELEASE_NAME was not set.

Doc impact:

There is no doc impact.

3 25.1.200
38197150 Horizontal data pod scaling failed using dbtscale_ndbmtd_pods script and exited with 'Create Nodegroup FAILED" error In a four site, ASM enabled, backup encrypted and password encrypted setup, the horizontal data pod scaling failed while using the dbtscale_ndbmtd_pods script and exited with 'Create Nodegroup FAILED" error. Wait for the new ndbmtd pods to start and assigned with the "no nodegroup" state before creating the node groups.

Doc Impact:

There is no doc impact.

3 25.1.100
38288330 db-monitor-svc Requests Backup Transfer Status Before Transfer Starts Georeplication recovery (non-fatal) was implemented using dbtrecover on a 2-site Georeplication (GR) setup with multi-channel replication with the following condition:
  • site 1 = Good site
  • site 2 = Site being recovered

Errors were observed in the backup-mgr-svc pod on site-1 and no GRR related logs were printed in the backup-mgr-svc logs.

Doc Impact:

There is no doc impact.

3 25.1.200
38304684 Georeplication recovery failed with 6 channel replication channel over SM setup Georeplication recovery was failing because the required Persistent Volume Claims (PVC) size for the replication service was not configured rightly.

Doc Impact:

There is no doc impact.

3 25.1.201
38314302 Document steps to create service account manually in case Helm MOP is enabled and individual flag are set as false with user defined name cnDBTier documentation did not provide steps to create service account, roles, and role binding manually if user does not want automated service account creation.

Doc Impact:

Updated the steps to create the Namespace in the "Verifying and Creating Namespace" section. For more information, see Oracle Communications Cloud Native Core cnDBTier Installation, Upgrade, and Fault Recovery Guide

   
38278476 Documentation for serviceAccounts/create flag is not clear when it is set as true cnDBTier documentation did not provide comprehensive and clear documentation of RBAC configuration parameters.

Doc Impact:

Added a table "autoCreateResources Configurations" that provides autoCreateResources parameter configurations in different scenarios in the "LCM Based Automation" section in Oracle Communications Cloud Native Core cnDBTier User Guide

   
38245044 Documentation should mention which site to be sourced in dbtremovesite cnDBTier documentation did not provide details on which site must be used as the source when using the dbtremovesite script.

Doc Impact:

Updated the "Removing cnDBTier Cluster" section to specify which site must be used as the source when using dbtremovesite script. For more information, see Oracle Communication Cloud Native Core, cnDBTier User Guide.

4 25.1.200

Note:

Resolved bugs from 25.1.103 and 24.2.6 have been forward ported to release 25.1.201.

Release 25.1.200

Table 4-12 cnDBTier 25.1.200 Resolved Bugs

Bug Number Title Description Severity Found In Release
37775811 Binlog cleanup command missing in example section of Restore DB procedure using local backup

While restoring ndb database, binlogs were not cleaned. The command DELETE FROM replication_info.DBTIER_INITIAL_BINLOG_POSTION was missing in the Restore procedure.

Doc impact:

Updated the sample output to include DELETE FROM replication_info.DBTIER_INITIAL_BINLOG_POSTION command in the "Downloading the Latest DB Backup Before Restoration" section in Oracle Communications Cloud Native Core, cnDBTier Installation, Upgrade, and Fault Recovery Guide.

2 25.1.100
37807135 dbtscale_ndbmtd_pods not working

The dbtscale_ndbmtd_pods script was failing in cnDBTier 24.2.5 single-site setup as the labels were not present in the stateful sets (STS).

Doc impact:

There is no doc impact.

2 24.2.5
37883263 dbtscale_vertical_pvc failing for ndbmgmd, ndbmysqld, ndbappmysqld, and ndbmtd

The dbtscale_vertical_pvc script contains a variable which can be configured for PVC size in the db-replication-svc deployment called "GEO_RECOVERY_RESOURCES_DISK_SIZE". However, this variable was not present in the db-replication-svc deployment in release 24.2.5. Hence, dbtscale_vertical_pvc script was failing for ndbmgmd, ndbmysqld, ndbappmysqld, and ndbmtd pods.

Doc impact:

There is no doc impact.

2 24.2.5
37978500 SQLException: Incorrect key file for table 'SmPolicyAssociation'; try to repair it

There was an incorrect key file for the table Smserviceand common configuration tables, due to which Sm calls were failing. It is recommended to always reopen the table with the missing index.

Doc impact:

There is no doc impact.

2 23.4.6
37864092 dbtscale_ndbmtd_pods script exited with 'Create Nodegroup FAILED' for wrong nodegroup

When the dbtscale_ndbmtd_pods script was run on a 4-site, ASM enabled, single channel cndBTier to scale the data pods, the script failed with the error, "Create Nodegroup FAILED" for wrong nodegroups. To clear the error, wait until the new ndbmtd pods to start and get assigned with the state "no nodegroup" before creating the node groups.

Doc impact:

There is no doc impact.

2 24.2.5
37859029 dbtscale_ndbmtd_pods failed when ndb backup triggered while scaling in progress

In a three site, multi-channel, cnDBTier setup while scaling of ndbmtd pods, the dbtscale_ndbmtd_pods script failed with the following error. "error 762 'Unable to alter table as backup is in progress'".

Doc impact:

There is no doc impact.

2 24.2.5
37911174 Doc Changes: Stopping cnDBTier Georeplication Between Sites caused replication outage between all sites

While performing the steps given in the cnDBTier User Guide to stop the cnDBTier while performing georeplication between the sites, caused replication outage.

Doc impact:

Updated the following step in the "Starting or Stopping cnDBTier Georeplication Service" section:

  • Run the following command to stop the replication service switchover in cnDBTier with respect to siteName:

    $ curl -X PUT http://$IP:$PORT/ocdbtier/georeplication/switchover/stop/sitename/{siteName}

For example, run the following command to stop the replication service switchover in cnDBTier with respect to cluster1:

$ curl -X PUT http://$IP:$PORT/ocdbtier/georeplication/switchover/stop/sitename/cluster1

Sample output:

{"replicationSwitchOver":"stop"}

For more information about how to start or stop cnDBTier Georeplication service, see Oracle Communications Cloud Native Core cnDBTier Installation, Upgrade, and Fault Recovery Guide.

2 24.2.2
37842445 dbtreplmgr uses hardcoded HTTP protocol causing failure in HTTPS-enabled setups

In a 4-site, HTTPS and TLS enabled, backup encryption and password encryption enabled setup, when the dbtreplmgr script was run to gracefully stop the replication, the replication did not stop and exited with an error. This was due to the script had a hardcoded HTTP parameter that caused the failure.

Doc impact:

There is no doc impact.

2 24.2.5
37076079 Data nodes are running on 99% disk usage

The Persistent Volume Claim(PVC) space for data node and SQL node were critically low and usage limit reached 99%. To monitor the PVC capacity, infra monitor container was injected to fetch the cnDBTier metrics from db-replication-svc service.

Doc impact:

There is no doc impact.

3 23.4.6
37859265 dbtscale_ndbmtd_pods disrupted by ndbmtd pod restart on 24.2.5

When the dbtscale_ndbmtd_pods script was run on a 4-site, ASM enabled, single channel cndBTier to scale the data pods, the script was disrupted by ndbtd pod restart. To resolve this, retried repartitioning the tables, if any data node was down or back up process was in progress.

Doc impact:

There is no doc impact.

3 24.2.5
36905360 CNDB-Upgrade:- ndbappmysqld-0 & ndbappmysqld-1 pods restart observed during CNDB upgrade

In a two-site Georeplication cnDBTier setup, pods were restarting during CNDB upgrade. By default, no-nodeid-checks parameter was set to enable for NDB pods.

Doc impact:

There is no doc impact.

3 24.2.0
37466028 Event name should be displayed instead of eventtype = <integer value> in Cluster Events API

Each type of Cluster event was documented for better readability and understanding.

Doc impact:

Added a list of cluster event types that retrieve information about the events that occur in a cluster in the table "Cluster Event Types" in Oracle Communications Cloud Native Core, cnDBTier Installation, Upgrade, and Fault Recovery Guide.

3 25.1.100
37422096 Documentation is required to understand what does eventtype = <integer value> mean in API response

Each type of Cluster event was documented for better readability and understanding.

Doc impact:

Added a list of cluster event types that retrieve information about the events that occur in a cluster in the table "Cluster Event Types" in Oracle Communications Cloud Native Core, cnDBTier Installation, Upgrade, and Fault Recovery Guide.

3 25.1.100
37442733 Helm test is failing

The Helm test was failing as the opensslversion was unknown during HTTPs certificate creation.

Doc impact:

Added a note that specifies the recommended version of opensslwhich is used to create certificates in the "Creating HTTPS or TLS Certificates for Encrypted Connection" section in Oracle Communications Cloud Native Core, cnDBTier Installation, Upgrade, and Fault Recovery Guide.

3 25.1.100
37404406 Helm rollback from TLS to non-TLS same version not dropping TLS

While Upgrading or rolling back cnDBTier from a non-TLS to TLS enabled version, sites must be upgraded or rolled back twice.

Doc impact:

Added a note that explains how cnDBTier sites must be upgraded or rolled back twice while upgrading or rolling back cnDBTier clusters from a non-TLS version to TLS enabled version is added in the "Upgrading cnDBTier from Non-TLS to TLS Enabled Version (Replication)" section in Oracle Communications Cloud Native Core, cnDBTier Installation, Upgrade, and Fault Recovery Guide.

3 24.2.1
37672597 No response body in case of Retrieve all cluster Status Events API after restore is performed on setup

No response body in case of Retrieve all cluster Status Events API after restore is performed on setup.

Doc impact:

There is no doc impact.

3 25.1.100
37789389 dbtscale_vertical_pvc script doesn't work if ndbdisksize is in decimal

While installing a single site setup, when the value of the parameter ndbdisksize was set in decimal format, the dbtscale_vertical_pvc script failed.

Doc impact:

There is no doc impact.

3 25.1.100
37839960 ndbmtd pods always restart with initial option because of which the data nodes restart time will be increased when no MySQL NDB parameters is changed

ndbmtd pods always restarted with initial (--) option because of which the time taken to restart the data nodes increased even when MySQL NDB parameters were not changed. This was due to cmp command not found in the container.

Doc impact:

There is no doc impact.

3 25.1.100
37753846 Vertical scaling of pvc failed using dbtscale_vertical_pvc script

The "dbtscale_vertical_pvc" script did not have an option to provide the name of the release due to which the script failed because the DBTIER_RELEASE_NAME was not set.

Doc impact:

There is no doc impact.

3 24.2.4
37855078 GRR is not working when the IPv6 address is configured in the remotesiteip configuration in db replication service deployment

If the db replication service deployment was configured with the IPv6 address in remotesiteip, the Georeplication Recovery (GRR) was not working.

Doc impact:

There is no doc impact.

3 25.1.100
37860493 dbtscale_ndbmtd_pods not working when release name contains prefix

When a single site setup was deployed with a prefix used in the release name, and when the dbtscale_ndbmtd_pods script was run on this setup, the script was failing with the following error: "Error: UPGRADE FAILED: "mysql-cluster" has no deployed releases". This was because DBTIER_RELEASE_NAME was not set.

Doc impact:

There is no doc impact.

3 24.2.5
37842199 Need a procedure for Ndbmtd recovery for continuous crashloop due to PVC corruption

The startup configuration must be updated in the NDB section of the custom value file.

Doc impact:

Updated the ndbmtd recovery procedure to add the startup configuration in the "Restoring Single Node Failure" section in Oracle Communications Cloud Native Core, cnDBTier Installation, Upgrade, and Fault Recovery Guide.

3 25.1.100
37884064 Georeplication Recovery Status in CNCC needs to be changed from ACTIVE to NOT_RUNNING

During georeplication recovery (GRR) process, the status on the CNC Console displayed "ACTIVE" for both the sites, which was incorrect. The status on the CNC Console was updated to display "Not Active" or "Not Running" for such scenarios.

Doc impact:

There is no doc impact.

3 25.1.100
37952176 The metric db_tier_ndb_backup_in_progress temporarily shows a value of 1 when a data pod is deleted, even though no backup is actually running on the system

Even though no backup was running on the cnDBTier setup, when a data pod was deleted, the metric db_tier_ndb_backup_in_progress temporarily reports a value of 1.

Doc impact:

There is no doc impact.

3 25.1.100
37943375 The dbtscale_vertical_pvc script doesn't throw any error when wrong charts are provided to the script

The dbtscale_vertical_pvc script did not throw an error when wrong charts are provided to the script. The dbtscale_vertical_pvc script did not validate the chart version.

Doc impact:

There is no doc impact.

3 24.2.5
38161643 CNDBtier upgrade from 23.4.7 to 25.1.101 failed

cnDBTier upgrade from version 23.4.7 to version 25.1.101 (which was having Webscale version 1.3) was failing because the kubectl exec commands did not explicitly specify the container name in Pre/Post upgrade scripts.

Doc impact:

There is no doc impact.

3 25.1.100
37902311 Rollback from TLS to Non-TLS still shows certificate in show replica status

The Upgrade and Rollback procedures did not specify that Updating the Non TLS to TLS and vice-versa procedures can disrupt the service.

Doc impact:

Added a note that specifies the downgrade procedure from TLS to Non-TLS is a disruptive procedure that may temporarily impact Geo-replication. Refer to the section "Rolling Back cnDBTier from Non-TLS to TLS Enabled Version (Replication)" in Oracle Communication Cloud Native Core, cnDBTier Installation, Upgrade, and Fault Recovery Guide.

4 24.2.1
37399510 Support for Console Customized DBtier Custom Values File Parameters

The CNC Console parameter global_max_binlog_size was exposed in the custom_values.yaml file, by default. This parameter sets the size of the binary logs.

Doc impact:

Added the CNC Console parameter global/api/max_binlog_size parameter in the "Global Parameters" section in Oracle Communications Cloud Native Core, cnDBTier Installation, Upgrade, and Fault Recovery Guide.

4 25.1.100
37343226 Implement the inclusive language practices and removing restricted terms from documents codes and logs

Implemented the inclusive language practices and removed restricted terms from documents, codes, and logs.

Doc impact:

Removed the restricted non-inclusive terms such as Slave, Master, Blacklist from the cnDBTier documentation set. See Oracle Communications Cloud Native Core cnDBTier Installation, Upgrade, and Fault Recovery Guide and Oracle Communications Cloud Native Core, cnDBTier User Guide.

4 24.3.0
37980727 Clarification Required for modifying the HTTPS/TLS secrets The section "Certificates to Establish TLS Between Georeplication Sites" in cnDBTier Installation Guide for updating the secrets, did not specify to "Patch" the secret instead of recreating it when the certificate expires or when there is a change in the root CA.

Doc impact:

Updated the section "Certificates to Establish TLS Between Georeplication Sites" to patch the secrets instead of recreating them while establishing TLS between georeplication sites in Oracle Communication Cloud Native Core, cnDBTier User Guide.

4 24.2.1

Note:

Resolved bugs from 25.1.101 and 24.2.5 have been forward ported to release 25.1.200.

4.2.4 CNE Resolved Bugs

Release 25.1.201

There are no resolved bugs in this release.

Release 25.1.200

Table 4-13 CNE 25.1.200 Resolved Bugs

Bug Number Title Description Severity Found in Release
37799030 CNE images_25.1.100.tar missing Velero images

CNE 25.1.100 did not have the Velero images in the images tar file. This issue can lead to install and upgrade failures.

Doc impact:

There is no doc impact.

3 25.1.100
38204306 CNLB egress NAT is not working when there are two NFs on the same ServiceIpSet Two NFs cannot communicate with each other via the external network, if they are in the same CNLB pair (ServiceIpSet), egress NAT is not performed. 3 24.3.1
37842711 CNE OpenStack installation failed due to qcow image changes

While Installing CNE 25.1.100 in Openstack (OL Image OL9U5_x86_64-kvm-b259) environment, deploy.sh script was failing with the ERROR 1: Bastion setup issue error.

Doc impact:

There is no doc impact.

4 25.1.100

Note:

Resolved bugs from 24.2.6, 24.3.3, and 25.1.101 have been forward ported to Release 25.1.200.

OSO Resolved Bugs

Release 25.1.201

Table 4-14 OSO 25.1.201 Resolved Bugs

Bug Number Title Description Severity Found in Release
38662737 OSO- ALERT PATCH USING HELM FAILS

Helm automation pod failed to start due to permission issues seen in image. Error is only seen in VCP/openshift platform.

Doc impact:

There is no doc impact.

3 25.1.200
38733419 OSO-ALM helm chart installation fails when helm test resources are commented

This failure happened because of a change introduced in OSO to separate test resource limits from ALM resource limits as the test limits were reported to have been overwritten by the ALM's.

Doc impact:

There is no doc impact.

3 25.1.200

Release 25.1.200

There are no resolved bugs in this release.

4.2.5 NRF Resolved Bugs

Release 25.1.206

NRF 25.1.206 is a Critical Patch Update. Critical Patch Updates provide security patches for supported Oracle on-premises products. They are available to customers with valid support contracts. For more information, see Critical Patch Updates, Security Alerts, and Bulletins.

There are no resolved bugs in this release.

Release 25.1.205

Table 4-15 NRF 25.1.205 Resolved Bugs

Bug Number Title Description Severity Found In Release
39050962 Incorrect discovery response w.r.t smf slice selection and incorrect value for preferredTaiMatchInd The preferredTaiMatchInd flag was set to true, even if DNN and TAI matches did not occur within the same slice or entity, resulting in false indications. This behavior is corrected so that the preferredTaiMatchInd flag is now set to true only when both are present within the same SmfInfo entity.

Doc Impact: There is no doc impact.

3 25.2.200
39275323 DB Fall backs observed when Subscription queries CDS service During periods of high traffic and frequent subscription requests, the Cache Data microservice intermittently threw NullPointerExceptions while processing subscription requests due to missing null checks on cache lookups. As a result, the Subscription microservice unnecessarily reverted to database access, increasing DB fallback metrics and leading to potential request failures. A null check was added to the duplicate-subscription evaluation logic to prevent these errors and ensure smooth handling when cache entries are absent.

Doc Impact: There is no doc impact.

3 25.2.200
39275395 Despite NF Screening Whitelist, Excluded NFs Eventually Register To NRF Under specific race conditions, registrations and subscriptions that did not meet NF Screening requirements were accepted. Synchronization in NF Screening logic was corrected to ensure rules are enforced for registration and subscription requests.

Doc Impact: There is no doc impact.

3 24.3.0

Release 25.1.204

Table 4-16 NRF 25.1.204 Resolved Bugs

Bug Number Title Description Severity Found In Release
38990515 Auditor microservice: `observedGeneration` in the JSON string is not defined in the `V1PodStatus` The NRF Auditor microservice logged errors when parsing the observedGeneration field in the pod status JSON, which is not defined in the Kubernetes V1PodStatus schema. This occurred on clusters where there were Kubernetes version discrepancies between CNE and NRF. All pods remained operational despite these log errors.

Doc Impact: Updated the supported CNE and Kubernetes versions.

For more information, see "CNE Requirement" and "Software Requirements" section in Oracle Communications Cloud Native Core, Network Repository Function Installation, Upgrade, and Fault Recovery Guide.

3 25.1.203
38771967 SMF Discovery Request With preferred-tai Answered With preferredTaiMatchInd:false Despite All Match NRF returned preferredTaiMatchInd:false in response to SMF discovery requests containing a matching preferred-tai, due to the filter being incorrectly applied only to SmfInfo and not to SmfInfoList. The logic now assesses both fields, ensuring the flag is correctly set to true if any matched entries are found in the SmfInfoList.

Doc Impact: There is no doc impact.

3 25.1.202

Release 25.1.203

Table 4-17 NRF 25.1.203 Resolved Bugs

Bug Number Title Description Severity Found In Release
37604778 TLS1.3 Handshake is failing between NRF and SCP NRF TLS1.3 Handshake failed if the client (SCP) sent session resumption during handshake.

Doc Impact: There is no doc impact.

3 24.2.3
38179022 Outgoing signalling messages from NRF-egressgateway getting failed while using IPv6 address in SLFHost Configuration

When destination host address is configured as IPv6Address, outgoing signalling messages are failing on Egress Gateway. This is because NRF backend microservices is sending IPv6Address without square brackets.

This is applicable to NRF to SLF, NRF to NRF forwarding, NRF Growth and NFStatusNotify use-cases.

Before Fix: Host Address configured as IPv6 value signalling message will fail for the use-cases defined.

After Fix : Signalling messages will be delivered to IPv6 based host configured for the use-cases defined.

Doc Impact: There is no doc impact.

3 25.1.100

Release 25.1.202

Table 4-18 NRF 25.1.202 Resolved Bugs

Bug Number Title Description Severity Found In Release
38336947 Unable to configure SLF Options due to missing or null values for maxSlfAttemptsUpperLimit and maxSlfAttemptsLowerLimit While configuring the SLF Options, the NRF returned a failure. This occurred when the values for maxSlfAttemptsUpperLimit and maxSlfAttemptsLowerLimit were set to null.

Doc Impact: There is no doc impact.

1 24.2.4
38476808 NRF: NF Profile Update with Large SNSSAI is not generating Notifications for Remote Growth Set Subscriptions When an NFProfile update included a large number of SNSSAIs or other attributes, the NF Subscription microservice to Cache Data microservice query failed due to a header size error. As a result, the NF Subscription microservice reverted to a local database lookup and generated notifications only for local NRF set subscriptions. Consequently, notifications for remote NRF segment subscriptions were not generated for these profile update.

Doc Impact:

There is no doc impact.

2 25.1.201
38373486 NRF growth connectivity broke between set-1 and set-2 in performance setup

With larger payload sizes, NRF Ingress Gateway microservice sends backpressure signal to the upstream, which resulted in latency at Ingress Gateway microservice, even though the backend latency is below 100ms, which caused the original request to timeout and fail.

Increased the value of maxInMemorySize parameter to fix the issue.

Doc Impact: For more information, see "Configuring NRF" section in Oracle Communications Cloud Native Core, Network Repository Function Installation, Upgrade, and Fault Recovery Guide.

2 25.1.200
38415299 SLF based discovery requests failing with cause "Internal Server Error"

SLF retries were not handled correctly when error responses were received without a body, resulting in excessive SLF retry attempts. Specifically, upon receiving an SLF response with a 502 status code and no body, the system continued to retry without adhering to an upper limit across the configured hosts.

Doc Impact: There is no doc impact.

3 25.1.200
38432201 REST API nrf-state-data subscription-details response includes nfProfileDataCount instead of subscriptionDataCount

NRF state data API response contained an incorrect attribute name nfProfileDataCount instead of subscriptionDataCount for subscription-details response.

Doc Impact: There is no doc impact.

3 24.2.4
38444392 NRF is returning 200 OK response with empty nfInstances list when SLF and Forwarding are enabled and the discovery request gets forwarded.

When the SLF was not reachable from NRF and both SLF and forwarding features were enabled, NRF1 forwarded the request to NRF2. After forwarding, NRF2 returned a response to NRF1. Regardless of the status of NRF2’s response, NRF1 always returned a 200 OK response with an empty nfInstances list in the NFDiscover service operation response. As a result, NRF did not send NF profiles in the 200 OK response, regardless of the actual response status from the forwarded NRF.

Doc Impact: There is no doc impact.

3 25.1.200
38370654 ERR_UNKNOWN_HOST is mentioned twice in custom yaml under errorCodeProfiles

The ERR_UNKNOWN_HOST key was present twice in the errorCodeProfiles section of the NRF custom values YAML. This caused NRF to select the wrong value for ERR_UNKNOWN_HOST, resulting in incorrect responses and subsequent FT failures. The duplicate entry was removed from errorCodeProfiles, ensuring that NRF used only the correct entry for the ERR_UNKNOWN_HOST key.

Doc Impact: There is no doc impact.

3 25.1.201
38103938 log4j2_events_total metric is not getting pegged

The log4j2_events_total metric was not being updated in any of the NRF microservices except for NRF Configuration microservice.

Consequently, the metric appeared in Prometheus, but its value remained at zero. This led to reduced observability due to a misleading count of log events, showing zero log events even when log events were being emitted.

Doc Impact: There is no doc impact.

4 25.1.200
36570522 NRF performance - Intermittent failures observed in NFdiscovery operation with Error code 500

Intermittent failures were observed in the NFDiscovery operation, which impacted NRF performance.

Doc Impact: There is no doc impact.

3 24.1.0
38462967 NRF performs additional reroutes in forwarding and SLF scenarios

NRF performed additional reroutes in discovery forwarding and SLF scenarios when it received error responses without a body. When the NRF discovery service received such responses to forwarding requests, it did not handle them correctly, resulting in the reroute logic being triggered regardless of the maximumHopCount configuration. In these error scenarios—such as when the target NRF was unreachable or misconfigured and an error response without a body was received—excessive reroutes and failures occurred. This increased both latency and the number of failures, leading to higher outbound load and potential NF overload.

Doc Impact: There is no doc impact.

3 25.1.200
38102687 During IGW and Registration service connectivity break, NRF is going to L2 overload state causing 25% discovery traffic failure

In NRF 25.1.200, when connectivity between the Ingress Gateway microservice and Registration microservice was disrupted, NRF entered the L2 overload state, resulting in a 25% failure rate for discovery traffic. SLF retries were not calculated correctly when error responses were received without a body, leading to an excessive number of retries. Specifically, when a 502 error response without a body was received, retries continued across all configured SLF hosts without checking the upper limit. Once all hosts were exhausted, NRF returned a 500 error to the consumer NF.

Doc Impact: There is no doc impact.

3 25.1.200

Table 4-19 NRF ATS 25.1.202 Resolved Bugs

Bug Number Title Description Severity Found In Release
38191585 OSO pods running out of memory

During ATS runs, OSO pods encountered out-of-memory (OOM) errors. This was caused by a rapid increase in metrics cardinality, as new nfinstanceId values were continuously generated during each ATS run, leading to excessive memory consumption.

3 24.2.4
38350539 New feature 'SystemOptions52_HBTimerEnhancement_ErrornessInput.feature' is not being executed

The new feature SystemOptions52_HBTimerEnhancement_ErrornessInput.feature was not executed individually. The root cause was that the feature file tag did not match the name of the file, preventing the individual execution of this test case

3 25.1.200

Release 25.1.200

Table 4-20 NRF 25.1.200 Resolved Bugs

Bug Number Title Description Severity Found In Release
37839300 Secondary NRF(e1e2) sending 500 internal server errors towards SMSF when primary NRF w2 is taken OOR

When an NF switched from one NRF to another NRF, and if the NF Profile did not contain the fqdn attribute, the NRF processed the NF Profile successfully and saved it in the database. However, before generating the response, the NRF pegged the metric ocnrf_nf_switch_over_total, which indicated that the NF had switched over from one NRF to another. This metric had the dimension NfFqdn, which corresponded to the fqdn in the profile. Since the attribute was not present in the profile, the metric threw an exception and resulted in a Failure Response being generated.

Doc Impact: There is no doc impact.

1 24.2.3
37912207 Feature Discovery Parameter Value Based Skip SLF Lookup backward compatible

Discovery queries using attributes other than dnn were not supported in valueBasedSkipSlfLookupParams. When the value-based Skip SLF feature was enabled, using query attributes other than dnn led to backward compatibility issues.

Support was added to fall back to the older Skip SLF lookup mechanism when the value-based Skip SLF feature was enabled and the query attribute was not dnn.

Doc Impact: There is no doc impact.

2 25.1.100
37912978 SLFOptions configuration not working after upgrade

The SLFOptions configuration did not work after the upgrade. The issue was caused by the upgrade logic related to the SLFOptions configuration.

Doc Impact: There is no doc impact.

2 25.1.100
37788289 Discovery query results in Empty Profile when discovery query is forwarded due to AMF profile is Suspended and Empty response received from Forwarded NRF.

During NF profile processing, if a NF profile did not match the guami query parameter, NRF did not process the suspended profiles when the EmptyList feature was enabled for AMF.

Doc Impact: There is no doc impact.

3 24.2.4
37784967 discovery response contains Profile having load value(30) greater then DiscoveryResultLoadThreshold (20)

If the NFService load was not present, the NFProfile load was not used to perform validation for the DiscoveryResultLoadThreshold feature.

Doc Impact: There is no doc impact.

3 24.2.4
37704295 Discovery requests with preferred-locality return otherLocalityInd attribute as "false" despite non-matched localities.

Discovery requests from consumer NFs that included the preferred-locality parameter were returning the otherLocalityInd attribute as "false", even when there were non-matching localities among the returned NFProfiles.

The values of otherLocalityInd and preferredLocalityMatchInd were set based on both the preferred locations configured in the NRF and the locality attribute present in the discovery query.

The values of otherLocalityInd and preferredLocalityMatchInd were set based only on the locality attribute in the discovery query.

Doc Impact:

There is no doc impact.

3 23.4.5
37135700 Delay Nnrf Services - Small Load Condition

NRF did not send SETTINGS_MAX_CONCURRENT_STREAMS in the HTTP/2 settings frame. As a result, the client considered the maximum number of concurrent streams to be 1, which caused requests to be queued and eventually time out.

Consumers were not able to create concurrent streams to send traffic.

NRF sent the SETTINGS_MAX_CONCURRENT_STREAMS based on the Helm configuration serverDefaultSettingsMaxConcurrentStream, which was set to 1000 by default in version 25.1.200.

Doc Impact:

There is no doc impact.

3 23.4.0
36989541 The Number of concurrent HTTP2 streams is not limited

NRF did not send SETTINGS_MAX_CONCURRENT_STREAMS in the HTTP2 settings frame. Due to this, the client considered the concurrent stream as 1, which causes requests to be queued and times out.

Doc Impact:

This behavior is controlled by the ingressgateway.serverDefaultSettingsMaxConcurrentStream parameter.

For more information, see "Ingress Gateway Microservice Parameters" in Oracle Communications Cloud Native Core, Network Repository Function Installation, Upgrade, and Fault Recovery Guide.

3 23.4.0
37187942 Incorrect Discovery Response when EmptyList and Forwarding feature enabled together for feature

When the emptyList and forwarding features were enabled, and NRF had profiles matching the target-nf-type in the REGISTERED and SUSPENDED states—but with only the SUSPENDED profiles matching the discovery query—these profiles were not considered while sending the discovery response. Due to this issue, even when there were profiles matching the discovery query in the SUSPENDED state and the emptyList feature was enabled, NRF sent back an empty discovery response. This scenario needed to be handled to send the matching SUSPENDED profiles as part of the emptyList response.

Doc Impact:

There is no doc impact.

3 24.3.0
38026282 Response code from NRF is coming 400, instead of 500 when the backend services is down.

By default, NRF sent the incorrect error code 400 when the backend service was not available.

The error code value was changed to 500 for Unknown Host Exception cases in the deployment YAML. Please find the updated configuration below:

name: ERR_UNKNOWN_HOST

errorCode: 500

errorCause: "Unknown Host Exception at IGW"

errorTitle: "Unknown Host Exception"

errorDescription: "Unknown Host Exception"

Doc Impact:

There is no doc impact.

3 25..1.100
37760760 Incorrect ingress gateway port number was whitelisted in NRF network policy's allow-ingress-sbi section for https connections

An incorrect Ingress Gateway port number had been whitelisted in the NRF network policy's allow-ingress-sbi section for HTTPS connections.

As a result, the NRF network policies did not function as expected, since HTTPS requests to the Ingress Gateway were blocked due to the incorrect port configuration.

The NRF network policy custom values YAML was subsequently updated with the correct Ingress Gateway port number for HTTPS connections. The ports should have the values "8081" and "8443".

Doc Impact:

There is no doc impact.

3 24.2.3
35675295 NRF- Missing mandatory "iat claim" parameter validation is not happening in CCA header for feature - CCA Header Validation

NRF was not validating missing mandatory "iat claim" parameter in CCA header.

Doc Impact:

There is no doc impact.

3 23.2.0
37797310 NFRegistration logs some attributes are showing wrong data

The ThreadContext was not properly cleared after each request. In certain error scenarios, particularly when Input/Output errors occurred while reading the input message the controller method was never reached. As a result, values like nfInstanceID, requestUrl, and so on, were retained from previous requests due to context leakage.

Doc Impact:

There is no doc impact.

4 24.2.4
37417637 Disable/Hide CCA Header Validation Flag (which is not applicable for NRF use case) from NRF CNCC GUI

The "enabled" field under CCA Header screen in CNC Console GUI was editable (reason: the "readonly" flag for fields is configured to false by default). The "enabled" field flag is read-only now.

Doc Impact:

There is no doc impact.

4 24.2.2
36707560 NRF Rest API "ALL_NF_TYPE" coming back even after deleting in the Discovery Validity Period table

The NRF REST API "ALL_NF_TYPE" reappeared even after it was deleted from the Discovery Validity Period table.

On the CNC Console GUI, users observed that in EDIT mode, the SAVE operation was successful when DELETE was attempted to clear the list. However, after saving, the deleted row reappeared, resulting in no effective change.

Doc Impact:

There is no doc impact.

4 24.1.0
35672666 NRF- Incorrect "detail" value in CCA Header Response when missing mandatory "exp/aud claim" for feature - CCA Header Validation

NRF was sending an incorrect message in the detail attribute of the ProblemDetails field during CCA.

Doc Impact:

There is no doc impact.

4 23.2.0

Note:

Resolved bugs from 24.2.4 have been forward ported to Release 25.1.200.

Table 4-21 NRF ATS 25.1.200 Resolved Bugs

Bug Number Title Description Severity Found In Release
37826579 NRF ATS installation is failing on clusters which do not have ASM installed.

NRF ATS installation failed on clusters which do not have ASM installed. The VirtualService resource did not have a flag to enable or disable its creation with respect to the ASM deployment. In clusters where ASM was not installed, the VirtualService CRD was not present, caused the ATS installation to fail.

The istio-vs.yaml was placed under a flag to disable its creation in non-ASM deployments.

2 25.1.100

4.2.6 NSSF Resolved Bugs

Release 25.1.202

NSSF 25.1.202 is a Critical Patch Update. Critical Patch Updates provide security patches for supported Oracle on-premises products. They are available to customers with valid support contracts. For more information, see Critical Patch Updates, Security Alerts, and Bulletins.

There are no resolved bugs in this release.

Release 25.1.201

There are no new resolved bugs in this release.

Release 25.1.200

Table 4-22 NSSF 25.1.200 Resolved Bugs

Bug Number Title Description Severity Found in Release
38107817 NSSF 25.1.100 | NSSF Installation fails when readOnlyRootFilesystem is set to true

The NSSF 25.1.100 installation failed to complete on an OpenShift environment when the readOnlyRootFilesystem parameter was set to true in the YAML configuration. The nsauditor-pre-install pod encountered an error, and the logs revealed that the application was unable to start the web server due to a read-only file system. Specifically, the application was unable to create a temporary directory in /tmp.

Doc Impact:

There is no doc impact.

2 25.1.100
36889943 traffic moves from site2 to site1 , we are getting 404 error code for ns-availability scenarios

A 404 error code was encountered when traffic was moved from Site 2 to Site 1 in an ns-availability scenario within a 3 GR site deployment. Each site had 3.5 traffic, and the replication channel was functioning correctly. During the failover, traffic routing from Site 3 to Site 1 and Site 2 to Site 1 was initiated.

Doc Impact:

There is no doc impact.

3 24.2.0
37591102 OCNSSF:24.2.x:snmp MIB Complain from SNMP server

An issue was encountered with the OCNSSF 24.2.x version's SNMP MIB, where the SNMP server reported an error. The SNMP notifier was appending ".1" to the SNMP trap, causing a discrepancy.

Doc Impact:

There is no doc impact.

3 24.2.0
37387621 NSSF DELETE method support for AMF Resolutions

The user requested the addition of support for the DELETE method in AMF Resolutions. The user expected that if an AMF resolution entry can be created manually, it should also be possible to delete it using the same interface.

Doc Impact:

There is no doc impact.

3 24.1.0
37773632 [10.5K TPS] when we are deleting all cnDBTier pods, ns-selection 2 pods have stuck in a 1/2 state.

When deleting all cnDBTier pods in a performance setup, two ns-selection pods became stuck in a 1/2 state, causing the replication channel to break. This issue occurred in a 3 GR Site setup with 10.5K TPS traffic on Site 1.

Doc Impact:

There is no doc impact.

3 25.1.100
37802321 helm upgrade for NSSF was stucked as hook failed to remove entry for previous release from common config table

The helm upgrade process for NSSF was stuck due to a failure in the post-install hook to remove the entry from the common configuration table. This issue occurred during the upgrade of Site-2.

Doc Impact:

There is no doc impact.

3 25.1.100
37474162 NSSF 24.3.0 - ConfiguredNssai must be present If Requested NSSAI includes an S-NSSAI not valid

NSSF's behavior deviated from the TS 29.531 standard for NS Selection service when the "Enhanced Computation of AllowedNSSAI" feature was disabled. According to the user guide, the NSSF should comply with the standard in such cases.

Doc Impact:

There is no doc impact.

3 24.3.0
37681032 NSSF 24.2.1: Missing Edit Option for nsconfig Logging Levels in CNCC GUI

The "Edit" option for the nsconfig logging level was missing in the CNCC GUI of NSSF 24.2.1. Upon clicking the Logging Level Options, the REST API path /nssf/nf-common-component/v1/all/logging returned all services, including nsconfig. However, when attempting to edit, the API path /nnssf-configuration/v1/cncc/datamodel/conLoggingLevel did not include nsconfig in the list of services.

Doc Impact:

Updated the "Logging Level Options" section in Oracle Communications Cloud Native Core, Network Slice Selection Function User Guide.

3 24.2.1
37578617 OCNSSF[25.1.100: The behaviour of nnssf-nssaiavailability/v1/nssai-availability in case of update session data for unknown PLMNs not as per user guide

When updating session data for unknown PLMNs using the nnssf-nssaiavailability/v1/nssai-availability endpoint in OCNSSF 25.1.100, the response received was "NOTAUTHORIZED" instead of the expected "PLMNNOT_SUPPORTED" as per the user guide.

Doc Impact:

There is no doc impact.

3 25.1.100
36844482 Alternate-route cache is not deleting the SCP entry after TTL(Time to live)

The alternate-route cache in NSSF 24.2.0 failed to delete SCP entries after their Time to Live (TTL) expired. This issue was observed during health checks and subsequent deregister requests.

Doc Impact:

There is no doc impact.

3 24.2.0
36528105 3.5K TPS : 99.99% Failures seen when Rate-limiting feature is enabled in ASM setup

When the rate-limiting feature was enabled in an ASM setup with 3.5K TPS, the NSSF failed to handle 1 TPS requests, resulting in 99.99% failures.

Doc Impact:

There is no doc impact.

3 24.1.0
37776049 Dynamic log level updating Using CNCC for various micro services for NSSF. "LogDiscarding" Option is coming while fetching configured log level via REST but in CNCC while configured that option is not present

When updating log levels dynamically for various NSSF microservices using CNCC, the "LogDiscarding" option was present in the REST response but was not available in the CNCC configuration. This issue was observed specifically for the nssubscription and nsconfig microservices.

Doc Impact:

Updated section "Logging Level Options" in Oracle Communications Cloud Native Core, Network Slice Selection Function User Guide.

3 25.1.100
37136248 If dnsSrvEnabled is set to false and peer1 is used as a virtual host, the egress gateway will not sending the notification to peer2 host and peer health status is empty

When dnsSrvEnabled is set to false and peer1 is configured as a virtual host, the egress gateway failed to send notifications to peer2, resulting in an empty peer health status.

Doc Impact:

There is no doc impact.

3 24.2.1
37926363 NSSF Georedundancy - No Subscription sent to NRF after initial deployment

NSSF subscription failed to send to NRF post-deployment. Success required a pod restart. Logs revealed potential issues with allowedNfTypes and subscription handling.

Doc Impact:

There is no doc impact.

3 25.1.100
37895878 NSSF 25.1.100 - Critical Pods in CrashLoopBackOff State in 3 Site GRR Setup

User encountered pod issues in a 3-site GRR environment due to database removal confusion during NSSF 25.1.100 installation. Clarification was needed on the correct database removal procedure for partial site uninstallation.

Doc Impact:

There is no doc impact.

3 25.1.100
37303227 [NSSF 24.3.0] [EGW-Oauth feature] "Oc-Access-Token-Request-Info:" IE should not come in notification.

In NSSF 24.3.0, when the EGW-Oauth feature is enabled, the "Oc-Access-Token-Request-Info" header was incorrectly included in the notification sent to the AMF. This issue was observed during a scenario where AMF subscribed to TAC and slice additions/deletions triggered notifications.

Doc Impact:

There is no doc impact.

4 24.3.0
37590706 NSSF is sending wrong response code when received patch remove request and authorizedNssaiAvailabilityData is empty

When NSSF received a PATCH remove request with an empty authorizedNssaiAvailabilityData, it sent an incorrect response code of 500 Internal Server Error instead of the expected 400 Bad Request. This issue was observed during a test scenario involving availability PUT and PATCH operations.

Doc Impact:

There is no doc impact.

4 25.1.100
38043793 NSSF ocnssf-custom-values-25.1.100.yaml does not expose containerPortNames

The 25.1.100 NSSF custom values YAML lacked the containerPortName, causing issues with CNLB annotations. To prevent misconfigurations, the containerPortName should be added to the YAML, aiding customers in setting up Multus-based traffic segregation.

Doc Impact:

There is no doc impact.

4 25.1.100

4.2.7 OCCM Resolved Bugs

Release 25.1.202

OCCM 25.1.202 is a Critical Patch Update. Critical Patch Updates provide security patches for supported Oracle on-premises products. They are available to customers with valid support contracts. For more information, see Critical Patch Updates, Security Alerts, and Bulletins.

There are no resolved bugs in this release.

Release 25.1.201

There are no resolved bugs in this release.

Release 25.1.200

There are no resolved bugs in this release.

4.2.8 Policy Resolved Bugs

Release 26.1.201

Table 4-23 Policy 26.1.201 Resolved Bugs

Bug Number Title Description Severity Found In Release
39750847 UM policies not executed for unknown subscribers in OCCNP

PCRF skipped the usage monitoring processing for subscribers whose profile is missing from UDR. As a result, UM policies and configured unknownsubscriber handling are not executed for those subscribers.

Doc impact: There is no documentation impact.

2 25.1.200
39748403 Observing the critical alert - PolicyDsIngressErrorRateAbove10Percent

SM Policy sessions for Data Network Named (DNNs) excluded from Policy Data Service (PDS) communication can still be processed after PDS notifications for another session of the same subscriber. Stale PDS resources can then trigger repeated requests for nonexistent associations, increasing PDS errors and raising the PolicyDsIngressErrorRateAbove10Percent alert.

Doc impact: There is no documentation impact.

2 25.1.203
39702052 Rollover data is updated without Rollover-limit in UDR if UDR is brought down/Up

Usage monitoring failed to retain the rollover definition in UDR when UDR updates failed during a rollover operation. After session termination, later requests cannot recover the rollover limit or allocate quota from an otherwise valid rollover plan.

Doc impact: There is no documentation impact.

3 25.2.200
39125564 UE Service fails to handle non-JSON "no healthy upstream" response from Istio during Timer Service downtime

UE Service failed to handle a non-JSON no healthy upstream response from Istio during timer service downtime. This can break N1N2 transfer retry after handling when the dependency outage returns a plain-text upstream error.

Doc impact: There is no documentation impact.

3 25.1.200
39155184 [Generic_Policy]: SAL logs for Nas messages needs to be improvised to have properly decoded details

Subscriber Activity Log (SAL) logs for NAS messages do not provide properly decoded details. This can make troubleshooting NAS message handling harder because the logged information is not sufficiently readable or complete.

Doc impact: There is no documentation impact.

3 25.1.200
39723617 After Policy rollback from 26.1.200 to 25.1.203(leap frog), diam-gateway went in crashloopback

During rollback from 26.1.200 to 25.1.203, diameter gateway pods entered CrashLoopBackOff because mixed version coherence members use incompatible PartitionedCache quorum policies. This can leave a diameter gateway pod unavailable during the rollback.

Doc impact: There is no documentation impact.

2 26.1.200
38741484 Observed that Grafana import is not working on CNE 25.2.100 version

Policy observability dashboard imports failed on CNE 25.2.100 because the dashboard cannot resolve the required data sources. This prevents the supplied Grafana dashboard from loading correctly in the supported environment.

Doc impact: There is no documentation impact.

2 25.1.201
38503445 [AM_UE_Perf]- Execution of ~80K Traffic having Stale Request Cleanup for UE Enabled throwing Error "java.lang.NullPointerException"

AM and UE performance traffic with stale-request cleanup enabled triggered a NullPointerException under high load. This can interrupt affected performance executions and produce errors during request cleanup.

Doc impact: There is no documentation impact.

3 25.2.100
38315824 [SM-PERFORMANCE] GRR with 10M db in SM failed with VALIDATERESOURCES "total required disk space for GRR is configured less"

SM GRR execution with a 10-million record database failed the resource validation because the configured disk space requirement is insufficient. This blocked the GRR execution for the expected database scale.

Doc impact: There is no documentation impact.

3 25.1.200
38203873 [AM-UE Performance] - Execution of 54k TPS, UE service have intermittent Error "Error in PDS request:404 Not Found"

UE service intermittently received PDS 404 Not Found errors during 54K TPS AM and UE performance execution. This caused failures in affected requests under sustained load.

Doc impact: There is no documentation impact.

3 24.2.7
38110128 Problem Statement: STALE_DIAMETER_CONNECTOR_REQUEST_CLEANUP alert expressions are wrong in AlertRules file

STALE_DIAMETER_CONNECTOR_REQUEST_CLEANUP alert expressions used incorrect metric-label matching. This prevents the alert calculation from retrieving the intended data for diameter connector request cleanup failures.

Doc impact: There is no documentation impact.

3 25.1.200
39526979 PA Create accepts a QoSMon subscription attempt when evSubsc.events is missing/empty, instead of rejecting it.

PCF PA create accepted a request whose evSubsc.events field is missing or empty even though the field is mandatory. The malformed request can create an application session and trigger SMF UpdateNotify processing instead of being rejected.

Doc impact: There is no documentation impact.

3 26.1.200
39171986 : "Observing "Emergency session establishment" failure as the evaluated message priority is lower during SM congestion."

Emergency session establishment failled during SM congestion because the evaluated message priority is lower than expected. This can prevent emergency traffic from receiving the intended priority handling under congestion conditions.

Doc impact: There is no documentation impact.

3 24.2.0
39206384 Audit notify fails at SM serivce with 500 INTERNAL_SERVER_ERROR because "sessionType" is null

SM service audit notification failed with a 500 INTERNAL_SERVER_ERROR when sessionType is null. This can prevent audit notify processing for sessions missing that field.

Doc impact: There is no documentation impact.

2 25.2.100
39271829 [Generic]: Unable to delete user data for pcrf-core service from session viewer

Session viewer failed to delete data for the pcrf-core service. You can be unable to remove PCRF Core session data through the expected UI workflow.

Doc impact: There is no documentation impact.

3 25.1.200
39580205 Session Management PUT/GET returns only partial payload instead of complete configuration

Session Management PUT and GET operations returned only a partial payload instead of the complete configuration. This can cause you or clients to see incomplete session-management configuration data.

Doc impact: There is no documentation impact.

3 24.2.0
38589051 Observing continuous flood of NPE in SM service while running PA-CREATE/UPDATE flows with SDC (Sponsored Data Connectivity Supports) for Failed to notify AF"errorStack": io.micrometer.core.instrument.ImmutableTag

SM service can continuously log NullPointerException errors while running PA-CREATE or PA-UPDATE flows with sponsored data connectivity enabled. The failure occurs during AF notification metric handling and can flood logs while the signaling flow is active.

Doc impact: There is no documentation impact.

2 25.2.200
38590212 Observing OCPM_PRE Pod is consuming more than 90% memory usage

OCPM_PRE pods consumed more than 90% memory in one of the environment. This high memory usage can affect pod stability and operational headroom during policy service execution.

Doc impact: There is no documentation impact.

2 24.2.7
38729096 Observing OCPM_PRE Pod is consuming more than 90% memory usage

OCPM_PRE pods showed excessive memory consumption above 90% in one of the environment. This can create resource pressure and reduce service stability during runtime.

Doc impact: There is no documentation impact.

2 24.2.7
38751374 Upgrading PCF from 25.1.200 to 25.1.201 "duplicate port definition with spec.template.spec.containers"

PCF upgrade from 25.1.200 to 25.1.201 failed because of a duplicate port definition in the pod container specification. This can block the upgrade flow for AM-UE performance environments.

Doc impact: There is no documentation impact.

2 25.1.201
38758473 Policy table rows silently missing when tested with 20 large tables

Policy table processing missed rows when tested with multiple large policy tables. This can cause policy data to appear incomplete without a clear error indication.

Doc impact: There is no documentation impact.

2 25.2.200
38789247 When one of pod of pcrf-core is in congestion state and overload condition hit we are seeing WARN "Exception occurred while applying overload control for backend BACKEND_PCRF_CORE" in diam-gateway

Diameter gateway logged warnings while applying overload control when a pcrf-core pod is congested and overload conditions are reached. This can make overload handling for the BACKEND_PCRF_CORE backend appear to fail or behave inconsistently.

Doc impact: There is no documentation impact.

2 25.2.200
38813332 SM pod is rejecting valid npcf-policyauth delete request and sending 415 Unsupported media type when content-length:0 and content-type header is not present

SM service rejected a valid npcf-policyauth DELETE request with 415 Unsupported Media Type when the request has content-length 0 and no content-type header. This can incorrectly fail valid delete requests.

Doc impact: There is no documentation impact.

2 25.2.200
38839988 For the UE service the congestion L1/L2/L3 thresholds are configured without any gap, which causes very rapid level fluctuations.

UE service congestion thresholds for L1, L2, and L3 can be configured without sufficient separation. This can cause rapid congestion-level fluctuations and unstable congestion behavior.

Doc impact: There is no documentation impact.

2 25.2.200
38860927 500 "INTERNAL_SERVER_ERROR" logs in SM service generated by BulwarkServiceConnector

SM service generated a 500 INTERNAL_SERVER_ERROR logs from BulwarkServiceConnector. This can add error noise and indicate failed backend connector handling during affected flows.

Doc impact: There is no documentation impact.

2 25.2.200
38870898 GUI hangs when saving SNSSAI message attribute after fresh installation

CNC Console did not respond when saving an Single Network Slice Selection Assistance Information (SNSSSAI) message attribute after a fresh installation. This can prevent you from completing the expected configuration save workflow.

Doc impact: There is no documentation impact.

2 25.2.200
38870925 PCF respond with empty problem details body to AMF while PDS pod is unreachable and also kept stale UE policy session in DB while responding 500 to AMF

PCF returned a 500 response with an empty problem details body to AMF when the PDS pod is unreachable. The same flow can leave a stale UE policy session in the database.

Doc impact: There is no documentation impact.

2 25.2.200
38885156 PCF using expired token

PCF continued using an expired token in affected call flows. This can cause authentication or authorization failures when communicating with dependent services.

Doc impact: There is no documentation impact.

2 25.1.200-1
38899915 PCF not sending umDecs on receiving PA subscribe with event USAGE_REPORT and usgThres while send policyCtrlReqTriggers US_RE

PCF exculded umDecs when receiving a PA subscribe request with the USAGE_REPORT event and usage threshold while sending the US_RE policy control request trigger. This can result in incomplete policy authorization subscription handling.

Doc impact: There is no documentation impact.

2 25.2.200
38918089 After successful Gx and Sd session termination, PCRF not sending Sy session termination causing stale session for pdssubscriber & pdsprofile in PCF and eventually on OCS as well.

PCRF failed to send Sy session termination after successful Gx and Sd session termination. This can leave stale pdssubscriber and pdsprofile sessions in PCF and eventually stale session state on OCS.

Doc impact: There is no documentation impact.

2 25.2.200
38922466 Missing Mandate checks in RCManager in SM resulting NPE in GR Regression Test: triggerClass":"[ocpm.pcf.service.pa](http://ocpm.pcf.service.pa).domain.component.AfAdaptor","errorName":"java.lang.NullPointerException"

SM service can encounter a NullPointerException in PA processing because required RCManager mandate checks are missing. This can affect GR regression flows involving AfAdaptor processing.

Doc impact: There is no documentation impact.

2 25.2.200
38922472 PCF not sending reportingLevel=RAT_GR_LEVEL  towards SMF for PA-UPDATE when sponStatus made AS SPONSOR_DISABLED

PCF exculded reportingLevel=RAT_GR_LEVEL toward SMF during PA-UPDATE when sponsored status is set to SPONSOR_DISABLED. This can result in incomplete update notification data for the SMF.

Doc impact: There is no documentation impact.

2 25.2.200
38922499 PA update request getting rejected even if in case NEF/AF need to update other parameter than sponsored data when ACCEPT_REQUEST_WHEN_MISSING_SPONSORED_CONNECTIVITY_DATA set to true

PA update requests rejected even when NEF or AF update parameters other than sponsored data and ACCEPT_REQUEST_WHEN_MISSING_SPONSORED_CONNECTIVITY_DATA is enabled. This can incorrectly block valid Policy Authorization updates.

Doc impact: There is no documentation impact.

2 25.2.200
38992796 UDR subscription delete request in Model-D communication mode getting failed in UDR-conn due to http port:null in uri

UDR subscription delete requests in Model-D communication mode can fail in UDR-Connector because the generated URI contains http port:null. This can prevent subscription cleanup in the affected communication mode.

Doc impact: There is no documentation impact.

2 25.2.200
39035473 [GR_Testing]: SM service log is continuously printing "Exception occurred calling Bulwark Unlock" ERROR logs after upgrading to 25.2.200 build - patch 26.1.200

After upgrade, SM service continuously printed ERROR logs indicating an exception while calling Bulwark Unlock. This can create persistent error noise and indicate failed unlock handling in affected flows.

Doc impact: There is no documentation impact.

2 25.2.200
39069811 Label error_reason for metrics occnp_oc_ingressgateway_http_responses_total resulting in high Cardinality

The error_reason label for the occnp_oc_ingressgateway_http_responses_total metric created high cardinality. This can increase observability storage and query load for ingress gateway response metrics.

Doc impact: There is no documentation impact.

2 25.2.200
39071135 update notify sent towards SMF for PA subscribe is disabling sponstatus by PCF

PCF disabled sponsored status in the update notification sent toward SMF for a PA subscribe flow. This can send incorrect sponsored-connectivity state to SMF.

Doc impact: There is no documentation impact.

2 25.2.200
39082018 Egress traffic increased for SMF notify after the upgrade from 25.1.201 to 25.2.200

SMF notify egress traffic increased after upgrade from 25.1.201 to 25.2.200. This can result in higher-than-expected outbound signaling volume for notification flows.

Doc impact: There is no documentation impact.

2 25.2.200
39082720 testbed-PCF&UDR: Incorrect Next Reset Time and Grant for user with Billing Day 31

PCF and UDR calculated an incorrect next reset time and grant for you with billing day 31. This can produce incorrect quota or billing-cycle behavior for those subscribers.

Doc impact: There is no documentation impact.

2 24.2.8
39095272 PCRF core with subs-to-notify false, PDS response is getting timed out causing Gx session create failure

PCRF core  timed out waiting for a PDS response when subs-to-notify is false. This can cause Gx session creation to fail in the affected flow.

Doc impact: There is no documentation impact.

2 25.2.200
39108818 Exception while PATCH SmPolicyData at UDR Connector with 500 INTERNAL_SERVER_ERROR and thrown NullPointerException

UDR Connector can throw a NullPointerException while handling PATCH SmPolicyData and return 500 INTERNAL_SERVER_ERROR. This can cause policy data patch requests to fail.

Doc impact: There is no documentation impact.

2 25.2.200
39109082 PCF 25.1.202 Binding Service fails to look up BSF Profile with IP Ranges other than /64

PCF Binding Service failled to look up a BSF profile when the BSF IPv6 range uses a prefix other than /64. This can prevent BSF selection for NEF use cases that register broader IPv6 ranges such as /32.

Doc impact: There is no documentation impact.

2 25.1.202
39112907 Congestion control for diam-connector is getting triggered at 55K TPS (SM call model) with default thresholds

Diameter connector congestion control can trigger at 55K TPS with default thresholds in the SM call model. This can cause congestion discards earlier than expected under load. 

Doc impact: There is no documentation impact.

2 25.2.200
39205123 To reduce cardinality, egressLatencyBuckets configuration needs to be fine tuned for ocpm_egress_response_total

The ocpm_egress_response_total metric had excessive cardinality because egressLatencyBuckets are configured too broadly across policy services. This can increase memory usage and observability overhead.

Doc impact: There is no documentation impact.

2 23.4.6
39213189 NRF Cache Auditor Not Purging Entries as per Configured Percentage

NRF cache auditor failed to purge cached discovery entries according to the configured purge percentage after the scheduler interval elapsed. Stale or excess cache entries can continue to be served instead of triggering fresh network discovery.

Doc impact: There is no documentation impact.

2 25.2.200
39224565 Config-server restarts during DBTIER ndbappmysqld pods scaled down

Config server pods can enter restart or CrashLoopBackOff behavior when DBTIER ndbappmysqld pods are scaled down. This can reduce service stability during DB tier unavailability or recovery.

Doc impact: There is no documentation impact.

2 25.2.200
39354716 SM Service fails to route to alternate SMF after 429 response from primary SMF

SM Service can fail to route traffic to an alternate SMF after receiving a 429 response from the primary SMF. This can prevent expected alternate routing during primary SMF throttling or overload.

Doc impact: There is no documentation impact.

2 25.2.200
37740602 ES3XX feature is mentioned as Not supported under 4.2.4.3 Request for termination of the policy association section, but ES3XX feature is not included under Not supported category under 4.2.4.2 section in PCF Compliance Matrix

The PCF Compliance Matrix lists ES3XX support inconsistently across related sections. You can see ES3XX marked unsupported in one section while it is missing from the unsupported category in another section.

Doc impact: There is no documentation impact.

3 25.1.100
37897111 The tier condition block is not available under PCRF-CORE service blockly

The tier condition block is not available under the PCRF-Core service blockly interface. You can be unable to configure tier-based PCRF-Core logic through the expected visual block.

Doc impact: There is no documentation impact.

3 25.2.200
37983361 Multiple issues on Table 2-372 of REST API guide.

Table 2-372 in the REST API guide contains multiple documentation issues. You can receive unclear or inaccurate REST API reference information from that table.

Doc impact: Updated the Binding Service section in Oracle Communications Cloud Native Core, Converged Policy REST Specification Guide.

3 25.1.200
38316856 policy_installation_guide_25.1.200 Note in section 5.11.d not clear

A note in section 5.11.d of the Policy Installation Guide is unclear. You can misinterpret the documented installation guidance for that section.

Doc impact: Updated the Preupgrade Tasks section in Oracle Communications Cloud Native Core, Converged Policy Installation, Upgrade, and Fault Recovery Guide.

3 25.1.200
38508960 CNC policy installation & Upgrade document Discrepancy 25.1.200

The CNC Policy installation and upgrade documentation contains inconsistent guidance for 25.1.200. You can follow conflicting information during installation or upgrade activities.

Doc impact: Updated the Preupgrade Tasks section in Oracle Communications Cloud Native Core, Converged Policy Installation, Upgrade, and Fault Recovery Guide.

3 25.1.200
38645027 Importing 23.x Profiles into 25.x

Profile import guidance or behavior for importing 23.x profiles into 25.x is incomplete or unclear. You can encounter issues when migrating older profiles into a newer release.

Doc impact: There is no documentation impact.

3 25.1.200
38689474 Uploaded Single UE ID MOP to update Rollback section

The Single UE ID MOP rollback section required correction. You can receive incomplete or unclear rollback guidance for the Single UE ID procedure.

Doc impact: There is no documentation impact.

3 25.1.200
38695883 FD is missing important information related to enhance warn logging on diameter interface

The feature document is missing important information about enhanced warning logging on the Diameter interface. You can lack required context for understanding or configuring Diameter warning logs.

Doc impact: There is no documentation impact.

3 25.2.200
38721106 SD CCR-T without session id should failed with error 5005 DIAMETER_MISSING_AVP and causing NPE error

An SD CCR-T request without a session ID can trigger a NullPointerException instead of failing cleanly with DIAMETER_MISSING_AVP error 5005. This can produce incorrect Diameter error handling for malformed requests.

Doc impact: There is no documentation impact.

3 25.2.200
38735637 Wrong accept=[application/json] header sent to CHF in subscription delete request by PCF will cause issue with real CHF

PCF sent an incorrect accept=[application/json] header to CHF in subscription delete requests. This can cause interoperability issues with a real CHF implementation.

Doc impact: There is no documentation impact.

3 25.2.200
38738240 CPU utilization of UE service has increased by ~40% after in-service upgrade to 25.2.200 from 25.2.100

UE service CPU utilization can increase by approximately 40% after an in-service upgrade from 25.2.100 to 25.2.200. This can reduce performance headroom for UE service after upgrade.

Doc impact: There is no documentation impact.

3 25.2.200
38761727 In case 3gpp-Sbi-Sender-Timestamp received in incorrect format SM service not able to create PDS set request and call fail

SM service failed to create a PDS set request when the 3gpp-Sbi-Sender-Timestamp header is received in an incorrect format. This can cause the affected call flow to fail.

Doc impact: There is no documentation impact.

3 25.2.200
38776742 Subscription-Id-Type is END_USER_SIP_URI , enhance warn log does not show subscription id details for diam error code 5009

Enhanced warning logs for Diameter error code 5009 do not show subscription ID details when Subscription-Id-Type is END_USER_SIP_URI. This can make troubleshooting subscription-related Diameter errors harder.

Doc impact: There is no documentation impact.

3 25.2.200
38779098 UDR connector not adding 3gpp-sbi-correlation-info while sending discovery request to nrf-client-nfdiscovery

UDR connector excluded 3gpp-sbi-correlation-info when sending discovery requests to nrf-client-nfdiscovery. This can reduce correlation visibility for NRF discovery traffic.

Doc impact: There is no documentation impact.

3 25.2.200
38779120 SPAD_PERF[AM-UE-Perf]- Executing ~54K TPS for long run leads to frequent ERROR in bulwark svc "java.lang.RuntimeException"

Long-running AM-UE performance traffic at around 54K TPS can cause frequent RuntimeException errors in the Bulwark service. This can add persistent error logging during high-throughput performance runs.

Doc impact: There is no documentation impact.

3 25.2.200
38783864 WARN logs for Binding Audit: Revalidation successfully changed across 25.2.100 vs 25.2.200

Binding Audit revalidation warning logs differed unexpectedly between 25.2.100 and 25.2.200. This can make audit revalidation behavior appear inconsistent across releases.

Doc impact: There is no documentation impact.

3 25.2.200
38787767 Diam-conn: NullPointerException (key is null) causes 5012 rejection of PcfSdEvent during Performance

Diameter connector  throwed a NullPointerException when a key is null, causing PcfSdEvent rejection with error 5012 during performance testing. This can interrupt affected Diameter event handling.

Doc impact: There is no documentation impact.

3 25.2.200
38788906 Subscriber Activity logs for UDR GET/POST/DELETE request missing apiroot in uri field

Subscriber Activity logs for UDR GET, POST, and DELETE requests can omit the apiRoot value in the URI field. This can make request tracing and troubleshooting incomplete.

Doc impact: There is no documentation impact.

3 25.2.200
38796704 For PDS session audit query sent for Gx session to PCRF-core, PCRF core return 404 for Gx session while session was active in DB

PCRF-Core returned a 404 for a PDS session audit query for a Gx session even though the session is active in the database. This can cause audit results to incorrectly indicate that an active session is missing.

Doc impact: There is no documentation impact.

3 25.2.200
38817020 [GR_Testing]:Policyds_Overall_Processing_time_Seconds is reaching nearly 3 seconds during audit notification handling thus causing "Unexpected error occurred: Scheduler unavailable errors at PDS

PolicyDS overall processing time approached three seconds during audit notification handling, causing scheduler-unavailable errors at PDS. This can delay or disrupt audit notification processing.

Doc impact: There is no documentation impact.

3 25.2.200
38817267 Abnormal restarts have been observed on ocpcf-oc-diam-gateway-5 pod on site-2 with during ndbmtd pod restart scenario lead to traffic loss

The ocpcf-oc-diam-gateway pod restarted abnormally during an ndbmtd pod restart scenario on site 2. This can lead to traffic loss during the affected DB pod restart condition.

Doc impact: There is no documentation impact.

3 25.2.200
38827482 NPE seen in sm-service after upgrade with error message Cannot invoke "java.util.Map.get(Object)" because the return value of "[ocpm.pcf.service.sm](http://ocpm.pcf.service.sm).domain.model.SmPolicyAssociation.getQosDatas()" is null","

SM service can throw a NullPointerException after upgrade when SmPolicyAssociation QoS data is null. This can interrupt affected SM policy processing after upgrade.

Doc impact: There is no documentation impact.

3 25.2.200
38828870 PCF doesn't send RAR with FRA to AF even though the RxReauth action SEND_RAR is getting applied

PCF failed to send an RAR with FRA to AF even when the RxReauth action SEND_RAR is applied. This can prevent the expected reauthorization request from reaching AF.

Doc impact: There is no documentation impact.

3 25.2.200
38846947 [GR_Testing]: Observing audit pod is restarting with OOM in longevity run at approximately 3 days 6 hours intervals

The audit pod restarted with an out-of-memory condition during longevity runs at roughly three-day intervals. This can affect long-running audit service stability.

Doc impact: There is no documentation impact.

3 25.2.200
38872036 Change in dimensions of ocpm_ingress_request_total metric causing UE service congestion validation failure

A change in ocpm_ingress_request_total metric dimensions can cause UE service congestion validation to fail. This can make congestion validation unreliable when using the affected metric.

Doc impact: There is no documentation impact.

3 25.2.200
38883699 Audit cleanup/delete metrics are not getting updated on binding service while session got removed due to audit

Binding service audit cleanup and delete metrics can fail to update when a session is removed by audit processing. This can leave monitoring data inconsistent with actual session cleanup activity.

Doc impact: There is no documentation impact.

3 25.2.200
38883715 Audit service pod is throwing "Error saving TimerPodStateEntities" Error after upgrading to 25.2.200.

Audit service pods can log errors while saving TimerPodStateEntities after upgrade to 25.2.200. This can indicate failed timer pod state persistence after upgrade.

Doc impact: There is no documentation impact.

3 25.2.200
38885830 OpenSpec API Compile Time Warnings

OpenSpec API generation can produce compile-time warnings. This can indicate inconsistencies in the API specification that affect generated API artifacts.

Doc impact: There is no documentation impact.

3 25.2.200
38898205 Few HTTP error codes eg. 415 and 406 are not reaching controllers

Certain HTTP error codes, including 415 and 406, can fail to reach the application controllers. This can prevent controller-level handling for those error conditions.

Doc impact: There is no documentation impact.

3 25.2.200
38901026 GUI PCRF-CORE Advanced Setting: DIAMETER.AF.SessionBindingAltKeys

The GUI advanced setting for DIAMETER.AF.SessionBindingAltKeys under PCRF-Core is not documented or exposed clearly. You can miss or misconfigure the session binding alternate key setting.

Doc impact: There is no documentation impact.

3 25.2.100
38903093 Update overload threshold values for AM, UE, SM, PCRF-Core, Diam-Connector

Overload threshold values for AM, UE, SM, PCRF-Core, and Diameter Connector are not aligned with the expected configuration. This can cause overload behavior to trigger at unintended levels.

Doc impact: There is no documentation impact.

3 25.2.200
38941633 Diam-GW assigns default message priority even when no priority profile is attached, preventing validation of "IfNotPresent" Request Priority Override

Diameter Gateway assigned a default message priority even when no priority profile is attached. This can prevent correct validation of the IfNotPresent request-priority override behavior.

Doc impact: There is no documentation impact.

3 25.2.200
38973595 PCF 25.2.100 : Table 7-47 ("SM Policy Association Section of Audit Group") incorrectly lists the TDF parameters

Table 7-47 in the PCF guide incorrectly lists TDF parameters in the SM Policy Association section of the Audit Group. You can receive incorrect parameter guidance from the documentation.

Doc impact: Updated the PCF Session Management section in Oracle Communications Cloud Native Core, Converged PolicyUser Guide.

3 25.2.100
39063863 [Generic_Policy]: occnp_oc_ingressgateway_incoming_connections metric details are missing in user guide

The User Guide does not include details for the occnp_oc_ingressgateway_incoming_connections metric. You can lack the information needed to monitor incoming ingress gateway connections.

Doc impact: Updated the Ingress Gateway Metrics section in Oracle Communications Cloud Native Core, Converged Policy Installation, Upgrade, and Fault Recovery Guide.

3 25.2.100
39064093 [Generic_Policy]: Handling_DB_Cluster_Disconnect feature documentation is missing in user guide

The User Guide does not include documentation for the Handling_DB_Cluster_Disconnect feature. You can be unaware of the feature behavior or required operational guidance.

 Doc impact: Updated the PCF Session Management section in Oracle Communications Cloud Native Core, Converged PolicyUser Guide.

3 25.2.100
39083388 Npcf_AMPolicyControl_TerminateNotify Resource URI details incorrect in User Guide

The User Guide contains incorrect resource URI details for Npcf_AMPolicyControl_TerminateNotify. You can use the wrong URI when implementing or validating terminate-notify behavior.

Doc impact: Updated the Policy Services section in Oracle Communications Cloud Native Core, Converged Policy User Guide.

3 25.2.200
39084971 [CNCESPOL-7335]  [GR_Testing]: NPE observed in cm-service with error "Cannot invoke "Object.toString()" because the return value of "java.util.LinkedHashMap.get(Object)" is null"

CM service can throw a NullPointerException when a LinkedHashMap lookup returns null and the service attempts to call toString on it. This can cause errors during the affected generic policy flow.

Doc impact: There is no documentation impact.

3 25.2.200
39187168 InfoDev :: Update - Policy User Guide : SAL limitation for subscription expiry audit notification

The Policy User Guide does not clearly describe the SAL limitation for subscription-expiry audit notifications. You can miss the documented limitation when planning or troubleshooting audit notification behavior.

Doc impact: Updated the Expiry Handling for Policy Data Subscriptions section in Oracle Communications Cloud Native Core, Converged Policy User Guide.

3 25.2.200
39238447 [SM_OCE_Phase2_Assume_Positive]: CM UI/SUT Allows Import of Higher Version (n+1) configuration into Lower Version (n) without Validation

CM UI/SUT can allow a higher-version configuration to be imported into a lower-version system without validation. This can permit unsupported configuration downgrade scenarios.

Doc impact: There is no documentation impact.

3 25.2.201
39280735 Advanced key for TDF enabling is wrong TDF.TDF_ENALBLED in SM Service configuration in User Guide at multiple places

The User Guide lists the SM Service TDF enablement advanced key incorrectly as TDF.TDF_ENALBLED in multiple places. You can configure the wrong key when enabling TDF behavior.

Doc impact: There is no documentation impact.

3 25.2.201
39440075 Duplicate policyds.mySql.connection block in 25.2.201 custom values overrides dynamic DB pool sizing

A duplicate policyds.mySql.connection block in 25.2.201 custom values can override dynamic database pool sizing. This can cause PolicyDS to use unintended DB connection settings.

Doc impact: There is no documentation impact.

3 25.2.201
39573249 While Doing DB Inservice Upgrade when DB pods are initializing PDS is throwing NPE :Cannot invoke "ocpm.uds.policyds.db.entity.PdsTableWrapper.setLstPdsSubs(java.util.List)"

PDS can throw a NullPointerException during DB in-service upgrade while DB pods are initializing. This can affect policy data service behavior during the database upgrade window.

Doc impact: There is no documentation impact.

3 25.2.201
35776567 PCF should add npcf-policyauthorization service on default custom yaml section appProfiles.

The default custom YAML appProfiles section can omit the npcf-policyauthorization service. This can require manual configuration before policy authorization service profiles are available.

Doc impact: There is no documentation impact.

3 23.2.0
37324111 ERRORS & Exceptions  observed in PDS Logs during UsageMon Performance Runs

PDS logs can contain errors and exceptions during UsageMon performance runs. This can indicate unstable behavior or noisy error logging under performance traffic.

Doc impact: There is no documentation impact.

3 24.2.3
38291688 PCF is not rejecting the Policy association request with valid error cause for invalid/incorrect conditional attributes

PCF can reject policy association requests with invalid or incorrect conditional attributes without returning the expected valid error cause. This can make request failures unclear to clients.

Doc impact: There is no documentation impact.

3 25.1.200
38305437 N CNE - Helm Warnings observed when installing/uninstalling and upgrading Policy on N CNE cluster

Helm warnings can appear during Policy installation, uninstallation, or upgrade on an N CNE cluster. This can make lifecycle operations look problematic even when they should proceed normally.

Doc impact: There is no documentation impact.

3 25.2.100
38418947 UE service is registering with Audit service where Audit is disabled by default on Fresh installation 25.2.100 when slicing enabled

UE service can register with Audit service on a fresh installation even though Audit is disabled by default when slicing is enabled. This can create unintended audit-service registration behavior.

Doc impact: There is no documentation impact.

3 25.2.100
38617440 [Rx_Enhancement_AVP_Phase2]: Metric occnp_ocnf_service_cookie_total (direction="out") only pegged when AAR-U received with ocnfservicecookie header

The occnp_ocnf_service_cookie_total metric with direction=out can be pegged only when AAR-U includes the ocnfservicecookie header. This can make service-cookie metric reporting incomplete for other affected flows.

Doc impact: There is no documentation impact.

3 25.2.200
38648280 : bulkexport & export report are incorrect when one of the policy project is missing with dependancy

Bulk export and export reports can be incorrect when a dependent policy project is missing. This can give you inaccurate export results for incomplete project dependencies.

Doc impact: There is no documentation impact.

3 25.2.200
38691549 POLICY_READ Role enabled but user is also able to edit the parameters

You can still edit parameters with the POLICY_READ role. This can allow changes from a role that should have read-only access.

Doc impact: There is no documentation impact.

3 24.2.3
38696528 PRE: Release variables that hold references and optimize the creation of policyTableMap, ensuring it does not retain unnecessary references

PRE can retain unnecessary references while creating policyTableMap. This can contribute to excessive memory retention during policy table processing.

Doc impact: There is no documentation impact.

3 24.2.7
38714868 From CNCESPOL-6097 High Memory Alerts for PRE

PRE can generate high-memory alerts under affected conditions. This can indicate elevated memory usage and reduced resource headroom.

Doc impact: There is no documentation impact.

3 25.1.201
38747169 Unable to edit/download Yaml Schema to modify Blockly for DNNReplacement feature

Unable to edit or download the YAML schema needed to modify Blockly for the DNNReplacement feature. This can block configuration changes for that feature.

Doc impact: There is no documentation impact.

3 25.2.200
38823032 PCF is rejecting SM Policy Request with 500 Internal Server Error when a mandatory IE SUPI is missing in the request

PCF returned 500 Internal Server Error when an SM Policy request is missing the mandatory SUPI information element. This can produce an incorrect server error instead of a clear client-side validation response.

Doc impact: There is no documentation impact.

3 25.2.200
38823361 PCF is not sending UpdateNotify to SMF to remove the pcc rule installed during AAR-I

PCF failed to send UpdateNotify to SMF to remove a PCC rule installed during AAR-I. This can leave policy rules active when they should have been removed.

Doc impact: There is no documentation impact.

3 25.2.200
38898259 occnp_pod_congestion_state metric is not getting generated for PCRF Service

The occnp_pod_congestion_state metric failed to generate for PCRF Service. This can prevent expected congestion-state monitoring for PCRF.

Doc impact: There is no documentation impact.

3 25.2.200
38909860 There are no warning or error-level logs in DGW that indicate the cause of load level changes—for example, whether they’re due to CPU usage or pending_request_count

Diameter Gateway can change load levels without warning or error logs explaining whether the cause is CPU usage or pending request count. This can make load-level changes difficult to diagnose.

Doc impact: There is no documentation impact.

3 24.2.9
38935609 [Soltest-25-C] [Diam-Cli]: Diamcli fails to send the RAA success response to PCF when sending 3gpp-User-Location-Info AVP from PCF (diam-connector)

Diamcli failed to send the RAA success response to PCF when PCF sends the 3gpp-User-Location-Info AVP through Diameter Connector. This can disrupt Rx reauthorization response handling.

Doc impact: There is no documentation impact.

3 25.2.100
38936767 For Cause "NOT_ACCEPTABLE" response Body doesn't contain the cause for the failure & error state code.

Responses with cause NOT_ACCEPTABLE can omit the failure cause and error state code from the response body. This can leave clients without the expected problem details.

Doc impact: There is no documentation impact.

3 25.2.200
38943008 25.2.200-: In the Default CV file of 25.2.200 (CSAR) , concurrency for istio container of all the Microservices is not mentioned

The default CV file in the 25.2.200 CSAR does not mention Istio container concurrency for all microservices. This can leave deployment configuration incomplete or unclear.

Doc impact: There is no documentation impact.

3 25.2.200
38964293 Voice Call model- Observed multiple Policy microservice container restart during the PCF upgrade from 25.1.200 to 25.2.200

Multiple Policy microservice containers can restart during PCF upgrade from 25.1.200 to 25.2.200 in the BT Voice call model. This can affect service stability during upgrade.

Doc impact: There is no documentation impact.

3 25.2.200
38970033 With READ_ONLY user CNCC prompt "Profile named DEFAULT is activated successfully" for Congestion Profile switch and Load Shedding Rules copy etc

With the READ_ONLY role, you can receive successful action prompts for operations such as congestion profile switch or load-shedding rule copy. This can incorrectly indicate that the read-only role performed configuration actions.

Doc impact: There is no documentation impact.

3 25.1.202
38973947 Config server pods are getting stuck and not processing any requests after restarting 1 out of 2 config server pods with 55K TPS traffic (SM Call Model)

Config server pods can become stuck and stop processing requests after one of two pods is restarted under 55K TPS SM call-model traffic. This can affect configuration service availability under load.

Doc impact: There is no documentation impact.

3 25.2.200
38985407 UE- Validation is not there for notificationURI in update request

UE service update requests can lack validation for notificationURI. This can allow invalid notification URI values to be accepted.

Doc impact: There is no documentation impact.

3 25.2.100
39066800 Need an alert off of “oc.egressgateway.resolve.fqdn.from.ars.failure” metric when EGW encounter DNS SRV resolution failure

Egress Gateway does not provide the expected alert based on oc.egressgateway.resolve.fqdn.from.ars.failure when DNS SRV resolution fails. This can leave DNS SRV failures without the intended operational notification.

Doc impact: There is no documentation impact.

3 24.2.4
39082749 pcrf-core: change default value for configurations for unsolicited messages routing via diam-gw

PCRF-Core default configuration for unsolicited message routing through Diameter Gateway can use an unintended value. This can cause unsolicited messages to follow the wrong routing behavior by default.

Doc impact: There is no documentation impact.

3 25.1.100
39092757 AM service: PCF is sending wrong Content-Type: application/problem+json header for successful response

AM service responses from PCF can use the problem-details content type for successful responses. This can give clients an incorrect Content-Type header for successful AM policy operations.

Doc impact: There is no documentation impact.

3 25.2.200
39098879 Removing the duplicate diamGatewayEnable parameter under the custom.yaml

custom.yaml can contain a duplicate diamGatewayEnable parameter. This can make Diameter Gateway enablement configuration ambiguous.

Doc impact: There is no documentation impact.

3 25.1.200
39125512 Update policy upgrade guide to inculde newly introduced table i.e. occnp_pcf_sm.TdfSession in existing replication group

The Policy Upgrade Guide does not include the newly introduced occnp_pcf_sm.TdfSession table in the existing replication group guidance. This can leave upgrade replication instructions incomplete.

Doc impact: There is no documentation impact.

3 25.2.200
39125875 Incorrect NFType label value in oc_egressgateway_http_responses_total metric

The oc_egressgateway_http_responses_total metric can report an incorrect NFType label value. This can make metric filtering and attribution inaccurate.

Doc impact: There is no documentation impact.

3 25.2.200
39136398 UDR patch request failed on GR site-2 EGW with error 3gpp-sbi-target-apiroot header is missing on minimal performance run of 1K TPS on Dual Stack setup

UDR PATCH requests can fail on GR site-2 Egress Gateway with a missing 3gpp-sbi-target-apiroot header during a 1K TPS dual-stack performance run. This can disrupt UDR update traffic in that setup.

Doc impact: There is no documentation impact.

3 25.2.200
39386429 PolicyDs: problem while removing oldest context from context_info on exceeding column size

PolicyDS can have trouble removing the oldest context from context_info when the column size is exceeded. This can prevent proper context cleanup when stored context data grows too large.

Doc impact: There is no documentation impact.

3 24.2.3
39604232 Internal server error importing a big file of Data Limit Profile json

CNC Console returned an internal server error when importing a large Data Limit Profile JSON file. This can prevent successful import of large profile data.

Doc impact: There is no documentation impact.

3 25.1.202
39604527 cnPCRF is adding an undesired custom AVP in Sy interface

cnPCRF added an undesired custom AVP on the Sy interface. This can send unexpected Diameter AVP data to peer systems.

Doc impact: There is no documentation impact.

3 25.1.200
39615975 PCF 25.2.100: Repeated Firing/Resolved Notifications for SYSTEM_OPERATIONAL_STATE_PARTIAL_SHUTDOWN Alert

PCF can repeatedly fire and resolve notifications for the SYSTEM_OPERATIONAL_STATE_PARTIAL_SHUTDOWN alert. This can create alert noise and make the operational state harder to interpret.

Doc impact: There is no documentation impact.

3 25.2.100
37721161 AN-Trusted AVP is not getting included in AAA response from PCRF for given specific RAT-Type

PCRF can omit the AN-Trusted AVP from AAA responses for a specific RAT-Type. This can produce incomplete Diameter response data for affected access-type scenarios.

Doc impact: There is no documentation impact.

3 25.1.100
37746896 When N7 Delete is received to SM service then Get PDS/v2/user-data is triggered although queryUseronDelete=false is configured

SM service can trigger a PDS /v2/user-data GET request when an N7 Delete is received even though queryUserOnDelete is configured as false. This can cause unnecessary user-data queries during delete handling.

Doc impact: There is no documentation impact.

3 24.2.4
37757536 Able to update the exclude DNN flags in advancedSettings of PCF Session Management service configuration using common service API with leading & trailing spaces

The common service API can allow exclude DNN flags in PCF Session Management advanced settings to be updated with leading or trailing spaces. This can result in malformed or unintended configuration values.

Doc impact: There is no documentation impact.

3 24.2.4
38417366 msg_type="SNR" parameter is missing from metric occnp_diam_congestion_message_reject_total

The occnp_diam_congestion_message_reject_total metric can omit the msg_type="SNR" parameter. This can make Diameter congestion rejection metrics incomplete for SNR messages.

Doc impact: There is no documentation impact.

3 25.2.100
38526952 Retry Feature enabled in App-Info but it is marking cluster as failed

App-Info can mark the cluster as failed even when the retry feature is enabled. This can report an incorrect cluster failure state during retry handling. 

Doc impact: There is no documentation impact.

3 25.2.100
38526975 Assume Positive property in app-info is enabled but it is marking cluster as failed

App-Info can mark the cluster as failed even when the assume positive property is enabled. This can incorrectly report cluster failure despite the configured positive-assumption behavior.

Doc impact: There is no documentation impact.

3 25.2.100
38587466 [Generic_Policy]:Retain/Ignore option is replacing the old configuration with the new configuration in PDS settings screen

The Retain or Ignore option in the PDS settings screen replaced the existing configuration with the new configuration. This can cause retained settings to be overwritten unexpectedly.

Doc impact: There is no documentation impact.

3 25.2.200
38590615 Even Query User on Terminate=False, SM sending GET request for smPolicyData (in case earlier POST subs-to-notify failed)

SM service can send a GET request for smPolicyData even when Query User on Terminate is false if an earlier POST subs-to-notify request fails. This can trigger an unexpected data query during termination handling.

Doc impact: There is no documentation impact.

3 25.2.100
38608724 [GENERIC_POLICY]:ocLogID is missing in AM Service Logs for the Response Messages received from PolicyDS and PRE Services.

AM Service logs can miss ocLogID values for response messages received from PolicyDS and PRE services. This can make response-message tracing harder across services.

Doc impact: There is no documentation impact.

3 25.2.200
38705518 [PA_SPONSOR_DATA_CONNECTIVITY_UPDATE_USAGE_REPORT]: sponId and aspId value changed in update_notify on PA-Subscribe request

sponId and aspId values can change in update_notify messages for a PA-Subscribe request in the sponsored data connectivity usage-report flow. This can send inconsistent sponsor identity data.

Doc impact: There is no documentation impact.

3 25.2.200
38718734 The "sender" field in the enhanced warning log is not showing the correct binding-pod name in the diam-gateway pod when error 5065 comes from the binding pod during the context-owner query.

Diameter Gateway enhanced warning logs can show the wrong binding-pod name in the sender field when error 5065 came from the binding pod during a context-owner query. This can make the source of the error difficult to identify.

Doc impact: There is no documentation impact.

3 25.2.200
38741355 java.lang.NullPointerException observed while binding triggers re-validation for binding session with GR site2 BSF

Binding session revalidation with GR site2 BSF can trigger a NullPointerException. This can interrupt binding revalidation processing for affected sessions.

Doc impact: There is no documentation impact.

3 25.2.200
38771910 allowedSnssais is missing from request section of AM Create Response when DNNReplacement and SliceSupport is disabled

allowedSnssais can be missing from the request section of the AM Create response when DNNReplacement and SliceSupport are disabled. This can produce incomplete AM policy response data.

Doc impact: There is no documentation impact.

3 25.2.200
38837486 invalidParams field is not correct when SM service is rejecting PA- Create request with invalid "notifURI"

SM service can populate the invalidParams field incorrectly when rejecting a PA-Create request with an invalid notifURI. This can give clients inaccurate validation details.

Doc impact: There is no documentation impact.

3 25.2.200
38857919 [GR_Testing]: Observing "Exception handling failed. Message: For input string: "INTERNAL_SERVER_ERROR"" error in PDS logs when audit notification is received and sm-service pod is in congestion

PDS logs can show an exception-handling failure when an audit notification is received while the SM service pod is congested. The error can occur while handling an INTERNAL_SERVER_ERROR string value.

Doc impact: There is no documentation impact.

3 25.2.200
38885139 [GR_Testing]: NPE seen in sm-service with reason: "message":"Cannot invoke "[ocpm.pcf.service.pa](http://ocpm.pcf.service.pa).domain.model.AppSession.isFeatureNegotiated(int)" because "appSession" is null"

SM service can throw a NullPointerException when appSession is null during feature-negotiation checks. This can interrupt affected policy authorization processing.

Doc impact: There is no documentation impact.

3 25.2.200
38885174 Alert UPDATE_NOTIFY_FAILURE_ABOVE_50_PERCENT is not getting fired

The UPDATE_NOTIFY_FAILURE_ABOVE_50_PERCENT alert can fail to fire when the configured failure condition is met. This can leave update-notify failure spikes without the expected alert.

Doc impact: There is no documentation impact.

3 25.2.200
38899895 The value of the sponId/aspId dimensions is not coming as "NotSpecified" when SYSTEM.INCLUDE_SPONID_ASPID_DIMENSIONS is false

The sponId and aspId metric dimensions can fail to report NotSpecified when SYSTEM.INCLUDE_SPONID_ASPID_DIMENSIONS is false. This can produce unexpected metric dimension values.

Doc impact: There is no documentation impact.

3 25.2.200
38930756 Prometheus cardinality control for the metric occnp_pa_sponsored_sessions_total is not enforced when the number of calls is below the configured SPONID_ASPID_PAIR_CARDINALITY_LIMIT value

Prometheus cardinality control for occnp_pa_sponsored_sessions_total can fail to apply when call volume is below the configured SPONID_ASPID_PAIR_CARDINALITY_LIMIT. This can allow higher-than-expected metric cardinality.

Doc impact: There is no documentation impact.

3 25.2.200
38980990 UDR-Notification is failing if "Charging Profile selection based on Notification - UDR" workflow is enabled

UDR notifications can fail when the Charging Profile selection based on Notification - UDR workflow is enabled. This can disrupt notification-driven charging profile selection.

Doc impact: There is no documentation impact.

3 25.2.200
39059680 SM service is not printing framedIpAddress, calledStationId, sessionId, reciever items correctly in enhanced WARN log

SM service enhanced WARN logs can print framedIpAddress, calledStationId, sessionId, and receiver values incorrectly. This can reduce the usefulness of warning logs for troubleshooting.

Doc impact: There is no documentation impact.

3 25.2.200
39061348 Oclog id is missing in server response(SAL is on) for PA-UPDATE when call failed as 403 REQUESTED_SERVICE_NOT_AUTHORIZED

ocLogId was missing from the server response for PA-UPDATE failures with 403 REQUESTED_SERVICE_NOT_AUTHORIZED when SAL is enabled. This can make failed request correlation harder.

Doc impact: There is no documentation impact.

3 25.2.200
39064208 [GR_Testing]: Session viewer displaying incorrect Creation Time in case of UE policy create request

Session Viewer displayed an incorrect creation time for UE policy create requests. This can show misleading session timing information to you.

Doc impact: There is no documentation impact.

3 25.2.200
39064258 occnp_dnn_replacement_total metrics is not update AM create response when UDR send "olddnn"= null for AM data for DNN_replacement feature

The occnp_dnn_replacement_total metric failed to update for AM create responses when UDR sends olddnn as null for DNN replacement data. This can make DNN replacement metric reporting incomplete.

Doc impact: There is no documentation impact.

3 25.2.200
39070829 ocLogId is not contained in enhanced log of diam-connector logs during SY 3002 error response from diam-gw - 26.1.200

Diameter Connector enhanced logs can omit ocLogId during Sy 3002 error responses from Diameter Gateway. This can make error correlation harder for Sy response handling.

Doc impact: There is no documentation impact.

3 25.2.200
39096625 Multiple issue is observed in SM service enhanced log when 5030 error received in SLA response from OCS

SM service enhanced logs contained multiple issues when a 5030 error is received in an SLA response from OCS. This can make OCS error handling harder to diagnose.

Doc impact: There is no documentation impact.

3 25.2.200
39096801 The occnp_http_congestion_message_reject_total metrics has "message priority" dimenesions diff as "priority" and "message_priority" in different micro services

The occnp_http_congestion_message_reject_total metric can use inconsistent message-priority dimension names across microservices. This can make congestion rejection metrics harder to query consistently.

Doc impact: There is no documentation impact.

3 25.2.200
39123731 With high rate SM calls (minimal performance 1k or more TPS), wrong ocLogId mapped for same transaction in udr-conn logs

UDR Connector logs mapped the wrong ocLogId for the same transaction under high-rate SM call traffic of 1K TPS or more. This can break log correlation for affected transactions.

Doc impact: There is no documentation impact.

3 25.2.200
39589081 ASR not triggered by PCF on UpdateNotify failure for AAR-I without Media-Type when it mismatches the media type in Rx Reauth profile with Suppress-ASR - patch 26.1.200

PCF can fail to trigger ASR after an UpdateNotify failure for AAR-I without Media-Type when the request mismatched the Rx Reauth profile media type with Suppress-ASR. This can leave the expected session cleanup or notification behavior incomplete.

Doc impact: There is no documentation impact.

3 25.2.200
37329590 Occasionally during CHF or UDR notification ocLogID missing from SM Service for GET request towards PDS

SM Service logs occasionally missed the ocLogID values for GET requests to PDS during CHF or UDR notification handling. This can make request tracing incomplete.

Doc impact: There is no documentation impact.

3 24.3.0
37375563 PCF is not sending CHF delete for 1st message received during race condition

PCF failed to send a CHF delete for the first message received during a race condition. This can leave charging-related cleanup incomplete for that flow.

Doc impact: There is no documentation impact.

3 24.2.0
37637352 No ocLogID in UDR (other NF) response in egress gateway subscriber tracing logs

Egress Gateway subscriber tracing logs can omit ocLogID for UDR or other NF responses. This can make cross-service response tracing incomplete.

Doc impact: There is no documentation impact.

3 25.1.100
38190543 Lots of UE services logs missing ocLogID for N1N2 Subscription or N1N2 Transfer failures and RAB attempts

UE service logs missed ocLogID values for N1N2 subscription failures, N1N2 transfer failures, and RAB attempts. This can make troubleshooting those UE flows harder.

Doc impact: There is no documentation impact.

3 25.1.200
38502162 ocLogID missing in SM-Service logs for GET from DIAM-Conn to SM service for PA policy GET

SM-Service logs excluded ocLogID for PA policy GET requests initiated from Diameter Connector. This can break log correlation for those Diameter-to-SM requests.

Doc impact: There is no documentation impact.

3 25.2.200
38521967 Policy 25.2.100 - IllegalArgumentException observed on pcrf-core service after upgrade and rollback between 25.1.200 and 25.2.100

PCRF-Core throwed an IllegalArgumentException after upgrade and rollback between 25.1.200 and 25.2.100. This can affect service behavior after rollback scenarios.

Doc impact: There is no documentation impact.

3 25.2.100
38568991 [Generic_Policy]: NPE seen in sm-service during audit notification flow towards SMF

SM service throwed a NullPointerException during audit notification flow toward SMF. This can interrupt audit notification handling for affected sessions.

Doc impact: There is no documentation impact.

3 25.2.200
38618037 [Generic_Policy]: AM service deletion is not happening and AM service logs are flooding with NPE when ASSOCIATIONID in Enabled

AM service deletion failed and AM service logs was flooded with NullPointerException errors when ASSOCIATIONID is enabled. This can prevent cleanup and create excessive error logging.

Doc impact: There is no documentation impact.

3 25.2.200
38638225 [Generic_Policy]: PDS settings default fields are not reflecting in GET and EXPORT requests output from Swagger

PDS settings default fields was missing from GET and EXPORT request output in Swagger. This can make exported or retrieved PDS settings appear incomplete.

Doc impact: There is no documentation impact.

3 25.2.200
38674636 [GR_Testing]: Observing audit service reporting different counts in different audit service pods for metric: oc_db_active_session_count metric

Audit service pods reported different oc_db_active_session_count values for the same environment. This can make active-session monitoring inconsistent across pods.

Doc impact: There is no documentation impact.

3 25.2.200
38689892 Enhance error details CauseCode for REQUESTED_SERVICE_NOT_AUTHORIZED sent as 0000 UNKNOWN

Error details for REQUESTED_SERVICE_NOT_AUTHORIZED reported CauseCode as 0000 UNKNOWN. This can give clients unclear or incorrect failure cause information.

Doc impact: There is no documentation impact.

3 25.2.200
38693201 PolicyDS: Handle Monotonic Increment of last_modified_time for Conflict Resolution During DB Updates

PolicyDS database updates failed to maintain a monotonic last_modified_time value for conflict resolution. This can make update ordering and conflict handling unreliable.

Doc impact: There is no documentation impact.

3 25.1.200
38693414 Binding: Prevent Time Drift by Enforcing Monotonic Increment of lastModifiedTime column value During DB Update Operations

Binding database updates allowed lastModifiedTime values to drift instead of increasing monotonically. This can affect conflict resolution or update ordering.

Doc impact: There is no documentation impact.

3 25.1.200
38700733 msgtype and appytype are diameter related but also include POST and URI which is for http in diam connecotor

Diameter Connector logs or fields for msgtype and apptype can include HTTP-specific values such as POST and URI. This can mix Diameter and HTTP semantics in diagnostic data.

Doc impact: There is no documentation impact.

3 25.2.200
38706710 [GR_Testing]: Audit dequeue rate is going beyond the configured notification rate in audit registration

Audit dequeue rate exceeded the configured notification rate in audit registration. This can cause audit notifications to be processed faster than the configured limit.

Doc impact: There is no documentation impact.

3 25.2.200
38718607 "sender" field in enhance warn log is adding k8 node name in diam-gateway pod for error 5012

Diameter Gateway enhanced warning logs populated the sender field with the Kubernetes node name for error 5012. This can make the logged sender identity incorrect.

Doc impact: There is no documentation impact.

3 25.2.200
38768694 NPE is seen in audit service during inservice upgrade from 25.2.100GA to 25.2.200.

Audit service throwed a NullPointerException during in-service upgrade from 25.2.100 to 25.2.200 . This can affect audit service stability during upgrade.

Doc impact: There is no documentation impact.

3 25.2.200
38787919 [GR_Testing]: Observing Audit service pod restart after performing upgrade to 25.2.200

Audit service pods restarted after upgrade to 25.2.200 . This can affect audit service availability during or after upgrade.

Doc impact: There is no documentation impact.

3 25.2.200
38796358 [GR_Testing]: NPE seen in policyds with ERROR "Cannot invoke "java.util.List.forEach(java.util.function.Consumer)" because the return value of "getPdsProfileData()" is null"

PolicyDS throwed a NullPointerException when pdsProfileData is null and the service attempted to iterate over it. This can interrupt affected policy data processing.

Doc impact: There is no documentation impact.

3 25.2.200
38819116 Infra Validation is not working for minViablePath feature during upgrade scenario for ocnrf

Infrastructure validation for the minViablePath feature failed during an OCNRF upgrade scenario. This can leave upgrade validation incomplete for that feature.

Doc impact: There is no documentation impact.

3 25.2.200
38877018 (PCF:25.2.200)AM Service Reports a Warning "Error found in Bulwark Unlock Request: null" full exception and stack trace do not get printed as Enhanced Logging is not present

AM Service logged a Bulwark Unlock warning with a null error while omitting the full exception and stack trace. This can make the underlying failure difficult to diagnose.

Doc impact: There is no documentation impact.

3 25.2.200
38902416 Diam-connector is printing error log "Timestamp cannot be processed because dateString is: 2025-07-04T09:50Z" during SM performance run

Diameter connector printed a timestamp-processing errors during SM performance runs. This can add error noise and indicate that valid timestamp formats are not handled correctly.

Doc impact: There is no documentation impact.

3 25.2.200
38909233 Remove unused helm parameter isIpv6Enabled

The Policy Helm chart contains an unused isIpv6Enabled parameter. This can create configuration confusion because the parameter appears available but has no useful effect.

Doc impact: There is no documentation impact.

3 25.2.200
38914302 The error response format does not match the expected Problem Details structure in binding microservice

Binding microservice error responses failed to match the expected Problem Details structure. This can give API clients inconsistent or nonstandard error payloads.

Doc impact: There is no documentation impact.

3 25.2.200
38930363 PCF is sending 3gpp-sbi-discovery-target-nf-set-id: with no value/null value to BSF for pcfbinding create request while same not found

PCF sent an empty or null 3gpp-sbi-discovery-target-nf-set-id header to BSF during pcfBinding create requests. This can send invalid discovery metadata in binding traffic.

Doc impact: There is no documentation impact.

3 25.2.200
38930703 [Systemic] Fix QueryTypeMismatchException in JPQL COUNT() queries (Hibernate 6.6 Migration)

JPQL COUNT queries throwed QueryTypeMismatchException after Hibernate 6.6 migration. This can break database query paths that relied on COUNT results.

Doc impact: There is no documentation impact.

3 25.2.200
38948315 PCF UE service rejecting N1N2 notification with incorrect error code while json format is invalid

PCF UE service rejected N1N2 notifications with an incorrect error code when the JSON format is invalid. This can give clients misleading validation failures.

Doc impact: There is no documentation impact.

3 25.2.200
38948483 Post GRR table mismatch has been found in occnp_overload2.leader_election table.

A table mismatch appeared in the occnp_overload2.leader_election table after GRR. This can indicate inconsistent leader-election state after recovery or replication.

Doc impact: There is no documentation impact.

3 25.2.200
39027875 [GR_Testing][intermittent]: Policy upgrade failing due to EGW failed to connect to database while upgrading from 25.1.200 to 25.2.101

Policy upgrade failed intermittently when Egress Gateway cannot connect to the database during upgrade from 25.1.200 to 25.2.101. This can interrupt upgrade completion.

Doc impact: There is no documentation impact.

3 25.2.100
39053775 Sender is printed as "null-" in SM service log while trying to generate 5002 error response for AAR-U message

SM service logs printed the sender as null- while generating a 5002 error response for an AAR-U message. This can make the sender identity unclear in enhanced logs.

Doc impact: There is no documentation impact.

3 25.2.200
39053783 receiver field in SM log is printed as 'AF-' instead of 'Diam-C' for 5002 error response on STR message

SM logs printed the receiver field as AF- instead of Diam-C for a 5002 error response on an STR message. This can misidentify the receiver in enhanced logs.

Doc impact: There is no documentation impact.

3 25.2.200
39059748 errorCause in diam-gw is shown as UNKNOWN whereas diam-conn is showing as DIAMETER_TOO_BUSY for 3004 diameter error code

Diameter Gateway showed errorCause as UNKNOWN for a 3004 Diameter error while Diameter Connector shows DIAMETER_TOO_BUSY. This can make error reporting inconsistent across components.

Doc impact: There is no documentation impact.

3 25.2.200
39063766 [Generic_Policy]: Custom values file does not contain readiness related configuration and proper description in diam-gw section

The custom values file excluded readiness-related configuration and a proper description in the Diameter Gateway section. This can leave deployment guidance incomplete for readiness behavior.

Doc impact: There is no documentation impact.

3 25.2.100
39083791 EGW logs for message "HTTP response body is empty" doesn't contains ocLogId

Egress Gateway logs for HTTP response body is empty messages can omit ocLogId. This can make those response errors harder to correlate.

Doc impact: There is no documentation impact.

3 25.2.200
39084868 Diam-conn log contains error code as 5012 & diam-gw log has error code as 5063

Diameter Connector and Diameter Gateway logged different error codes for the same failure, with Diam-Conn showing 5012 and Diam-GW showing 5063. This can make troubleshooting inconsistent across components.

Doc impact: There is no documentation impact.

3 25.2.200
39090587 Relevant error should be printed in errorCause field instead of UNKNOWN in Diam-conn and SM for HTTP related error log

Diameter Connector and SM HTTP-related error logs printed UNKNOWN in the errorCause field instead of the relevant error. This can reduce diagnostic value for HTTP failures.

Doc impact: There is no documentation impact.

3 25.2.200
39090727 EGW 25.2.109: Host dimension in Egress gateway response metrics still has cardinality explosion

The Host dimension in Egress Gateway response metrics can still have excessive cardinality. This can increase monitoring storage and query load.

Doc impact: There is no documentation impact.

3 25.2.200
39100130 [GR_Testing]:reactor.core.Exceptions$RetryExhaustedException Error log is seen while upgrading policy to 25.2.200

Policy upgrade to 25.2.200 can produce RetryExhaustedException error logs. This can add error noise or indicate retry handling issues during upgrade.

Doc impact: There is no documentation impact.

3 25.2.200
39110950 Errors are printed in errorCode field rather than errorStatus field for all HTTP related enhanced error log in pcrf-core

PCRF-Core enhanced HTTP error logs printed errors in the errorCode field instead of the errorStatus field. This can make error log fields inconsistent or misleading.

Doc impact: There is no documentation impact.

3 25.2.200
39110969 Incorrect sender field with senderType as "OCS-ocpcf" is printed in daim_gw log for SNA message for 5005 error response

Diameter Gateway logs can print an incorrect sender field with senderType OCS-ocpcf for SNA messages with a 5005 error response. This can misidentify the source in enhanced logs.

Doc impact: There is no documentation impact.

3 25.2.200
39120227 PCF nrf-client sending NRF subscription request with invalid URI causing subscription failure by NRF

PCF NRF client sent NRF subscription requests with an invalid URI. This can cause NRF subscription creation to fail.

Doc impact: There is no documentation impact.

3 25.2.200
39155094 calledStationId, framedIpAddress and other value are printed with a place holder in enhanced log for all http error codes in SM service

SM service enhanced logs printed placeholders instead of actual values for calledStationId, framedIpAddress, and related fields across HTTP error codes. This can reduce the usefulness of error logs.

Doc impact: There is no documentation impact.

3 25.2.200
39155221 In received error response enhanced log of SM service, receiver field is printed as SM-, it doesn't contian receiverID value

SM service enhanced logs for received error responses can print the receiver field as SM- without the receiverID value. This can make receiver identification incomplete.

Doc impact: There is no documentation impact.

3 25.2.200
39278726 PCF sending additional AVP AN-Trusted as untrusted in Rx RAR

PCF sent an additional AN-Trusted AVP with an untrusted value in Rx RAR messages. This can produce incorrect AVP data in Rx reauthorization traffic.

Doc impact: There is no documentation impact.

3 25.1.203
38291687 PCF is not rejecting the Policy association request with invalid optional attributes.

PCF accepted policy association requests containing invalid optional attributes. This can allow malformed policy association data instead of rejecting it with a validation error.

Doc impact: There is no documentation impact.

3 25.1.200
38477293 [FTP-201/197]Handling: Error State and Error Cause- Code Mapping  not working  for cause code "optional_ie_incorrect" status code 400,

Error state and error-cause code mapping can fail for the optional_ie_incorrect cause with HTTP status 400. This can produce incorrect or missing error details for that validation failure.

Doc impact: There is no documentation impact.

3 25.2.100
38564066 [25.2.200.beta4]NPE is seen in UDR-conn once in SM performance run with receivedHeaders is null

UDR connector throwed a NullPointerException during SM performance runs when receivedHeaders is null. This can interrupt affected UDR connector processing.

Doc impact: There is no documentation impact.

3 25.2.200
38590640 NullPointerException observed in UE service during AM/UE call flow with AMFSET_UPDATE feature enabled.

UE service throwed a NullPointerException during the AM/UE call flow when AMFSET_UPDATE is enabled. This can disrupt affected UE policy processing.

Doc impact: There is no documentation impact.

3 25.2.200
38602106 [Micronaut]: io.micrometer.core.instrument.MeterRegistry WARN log is seen in multiple services in pod logs after upgrading to 25.2.200

Multiple services emitted MeterRegistry warning logs after upgrade to 25.2.200. This can create noisy pod logs and indicate metric registration issues.

Doc impact: There is no documentation impact.

3 25.2.200
38803368 Binding Service logs WARN: "found 1 argument placeholders, but provided 3" at 1 CPS

Binding Service logged warning messages about mismatched argument placeholders even at low traffic. This can create misleading WARN log noise during normal operation.

Doc impact: There is no documentation impact.

3 25.2.200
38810100 UDR subscriber termination request is getting conflicted with error 409 in case sm-data and usage-mon data enabled for PCRF

UDR subscriber termination requests can fail with 409 conflict when SM data and usage-monitoring data are enabled for PCRF. This can prevent subscriber termination cleanup.

Doc impact: There is no documentation impact.

3 25.2.200
38817096 SM Create requests with non-matching DNN (sos) are incorrectly rejected during overload when rejection rules are configured for dnn=internet

SM Create requests using a non-matching DNN such as sos can be incorrectly rejected during overload when rejection rules are configured for dnn=internet. This can reject traffic outside the intended DNN rule scope.

Doc impact: There is no documentation impact.

3 25.2.200
38826799 Remove the license information and other irrelevant information from REST documentation

REST documentation includes license information and other irrelevant content. This can clutter the API reference and confuse you reviewing REST documentation.

Doc impact: There is no documentation impact.

3 25.2.200
38856018 Usage monitoring prompt ERROR Exception occurred in GrantManager /WARN getType()\" because "umD" is null with no clear error/warning of failure reason

Usage monitoring logged GrantManager errors or warnings when umD is null without clearly reporting the failure reason. This can make usage-monitoring failures harder to diagnose.

Doc impact: There is no documentation impact.

3 25.2.200
38856758 Ambiguity on namespace label on PCF /PCRF alertrule yaml file.

The PCF and PCRF alert rule YAML file has ambiguous namespace label usage. This can make alert rule configuration unclear for you.

Doc impact: There is no documentation impact.

3 25.2.100
38867718 [MICRONAUT] isIpvSixSetup used for SCLB to be removed if redundant post micronaut migration

The isIpvSixSetup setting for SCLB can remain after Micronaut migration even if it is redundant. This can leave obsolete configuration in the service.

Doc impact: There is no documentation impact.

3 25.2.200
38902456 (PCF:25.1.200): Egress Gateway (EGW) is generating a WARNING log with the message: "HTTP response body is empty." This occurs when SAL is enabled

Egress Gateway can generate warning logs stating HTTP response body is empty when SAL is enabled. This can create misleading warning noise during subscriber activity logging.

Doc impact: There is no documentation impact.

3 25.1.200
38907997 The Family of Alerts CPUUsagePerService.. and MemoryUsagePerServiceAbove.. are logically incorrect as the rate() function is being used on a gauge metric

CPUUsagePerService and MemoryUsagePerServiceAbove alert rules can use rate() on gauge metrics. This can make the alert logic incorrect for CPU and memory usage monitoring.

Doc impact: There is no documentation impact.

3 25.2.200
38920493 Audit service reported "Caught Exception while executing timer count synchronization job" due to Specified result type [java.lang.Integer] did not match Query selection type [java.lang.Long]

Audit service can report an exception during timer count synchronization because the query result type does not match the selected type. This can disrupt timer count synchronization jobs.

Doc impact: There is no documentation impact.

3 25.2.200
38953982 UDR_XX_IMMREP_FEATURE_NEGOTIATION_FAILED & UDR_XX_IMMREP_RESPONSE_MISSING_DATA alerts introduced in immediate reporting feature are activated during 4XX & 5XX failure condition

Immediate reporting alerts for UDR feature negotiation failure and missing response data can activate during 4XX and 5XX failure conditions. This can generate alerts for expected failure-response scenarios.

Doc impact: There is no documentation impact.

3 25.2.200
38957418 Observing 500 INTERNAL_SERVER_ERROR during fetch/export operation of UE Service Configuration if AMF Resubscription Condition is configured as "Please Select"

UE Service Configuration fetch or export can fail with 500 Internal Server Error when AMF Resubscription Condition is set to Please Select. This can block configuration retrieval or export.

Doc impact: There is no documentation impact.

3 25.2.200
38973311 When ImmRep is true, after 1st SM create success with POST ImmRep exchange and 2nd SM create revalidation with unsuccess GET-> PUT-> POST failure then SM update is not triggering POST with ImmRep enabled as per FD 4.2.11

SM update can fail to trigger the expected POST with Immediate Reporting enabled after a revalidation sequence involving unsuccessful GET, PUT, and POST operations. This can make immediate reporting behavior inconsistent with the documented flow.

Doc impact: There is no documentation impact.

3 25.2.200
39010720 Bulwark logs for "Lock Response status" changed in 25.2.200 vs 25.2.100 (Similar to CNCESPOL-6535, status code missing)

Bulwark lock response logs can omit the status code or differ unexpectedly between releases. This can reduce the usefulness of lock-response diagnostics.

Doc impact: There is no documentation impact.

3 25.2.200
39012904 Bulk export from 23.4.6 fails import on 25.1.200 for congestion load shedding profile for diam-gw

A bulk export from 23.4.6 can fail to import on 25.1.200 for the Diameter Gateway congestion load-shedding profile. This can block migration of that configuration.

Doc impact: There is no documentation impact.

3 25.1.200
39048337 PCF is sending wrong Content-Type: application/problem+json header for successful response

PCF can send Content-Type application/problem+json on successful responses. This can give clients an incorrect response content type.

Doc impact: There is no documentation impact.

3 25.2.200
39114139 PCF CSAR package occndbtier_custom_values_model_d file having Invalid value for schedulertimer.

The PCF CSAR package occndbtier_custom_values_model_d file can contain an invalid schedulertimer value. This can provide incorrect default deployment configuration.

Doc impact: There is no documentation impact.

3 25.2.200
39121038 config server and audit service pods unexpected restarts have been observed in scaling down pod for 15 Min scenario on site-1

Config server and audit service pods can restart unexpectedly during a 15-minute pod scale-down scenario on site 1. This can affect service stability during scaling operations.

Doc impact: There is no documentation impact.

3 25.2.200
39139447 High cardinality metrics in oc-policy-ds

oc-policy-ds can emit metrics with high cardinality. This can increase monitoring storage and query load.

Doc impact: There is no documentation impact.

3 25.2.200
39181026 UDR Connector Have WARN Logs ""Error while reading client-metadata header" getting Printed during Execution of 54K Traffic Over AM-UE call Model

UDR Connector can print warning logs about reading the client-metadata header during 54K AM-UE traffic execution. This can create warning noise under high traffic.

Doc impact: There is no documentation impact.

3 25.2.201
37042968 Mismatch in IGW occnp_oc_ingressgateway_http_requests_total & occnp_oc_ingressgateway_http_responses_total when request sent with Content-Length:0 and Body- PRESENT

Ingress Gateway request and response metrics can mismatch when a request has Content-Length: 0 while a body is present. This can make ingress HTTP request and response counts inconsistent.

Doc impact: There is no documentation impact.

3 23.4.6
37055606 ocpm_ingress_response_total{servicename_3gpp="npcf-ue-policy-control"} for response_code=4xx not updating while request received with Content-Length:0 and Body-Absent

The ocpm_ingress_response_total metric for npcf-ue-policy-control 4xx responses can fail to update when a request has Content-Length: 0 and no body. This can underreport ingress error responses.

Doc impact:There is no documentation impact.

3 23.4.6
37618869 pre pods restart observed due to OOM on Policy 24.2.4

PRE pods restarted because of out-of-memory conditions on Policy 24.2.4 . This can affect PRE service stability.

Doc impact: There is no documentation impact.

3 24.2.4
37685088 Two ASRs are being triggered from PCF, resulting in a Diameter "Unknown Session ID" (5002) error.

PCF can trigger two ASRs for a session, resulting in a Diameter Unknown Session ID 5002 error. This can create duplicate session termination signaling.

Doc impact: There is no documentation impact.

3 23.4.5
38428760 FTP-197[TC-047]Handling: Error State and Error Cause- Code Mapping is not correct for cause code "MANDATORY_IE_INCORRECT" status code 400,

Error state and error-cause code mapping can be incorrect for MANDATORY_IE_INCORRECT with HTTP status 400. This can give clients wrong error details for mandatory IE validation failures.

Doc impact: There is no documentation impact.

3 25.2.100
38676847 Diam GW once stuck in Overload state continued to be in same state even No traffic was there

Diameter Gateway remained stuck in overload state even after traffic stops. This keeps the gateway in an incorrect overload condition.

Doc impact: There is no documentation impact.

3 24.2.7
38709061 TDF value gets change in policy project when policy bulk import is performed

TDF values in a policy project changed during policy bulk import. This can alter imported policy configuration unexpectedly.

Doc impact: There is no documentation impact.

3 24.2.0
38709401 Rollback fails due to Missing "empty-dir" volumeMount in 24.2.8 ARS deployment.yaml

Rollback can fail because the ARS deployment YAML missed an empty-dir volumeMount. This can block rollback for the affected deployment package.

Doc impact: There is no documentation impact.

3 25.1.201
38750370 SM is not storing the rule failure report when the rule status is "active"

SM service failed to store rule failure reports when the rule status is active. This can leave failure-report information missing for active rules.

Doc impact: There is no documentation impact.

3 23.4.6
38770251 PA Create without MediaSubComponents causes null pointer exception on SMF Update Notify

PA Create requests without MediaSubComponents can cause a NullPointerException during SMF Update Notify processing. This can interrupt notification handling for that request shape.

Doc impact: There is no documentation impact.

3 25.1.200
38770894 Alternate route retry does not work for nBSF initial message in model B

Alternate route retry can fail for the nBSF initial message in Model B. This can prevent expected rerouting when the initial path fails.

Doc impact: There is no documentation impact.

3 24.2.3
38797394 PCF choosing SUSPENDED BSF instead of the REGISTERED BSF in case of Alternate route for deleteBinding request

PCF can choose a suspended BSF instead of a registered BSF when using alternate routing for deleteBinding requests. This can route binding deletion traffic to the wrong BSF state.

Doc impact: There is no documentation impact.

3 24.2.3
38824470 Inconsistent grant by UM when max grant limits granted units

Usage Monitoring can grant inconsistent units when maximum grant limits are applied. This can produce incorrect quota grants.

Doc impact: There is no documentation impact.

3 25.2.100
38835801 chf_tracking_request_total and chf_tracking_response_total metrics are getting pegged for incorrect nfName in case of rerouted-retried attempts by ARS

CHF tracking request and response metrics can be pegged with the wrong nfName during ARS reroute and retry attempts. This can misattribute CHF tracking metrics.

Doc impact: There is no documentation impact.

3 25.2.100
38842438 Dynamic rule with Ethernet Flow Description VLAN tag is not working

Dynamic rules using an Ethernet Flow Description VLAN tag failed to work. This can prevent correct policy behavior for VLAN-tagged Ethernet flow rules.

Doc impact: There is no documentation impact.

3 25.1.200
38846215 UE svc exposing too much of the data in the log. Which will potentially results in over flood of the log and will increase the cpu

UE service logs exposed excessive data, causing log flooding and increased CPU usage. This can reduce observability quality and add runtime overhead.

Doc impact: There is no documentation impact.

3 25.2.200
38864849 Exception in non-ASM setup for content-length and content-type are absent

Non-ASM setups can throw an exception when both content-length and content-type headers are absent. This can fail request handling for headerless payload scenarios.

Doc impact: There is no documentation impact.

3 23.4.6
38883549 Stale data is present when PCF send POST request with ImmRep attribute as true to UDR but 5xx response is received since validate user is true SM create is declined but stale PDS data is not deleted

Stale PDS data can remain when PCF sends a POST request with ImmRep true to UDR and receives a 5xx response while validation is enabled. This can leave stale data after an SM create request is declined.

Doc impact: There is no documentation impact.

3 25.2.200
38883651 Binding Sevice : ar_request_total and ar_response_total metrics are not being pegged for nBSF initial messages retry attempts when Binding service performs rerouting on alternate route.

Binding Service failed to peg ar_request_total and ar_response_total metrics for nBSF initial-message retry attempts during alternate-route rerouting. This can underreport alternate routing activity.

Doc impact: There is no documentation impact.

3 25.2.200
38905299 BAUTTMELAB: PCF EGW not giving precedence to IPV6 and resolving to IPV4 address

PCF Egress Gateway resolved to an IPv4 address instead of giving precedence to IPv6. This can route traffic over the wrong IP family in IPv6-preferred environments.

Doc impact: There is no documentation impact.

3 25.1.200
38956556 "occnp_oc_ingressgateway_http_responses_total" metric not getting incremented

The occnp_oc_ingressgateway_http_responses_total metric failled to increment. This can underreport ingress gateway HTTP responses.

Doc impact: There is no documentation impact.

3 24.2.7
38966619 N5 PA update PATCH request is reject with wrong error cause when Mandatory parameter is missing in request

N5 PA update PATCH requests with missing mandatory parameters was rejected with the wrong error cause. This gives clients misleading validation information. 

Doc impact: There is no documentation impact.

3 25.1.202
38972667 EGW is not able to send access token request towards NRF in TLS enabled setup

Egress Gateway failed to send access-token requests toward NRF in TLS-enabled setups. This can prevent expected NRF authorization flow.

Doc impact: There is no documentation impact.

3 25.1.200
38974428 SPAD_POLICY[AM-UE-Performance]- UE services has Intermittent Error "Error creating params for PDS DELETE request with exceptionl"

UE service intermittently log errors while creating parameters for PDS DELETE requests during AM-UE performance runs. This can affect PDS delete request handling.

Doc impact: There is no documentation impact.

3 25.1.202
38982314 PCF not sending Event Triggers in notification message towards SMF in continuous call testing

PCF excluded event triggers in notification messages sent to SMF during continuous call testing. This sent an incomplete notification data.

Doc impact: There is no documentation impact.

3 24.2.9
38984315 Network Element capability must be restricted to a few values

Network Element capability values were accepted without the expected restriction to allowed values. This can permit invalid or unsupported capability values.

Doc impact: There is no documentation impact.

3 25.1.200
39007416 25.1.200 PCF Congestion Control migration: Activities

PCF congestion-control migration activities had incomplete or incorrect behavior for the 25.1.200 migration path. This affected migration of congestion control configuration.

Doc impact: There is no documentation impact.

3 25.1.200
39028996 Pcrf-core: Need a retry mechanism for context and dependentContext binding creation failure

PCRF-Core lacked retry handling when context or dependentContext binding creation fails. This can leave binding creation failures unrecovered.

Doc impact: There is no documentation impact.

3 24.2.9
39066625 Seeing extra PA Service Received Event: msg type: DELETE in SM-service logs when executing SM-Rx call

SM-service logs can show an extra PA Service received event with DELETE message type during SM-Rx calls. This can create misleading log entries for the call flow.

Doc impact: There is no documentation impact.

3 23.4.4
39128166 OCCNP25.1.201-Incorrect destination-host avp in Sd TSR message

Sd TSR messages included an incorrect Destination-Host AVP. This can send Diameter traffic with wrong routing information.

Doc impact: There is no documentation impact.

3 25.1.201
39162602 cnPCRF CCA-I (3004) does not include Mandatory AVP CC-Request-Type

cnPCRF CCA-I responses with result code 3004 omitted the mandatory CC-Request-Type AVP. This can produce noncompliant Diameter response messages.

Doc impact: There is no documentation impact.

3 24.2.0
39189141 Deletion of config item causes export failure

Deleting a configuration item caused an export operations to fail. This can prevent the user from exporting configuration after item deletion.

Doc impact: There is no documentation impact.

3 25.1.203
39216654 Policy synchronization issue: Post-upgrade/failover state mismatch

Policy state mismatched after upgrade or failover. This can leave synchronized policy data inconsistent across system components.

Doc impact: There is no documentation impact.

3 24.2.8
39285181 No policy evaluated for service pds as there is no policy project in 'Prod' state

PDS policy evaluation failled when no policy project is in Prod state. This can prevent expected policy evaluation for the PDS service.

Doc impact: There is no documentation impact.

3 25.1.200
39320933 Snssai showing blank

SNSSAI values were displayed as blank. This can hide slice information from the user.

Doc impact: There is no documentation impact.

3 24.2.3
39377723 Import containing Subscriber Activity Logging configuration is responded with 500 ISE

Imports containing Subscriber Activity Logging configuration failed with a 500 Internal Server Error. This can block import of SAL-related configuration.

Doc impact: There is no documentation impact.

3 25.2.201
39378360 DnsConfig addition in CV yaml file

The CV YAML file lacked required DnsConfig content for the scenario. This can leave DNS configuration incomplete in custom values.

Doc impact: There is no documentation impact.

3 24.2.1
39396476 config-server: When found a duplicate entry in the config-server DB for a config_item, delete it based on a configuration

Config-server encountered a duplicate config_item entries in its database without configuration-based cleanup behavior. This can leave duplicate configuration records unresolved.

Doc impact: There is no documentation impact.

3 23.4.6
39480148 Changing: PCF -> Controlled Shutdown -> Operational State in the CNCC GUI gives "Unable to switch the operational state" error

Changing PCF controlled-shutdown operational state from the CNCC GUI failed with an Unable to switch the operational state error. This can prevent you from changing PCF operational state through the GUI. 

Doc impact: There is no documentation impact.

3 25.1.202
39488706 NPE seen in sm-service when it directly communicates with BSF when binding is disabled

SM service throwed a NullPointerException when directly communicating with BSF while binding is disabled. This can interrupt affected SM-to-BSF communication.

Doc impact: There is no documentation impact.

3 24.2.3
39669081 OCS_KEY_PRECEDENCE=GPSI does not suppress IMSI in Sy SLR when request contains both SUPI and GPSI

OCS_KEY_PRECEDENCE=GPSI  failed to suppress IMSI in Sy SLR messages when the request contains both SUPI and GPSI. This sent an unintended subscriber identifiers on the Sy interface. 

Doc impact: There is no documentation impact.

3 25.1.203
39681602 Unavailability of the db-monitor-svc, shall not be considered db cluster failure

App-info incorrectly interpreted the db-monitor service unavailability or probe failure as a database cluster failure. Transient db-monitor errors, timeouts, or unavailable responses can cause the database tier to be reported as Not_Running even when the DB cluster is not down.

Doc impact: There is no documentation impact.

3 23.4.6

4.2.9 SCP Resolved Bugs

Release 25.1.205

Table 4-24 SCP 25.1.205 Resolved Bugs

Bug Number Title Description Severity Found in Release
39508432 Monitoring Probe Traffic Mismatch Following SCP Upgrade SCP Traffic Feed parsed an empty 5G SBI message with content type JSON as empty instead of null or an empty string.

Doc Impact:

There is no doc impact.

3 25.1.204
39589002 Header "authority" has changed since SCP was upgraded After upgrading SCP to 25.1.202, the authority header changed from the hostname to the SCP-Worker name. This led to packet correlation failures.

Doc Impact:

There is no doc impact.

3 25.1.202
39696666 SCP DNSSVR Feature heartbeat issue SCP profile was suspended during migration.

Doc Impact:

There is no doc impact.

3 25.1.204
39696404 Egress Congestion Control - SCP is not throttling SCP incorrectly excluded NF service when service FQDN was missing, and Load Manager metrics stopped pegging.

Doc Impact:

There is no doc impact.

3 25.1.204
39696607 SCP is not creating NF subscriptions for all registered NFs on the NRF A missing subscription issue occurred while testing the NRF Bootstrap feature.

Doc Impact:

There is no doc impact.

3 25.1.204
39696845 Fix Duplicate NRF subscription issue and subscription patch empty body Null Pointer Issue SCP encountered duplicate NRF subscription and subscription patch empty body Null Pointer issues.

Doc Impact:

There is no doc impact.

3 25.1.204
39696435 SCP is intermittently returning the **CACHE_INVALID_OR_EMPTY_DETAILS** event when the OCI reduction rate is updated multiple times on SCP. Peer OCI local cache update failed for SCP and SEPP FQDN coherence keys.

Doc Impact:

There is no doc impact.

3 25.1.204
39478045 Update liveness probe config to avoid worker restart in Overload Traffic Scenarios SCP restarted workers in the overload traffic scenarios because of the liveness probe config.

Doc Impact:

There is no doc impact.

3 25.1.204
39477995 Port Bug: Stale Thread entries could be seen in Thread Watch Dog info with COMPLETED+isStuck=true Stale entries for stuck threads were observed in the SCP-Worker logs, indicating threads with a status of COMPLETED and isStuck set to true. Therefore, some threads remained in a stuck state indefinitely until the pod was restarted.

Doc Impact:

There is no doc impact.

3 25.1.204

Note:

Resolved bugs from 24.2.4, 24.3.0, and 25.1.100 have been forward ported to Release 25.1.205.

Release 25.1.204

Table 4-25 SCP 25.1.204 Resolved Bugs

Bug Number Title Description Severity Found in Release
38850056 SCP uses port 80 instead of 443 towards UDR causing nudr-dr timeouts After upgrading SCP from 25.1.100 to 25.1.202, intermittent communication errors occurred between SCP and UDR, where some nudr-dr requests returned 504 timeout responses to PCF.

Doc Impact:

There is no doc impact.

2 25.1.202
39171957 In case of scale down of NRF proxy/mediation pods, scp-worker map keep sending message to old IP Address of already deleted nrfproxy pod The Jetty client in SCP-Worker failed to refresh the target IP list and did not remove stale IPs, causing requests to be sent to invalid addresses during NRF proxy pod scaling.

Doc Impact:

There is no doc impact.

3 25.1.200
39157983 Fix pegging of ocscp_metric_nf_oci_rx_total in response The ocscp_metric_nf_oci_rx_total metric was not updated when the OCI header was received in the response from the producer NF.

Doc Impact:

There is no doc impact.

3 25.1.200
39099528 SCPAuditErrorResponse and SCPAuditEmptyNFArrayResponse ALERTS are not generated for new nfTypes-nfServices entries and persists for auditInterval even after TSI=LOCAL SCPAuditErrorResponse and SCPAuditEmptyNFArrayResponse alerts were not raised when a new nFType was added through the nfTypes-nfServices REST API.

Doc Impact:

There is no doc impact.

3 25.1.204
39086122 Duplicate header values are being concatenated in response to consumer SCP-Worker concatenated duplicate header values into a single value for the same key when sending the response to the consumer NF.

Doc Impact:

There is no doc impact.

3 25.1.203
39072551 UPF profile registration failure due to Incorrect usage of NonEmpty annotation for Snssai The User Plane Function (UPF) notification from NRF, containing a valid SNSSAI field in upfInfo, caused a failure while processing the NF profile at SCP during routing rule creation.

Doc Impact:

There is no doc impact.

3 25.1.200
39243589 SCP Profiles are not updated with correct ports Some configuration changes, such as system options at SCP, triggered reprocessing of already known peer SCP profiles upon notification from the SCP-Configuration microservice. In this case, SCP-Configuration had provided SCP profiles without including scpInfo information, resulting in incorrectly formed rules.

Doc Impact:

There is no doc impact.

3 25.2.102
39087502 SCP 25.1.202 still not able to be configured to send full chain in TLS handshake SCP supported the intermediate certificate when it was part of the CA bundle file, but not when it was included in the server or client certificate.

Doc Impact:

Updated the description of the following Helm parameters in the Oracle Communications Cloud Native Core, Service Communication Proxy Installation, Upgrade, and Fault Recovery Guide:

  • sbiProxySslConfigurations.server.primary.certificate.rsa
  • sbiProxySslConfigurations.server.secondary.certificate.rsa
  • sbiProxySslConfigurations.client.primary.certificate.rsa
  • sbiProxySslConfigurations.client.secondary.certificate.rsa
  • sbiProxySslConfigurations.server.primary.certificate.ecdsa
  • sbiProxySslConfigurations.server.secondary.certificate.ecdsa
  • sbiProxySslConfigurations.client.primary.certificate.ecdsa
  • sbiProxySslConfigurations.client.secondary.certificate.ecdsa
  • ddSslConfiguration.primary.certificate.rsa
  • ddSslConfiguration.secondary.certificate.rsa
  • ddSslConfiguration.primary.certificate.ecdsa
  • ddSslConfiguration.secondary.certificate.ecdsa
3 25.1.202
39257426 SCP rejecting accept header other than application/json and application/problem+json SCP rejected requests containing accept header other than application/json and application/problem+json.

Doc Impact:

There is no doc impact.

3 25.1.200

Note:

Resolved bugs from 24.2.4, 24.3.0, and 25.1.100 have been forward ported to Release 25.1.204.

Release 25.1.203

Table 4-26 SCP 25.1.203 Resolved Bugs

Bug Number Title Description Severity Found in Release
39072215 High CPU Utilization Observed on Load Manager reached upto 98% at 1200 NF Profiles (730K MPS) While the traffic was run at 730K MPS with 1200 NF profiles and sent 80 to 100 notifications per second for at least 12 hours, Load Manager CPU utilization reached 98% and the load-manager microservice logged an error continuously.

Doc Impact:

There is no doc impact.

2 25.1.200
38895958 SCP forwarding single header even when multiple headers are present with same header name SCP consolidated two 3gpp-sbi-binding headers sent by SMSF down to one header when AMF received the request.

Doc Impact:

There is no doc impact.

2 25.1.200
38666287 ArrayIndexOutOfBound Exception observed in traffic run After enabling Model D and Mediation, SCP-Worker continuously logged TLS, Jetty, and Micronaut exceptions.

Doc Impact:

There is no doc impact.

3 25.1.200
38676349 Page not found exception observed in configuration pod After upgrading SCP from 25.1.100 to 25.2.100, scrolling errors were logged every 12 to 14 minutes for the occ1-mudflap-ocscp-scpc-configuration-7d98dddc59-qlrkv pod when the log level was set to INFO.

Doc Impact:

There is no doc impact.

3 25.1.200
38736605 Worker not sending any response back to consumer if no foreign SCP is found service foreign producer. SCP-Worker did not send any response back to the consumer NF when no foreign SCP was found for the foreign producer.

Doc Impact:

There is no doc impact.

3 25.1.200
38711265 Not able to do any configuration changes in CNCC SCP GUI When cnDBTier, CNC Console, and SCP were deployed in an IPv6 only environment, the CNC Console displayed only SCP information, and configuration changes could not be made.

Doc Impact:

There is no doc impact.

3 25.1.201
38896281 Unable to route when port definition is missing from NFServices in NF Profile using only FQDN When an NF profile contained only an FQDN with no IP address or port, SCP did not route traffic correctly over TLS with the HTTPS scheme.

Doc Impact:

There is no doc impact.

3 24.2.6
38923076 SCP creates routing rules for NRF with incorrect FQDN format where MNC has 2 digits In the R16 release, SCP routing rule configuration incorrectly generated a two-digit MNC in the FQDN for a PLMN ID, instead of using the required three-digit format for the 5G domain.

Doc Impact:

There is no doc impact.

3 24.2.6
38943409 SCP tampering with HTTP2 body in message feed SCP sent a modified message body to Data Director instead of the exact body that it received, which caused the Content-Length value to not match the actual body length.

Doc Impact:

There is no doc impact.

3 25.1.200
39008940 TTMELAB STAGE-3 | SCP0015 WS1.5 Regression fail during nightly runs Multiple SCP ATS test cases failed over the last few days, and the NF pod logs were not available at the time of failure.

Doc Impact:

There is no doc impact.

3 25.1.200
38972143 SCP does not get registered with NRF (java.lang.IllegalArgumentException in Subscription pod)) Although all pods were running, and SCP received notifications from NRF, SCP was not registered with NRF.

Doc Impact:

There is no doc impact.

3 25.1.202
38751557 Every SCP Audit, picks up NRF profile for de-register event and SCP's self profile as change event to have trigger towards notification, which later gets ignored at notification During each SCP audit, the audit process selected an NRF profile for a de-registration event and SCP’s self profile for a change event, which triggered notifications that were later ignored.

Doc Impact:

There is no doc impact.

4 25.1.200
38746228 OpenAPI file is not generated correctly in SCP package The configuration pod generated an OpenAPI file (OCSCP-Configuration-OpenAPI.json) during the CICD process, but the file was empty because the output path was not enabled.

Doc Impact:

There is no doc impact.

4 25.1.200

Note:

Resolved bugs from 24.2.4, 24.3.0, and 25.1.100 have been forward ported to Release 25.1.203.

Table 4-27 SCP ATS 25.1.203 Resolved Bugs

Bug Number Title Description Severity Found in Release
38702138 ATS Framework fails to handle uri formation with bracket for ipv6 of worker pod IP After deploying SCP, ATS, cnDBTier, and CNC Console on an IPv6 environment, two test cases failed with a parse error while fetching metrics from the Prometheus.

Doc Impact:

There is no doc impact.

3 25.1.201

Release 25.1.202

Table 4-28 SCP 25.1.202 Resolved Bugs

Bug Number Title Description Severity Found in Release
38692824 SCP used to accept a non standard health request for a success response, path validation of health request was not proper In earlier releases of SCP, the response was the default response for the OPTIONS method (200 OK default response even if the path URI does not match is not through SCP application logic).

It was the underlying Spring Boot behavior to respond with 200 OK as the default response.

In the later release, there is a strict match for the path irrespective of the method. This difference is part of SCP’s transition from Spring Boot to Micronaut.

Doc Impact:

There is no doc impact.

2 25.1.100
38552864 Mediation updates on discovery headers is not considered in the SbiDiscovery request creation SCP did not consider the newly added or updated 3gpp-Sbi-Discovery-preferred-locality header from the mediation service when sending requests to NRF.

Doc Impact:

There is no doc impact.

2 25.1.200
38152282 SCP continues to use old certificates even after patching secrets with new certificates SCP continued to use old certificates even after patching secrets with new certificates. SslProviderObject had previously been available in Reactor Netty to handle H2, TCP, and NONE configurations, but Micronaut Netty did not offer a direct alternative.

Doc Impact:

There is no doc impact.

3 25.1.200
38552625 Check applied certificate before primary certificate reload on SSL config details SSE for 25.1.2x-patch When an SSL configuration details SSE was received, the system reloaded the primary server certificate, which was incorrect. It should have first checked the applied certificate and reloaded the same certificate.

Doc Impact:

There is no doc impact.

3 25.2.100
38552644 Fix TLS certificate reload issues for 25.1.200 When the primary server certificate had expired and the scp-worker pod was restarted, it continued to use the expired primary server certificate. 3 25.1.100
38553536 ocscp_worker_egress_res_total Metric not getting pegged The ocscp_worker_egress_res_total metric was not updated for responses from SCP.

Doc Impact:

There is no doc impact.

3 25.1.200
38553016 SCP generated timestamp sent to kafka without padding for nanoseconds SCP was sending messages to Kafka with timestamps that lacked proper padding for nanoseconds, resulting in Kafka interpreting the sequence of messages incorrectly.

Doc Impact:

There is no doc impact.

3 24.2.5
38552977 DNSSRV based alternate routing not working for static configuration DNS SRV-based alternate routing did not work for static configuration when the apiRoot header was present.

Doc Impact:

There is no doc impact.

3 25.2.100
38471728 Accept header added by SCP if it´s not in the original request SCP added the header Accept: application/json to an outbound request when the original request from the NF Consumer did not include an Accept header, and the NF Producer rejected the request because it only supported Accept: application/problem+json or no Accept header. In earlier releases, SCP did not add an Accept header when the original request did not have.

Doc Impact:

There is no doc impact.

3 25.1.201
38553599 Pseudo header values are not being taken in request Ingress mediation trigger point The Pseudo header values were not considered in the request ingress mediation trigger point rules. The acceptance criteria required that pseudo header values were considered in these rules when present.

Doc Impact:

There is no doc impact.

3 25.2.100
38543550 SCP rejecting profiles due to canaryReleaseConfigName SCP rejected profiles when an incorrect canaryReleaseConfigName was configured.

Doc Impact:

There is no doc impact.

3 25.1.100
38552843 SCP Errors generated during the upgrade from 25.1.100 to 25.1.200 are not captured in the ocscp_metric_scp_generated_response_total metrics During the upgrade from SCP 25.1.100 to 25.1.200, SCP errors were not recorded in the ocscp_metric_scp_generated_response_total metric.

Doc Impact:

There is no doc impact.

3 25.1.200
38552894 Rate Limit Service Initialization Flag Correction In rare scenarios, the BucketProxy variable was not initialized with appropriate value when an SCP-worker pod comes up, causing ingress rate limiting rules to fail and returning an internal server error to the consumer NF.

Doc Impact:

There is no doc impact.

3 24.2.5
38553620 DD client stub running with debug logs enabled The DDClient stub was configured with DEBUG as the default log level instead of INFO.

Doc Impact:

There is no doc impact.

4 25.1.200

Note:

Resolved bugs from 24.2.4, 24.3.0, and 25.1.100 have been forward ported to Release 25.1.202.

Table 4-29 SCP ATS 25.1.202 Resolved Bugs

Bug Number Title Description Severity Found in Release
38553659 Timeout for request to promethues is missing in ATS The Prometheus client did not consider request timeouts, and when Prometheus did not respond, ATS remained stuck indefinitely. With timeouts configured for Prometheus requests, ATS did not remain stuck.

Doc Impact:

There is no doc impact.

4 25.1.200

Release 25.1.201

Table 4-30 SCP 25.1.201 Resolved Bugs

Bug Number Title Description Severity Found in Release
38284085 SCP 25.1.200 Notification throwing NF_RULE_PROCESSOR_FAILURE for all NFs except UDR

While testing SCP 25.1.200, it was observed that routing rules for four test UDR profiles were processed and updated successfully. However, all other NF profiles were rejected, resulting in the following exception:

"message":"Category: NF_RULE_PROCESSOR_FAILURE, Event: RULE_PROCESSOR_MISCELLANEOUS, EventId: OSCP-NTF-RULPRC-EV001"

Doc Impact:

There is no doc impact.

2 25.1.200
38206028 Error while trying to Upgrade SCP from 25.1.100 to 25.1.200 and on fresh install of 25.1.200

The following error was observed while upgrading SCP from 25.1.100 to 25.1.200:

INSTALLATION FAILED: YAML parse error on ocscp/charts/scpc-configuration/templates/configuration.yaml: error converting

helm.go:84: [debug] error converting YAML to JSON: yaml: line 19: did not find expected key

YAML parse error on ocscp/charts/scpc-configuration/templates/configuration.yaml

Doc Impact:

There is no doc impact.

3 25.1.200
38318190 SCP 25.1.200 ModelD AUSF discovery failure: getAusfInfo() is null During service discovery of the nausf-auth service for NRF, the AUSF profile was sent by NRF in the response. However, SCP encountered a 500 error because the Ausfinfo header was missing from the response.

Doc Impact:

There is no doc impact.

3 25.1.200

Note:

Resolved bugs from 24.2.4, 24.3.0, and 25.1.100 have been forward ported to Release 25.1.201.

Table 4-31 SCP ATS 25.1.201 Resolved Bugs

Bug Number Title Description Severity Found in Release
38328447 Metric "ocscp_metric_nf_lci_tx_total" at times does not get validated if scp is not enabled to decode consumer on the basis of XFCC header and response from producer having LCI gets conveyed to Consumer NF The ocscp_metric_nf_lci_tx_total metric was not consistently validated when SCP was not enabled to decode the consumer based on the XFCC header. As a result, responses from the producer NF containing LCI were incorrectly conveyed to the consumer NF.

Doc Impact:

There is no doc impact.

3 25.2.100

Release 25.1.200

Table 4-32 SCP 25.1.200 Resolved Bugs

Bug Number Title Description Severity Found in Release
37838652 SCP unable to send requests when maxStreamId is reached on a connection SCP was unable to send requests when the stream ID reached its maximum value.

Doc Impact:

There is no doc impact.

2 25.1.100
37942341 SCP is erroneously routing inter-SCP traffic to other SCP instances within the same region. SCP generated inter-SCP routing rules for instances that were located within the same region.

Doc Impact:

There is no doc impact.

2 25.1.100
38120012 SCP internal traffic sent to OCNADD despite fix for BUG 37226666 delivered in 24.2.2

The internal traffic from SCP 24.2.4 was incorrectly routed to OCNADD, even though a fix for this issue was provided in SCP 24.2.2.

Doc Impact:

There is no doc impact.

3 24.2.2
38012554 SCP/ATS_25.1.100_Full_Regression_Failure_0252925

In SCP-ATS 25.1.100, a complete regression test failed with error codes.

Doc Impact:

There is no doc impact.

3 25.1.100
37931177 Notifications {"title":"Loop Detected","status":508"}

In SCP 25.1.100, notifications with the title "Loop Detected" and status code 508 were incorrectly generated.

Doc Impact:

There is no doc impact.

3 25.1.100
37859976 SCP is showing 504 errors for peer SCPs in the egress response metrics which excludes ocscp-initiated messages

SCP generated 504 errors when the peer SCP was unreachable and the destination route was exhausted.

Doc Impact:

There is no doc impact.

3 25.1.100
37843293 SCPMediationConnectivityFailure alerts are active even the connectivity is fine toward mediation

SCPMediationConnectivityFailure alerts were previously active despite confirmed connectivity toward Mediation.

Doc Impact:

There is no doc impact.

3 24.2.2
37840642 'DBOperation Failed: Failed to get ServiceEntry' exception was observed on the notification pod within the SCP

During a traffic run at the rate of 730K MPS with 700 NF profiles, a 'DBOperation failed to get service entry' exception occurred on the SCP. The setup included 7 SCP triplets in each region.

Doc Impact:

There is no doc impact.

3 25.1.100
37840553 A warning concerning an 'empty version map' was observed while running traffic at a rate of 730K MPS using a 700 NF profile.

While running traffic at a rate of 730K MPS using 700 NF profiles, a warning about an "empty version map" was observed.

Doc Impact:

There is no doc impact.

3 25.1.100
37815522 SCP Provides Grafana wrong Metric in Prometheus CPU utilization and Prometheus memory utilization

SCP provided incorrect metrics to Grafana for Prometheus CPU utilization and Prometheus memory utilization.

Doc Impact:

There is no doc impact.

3 24.2.2
37775369 SCPProducerNfSetUnhealthy Alert not getting raised

The SCPProducerNfSetUnhealthy alert was not raised.

Doc Impact:

There is no doc impact.

3 25.1.100
37746963 SCP Worker pod generating high Kube API traffic

In SCP 24.2.2, the SCP-Worker pod generated high Kubernetes API traffic.

Doc Impact:

There is no doc impact.

3 24.2.2
37721950 Getting IP instead of FQDN in peerscpfqdn dimension of SCPUnhealthyPeerSCPDetected Alert

The peerscpfqdn dimension of the SCPUnhealthyPeerSCPDetected alert displayed an IP address instead of FQDN.

Doc Impact:

There is no doc impact.

3 25.1.100
37721565 If SCP received request message with 3gpp-Sbi-Client-Credentials header with x5u - X.509 URL, then SCP should passthrough without CCA validation and should not reject the request message.

When SCP received a request message containing the 3gpp-Sbi-Client-Credentials header with an x5u (X.509 URL), it incorrectly rejected the message instead of bypassing CCA validation and processing the request.

Doc Impact:

There is no doc impact.

3 25.1.100
37713112 LCI and OCI not having validation for timestamp header causing nullPointerException leading to failure in responding to the consumer

LCI and OCI lacked validation for the timestamp header, which resulted in NullPointerException. This issue caused failures in responding to consumer NFs.

Doc Impact:

There is no doc impact.

3 25.1.100
37700589 SCP Notification pod restarted while sending invalid notification requests at a higher rate around 2K TPS

The SCP-Notification pod restarted when sending invalid notification requests at a high rate, approximately 2K TPS.

Doc Impact:

There is no doc impact.

3 25.1.100
37693288 SCP does not make NF rule profile for the de-registered NF on Last NF De-registration

SCP did not make NF rule profile for the de-registered NF on the last NF de-registration.

Doc Impact:

There is no doc impact.

3 24.3.0
37657153 Configuration pod crash was noticed on SCP when traffic was flowing at 730K MPS (signaling) and 1K TPS (control plane) GET requests to retrieve the ingress rate limit configuration

The configuration pod restarted in SCP when handling traffic at 730K MPS (signaling) and 1K TPS (control plane). This occurred during GET requests to retrieve the ingress rate limit configuration.

Doc Impact:

There is no doc impact.

3 25.1.100
37640874 SCP Metrics and dimensioning questions

Discrepancies related to metric dimensions and descriptions were observed in SCP 24.3.0.

Doc impact:

Updated the descriptions of the ocscp_nf_end_point dimension and the ocscp_nrf_notifications_requests_nf_total metric in Oracle Communications Cloud Native Core, Service Communication Proxy User Guide.

3 24.3.0
37640288 SCP Possibility to create subscriptions using the fqdn for TLS purpose

In the SCP implementation with NRF using TLS, notifications were not being received. This issue occurred because subscriptions were created using the IP address instead of the Fully Qualified Domain Name (FQDN), which was required by the NRF verification process.

Doc Impact:

There is no doc impact.

3 24.2.2
37634513 DiscardWithErrorRspCount parameter needs to be corrected in worker logs.

The DiscardWithErrorRspCount parameter in worker logs was incorrectly recorded.

Doc Impact:

There is no doc impact.

3 25.1.100
37632229 SBI Message Priority Rest API does not allow nftype as query parameter & PUT operation on existing rule is not allowed for change in scope of method array list

The SBI Message Priority REST API did not support nftype as a query parameter. Additionally, the PUT operation on an existing rule was not permitted when attempted to modify the scope of the method array list.

Doc Impact:

There is no doc impact.

3 25.1.100
37565543 SCP Alert triggered SCPEgressTrafficRoutedWithoutRateLimitTreatment without ERL enabled

In SCP 24.2.1, an alert for SCPEgressTrafficRoutedWithoutRateLimitTreatment was triggered, even though Egress Rate Limiting was not enabled.

Doc Impact:

There is no doc impact.

3 24.2.1
37439576 API Missing Validation for Mandatory Parameter: "enabled"

When a PUT request was made to the scp-features REST API, SCP did not return an error if the mandatory "enabled" parameter was missing.

Doc Impact:

There is no doc impact.

3 25.1.100
37428245 scp does not show profile details for NF-TYPE= SCP under edit profile option

When editing a profile for NF-TYPE=SCP, SCP did not display the profile details.

Doc Impact:

There is no doc impact.

3 25.1.100
37428201 scp returns misleading error when editing static nrf profiles

When editing static NRF profiles, SCP returned a misleading error message.

Doc Impact:

There is no doc impact.

3 25.1.100
37426620 SCP scp-subscription pod is generating WARN messages with "{Response is Successful but NO BODY found}"

In SCP 24.2.1, the SCP-Subscription pod generated WARN messages {Response is Successful but NO BODY found}".

Doc Impact:

There is no doc impact.

3 24.2.1
37407917 "Max Retry Attempts field" is saved as zero value in Routing options of Mediation tab.

When saving routing options in the Mediation tab, the "Max Retry Attempts" field was stored as a zero value, even if a different value was entered.

Doc Impact:

There is no doc impact.

3 25.1.100
36173358 SCP Unable to forward notification requests when request is received with FQDN at profile level and DNS is not configured to resolve the FQDN.

When a notification request was received with a Fully Qualified Domain Name (FQDN) at the profile level and the DNS was not configured to resolve the FQDN, SCP was unable to forward the request.

Doc Impact:

There is no doc impact.

3 23.3.0
38157537 SCP notification pod in CrashLoopBackOff state after OCCNE upgrade from 24.2.3 to 24.2.6

After upgrading CNE from 24.2.3 to 24.2.6, SCP-Notification pod entered a CrashLoopBackOff state, despite functioning correctly before the upgrade.

Doc Impact:

There is no doc impact.

3 24.2.3
38157409 SCP Worker pod continuous restarts due to Traffic Feed stackTrace java.lang.StringIndexOutOfBoundsException: begin 7, end 4

The SCP-Worker pod continuously restarted due to a Traffic Feed stack trace error, specifically a java.lang.StringIndexOutOfBoundsException with begin index 7 and end index 4.

Doc Impact:

There is no doc impact.

3 24.2.3
38143198 SCP not allowing to edit NRF record in NRF SRV configuration

SCP did not allow to edit NRF record in the NRF SRV configuration.

Doc Impact:

There is no doc impact.

3 25.1.100
38116473 Enhancement in metric ocscp_metric_scp_generated_response_total to get pegged for timeout and connection error from mediation ms.

The ocscp_metric_scp_generated_response_total metric did not accurately reflect timeout and connection errors from the mediation service, leading to incomplete data representation.

Doc Impact:

There is no doc impact.

3 24.2.0
38111599 Envoy filter configuration section needs to be corrected in 25.1.200 user guide of SCP

In the 25.1.200 Oracle Communications Cloud Native Core, Service Communication Proxy Installation, Upgrade, and Fault Recovery Guide, name and type fields were incorrectly documented for ASM configuration to allow the XFCC header.

Doc impact:

Updated the name and type fields for ASM configuration to allow the XFCC header in the "Deployment Configurations" section in Oracle Communications Cloud Native Core, Service Communication Proxy Installation, Upgrade, and Fault Recovery Guide.

3 25.1.100
38109905 ATS scenario is failing because duplicate registration observed on setnrfl1.nrfset.5gc.mnc012.mcc345 nrf post migration

Duplicate registrations were observed on the NRF setnrfl1.nrfset.5gc.mnc012.mcc345 after migration, causing the ATS scenario to fail.

Doc Impact:

There is no doc impact.

3 25.1.100
38073526 OCI threshold API returns error despite putting correct data.

The OCI threshold API returned an error when provided with accurate data, preventing successful threshold configuration.

Doc Impact:

There is no doc impact.

3 25.1.100
38034923 SCP User guide discrepancies

The metrics with dimension ocscp_nf_service_name were not updated to use ocscp_nf_service_type in Oracle Communications Cloud Native Core, Service Communication Proxy User Guide.

Doc impact:

Replaced the dimension ocscp_nf_service_name with ocscp_nf_service_type in the "Metrics" section in Oracle Communications Cloud Native Core, Service Communication Proxy User Guide.

3 24.3.0
38030151 NrfBootStrapInfo: Heartbeat request is happening with old replaced nrf

SCP sent heartbeat requests using an outdated NRF instance that was replaced.

Doc Impact:

There is no doc impact.

3 25.1.100
38025580 NrfBootStrapInfo: Audit is happening with the old replaced nrf

During the audit process, SCP referenced outdated NRF information was previously replaced.

Doc Impact:

There is no doc impact.

3 25.1.100
37987680 On Dual stack setup, service entry for foreign SCP profile is getting created with ipv4 only.

In a dual stack setup, the service entry for a foreign SCP profile was incorrectly created using only IPv4, despite SCP's capability to support both IPv4 and IPv6.

Doc Impact:

There is no doc impact.

3 25.1.100
37954103 SCP not able to register mate SCP profile if capacity is not present in profile

SCP failed to register a secondary profile when the associated primary profile lacked the required capacity.

Doc Impact:

There is no doc impact.

3 25.1.100
37511517 During SCP overload scenario(200%), Request and Response processing time for SCP exceeded 2 seconds

While performing upgrade and rollback operations between SCP 23.4.x and 24.2.x, the request and response processing time exceeded the expected limit of 10 seconds.

Doc Impact:

There is no doc impact.

3 24.2.3
37779596 Error Message summary needs to be corrected in CNCC for NF Service Config Set

The Error Message summary required correction on the CNC Console for NF Service Config Set.

Doc impact:

There is no doc impact.

4 25.1.100
37779565 ocscp_notification_nf_profile_rejected_total metrics pegged with internal error in case of received invalid notification with mandatory parameter missing in request

The ocscp_notification_nf_profile_rejected_total metric remained pegged with an internal error when an invalid notification was received with a mandatory parameter missing in the request.

Doc Impact:

There is no doc impact.

4 25.1.100
37697207 Api root header with ipv6 without square bracket and no port gives 500.

When an API root header contained an IPv6 address without square brackets and no specified port, it returned response 500.

Doc Impact:

There is no doc impact.

4 25.1.100
37690826 Exceptions list is not updating properly under nextHopSEPP when one exception is passing the list

When one exception was passing through the list, the exceptions list under nextHopSEPP was not updated.

Doc Impact:

There is no doc impact.

4 25.1.100
37659775 clarification for Side Car Proxy Server Header

The following sidecar proxy server header behavior was observed: "SCP responds to client with “503” and "envoy" as server header".

Doc impact:

Added the "Understanding sideCarProxyServerHeader and sideCarProxyStatusCode Configurations" subsection in Oracle Communications Cloud Native Core, Service Communication Proxy REST Specification Guide.

4 23.4.3
37648525 Then Vender Specific Error ID for error resulted because of ConnectionFailed due to jetty client and ConnectionTimeout at SCP are same

A Vendor Specific Error ID was triggered due to a connection failure between Jetty client and SCP. The failure was caused by a connection timeout, and the error IDs for both the Jetty client and SCP were identical.

Doc impact:

Updated the Error ID OSCP-WRK-ROUTE-E002 in "Table 3-6 SCP-Worker Microservice Error IDs" in Oracle Communications Cloud Native Core, Service Communication Proxy User Guide.

4 25.1.100
37615522 Two subscription requests are sent for UDM, with TSI as NRF for UDM and LOCAL for the other NFs, in the upgrade setup from 24.3.0 to 25.1.100

During an upgrade from SCP 24.3.0 to 25.1.100, two subscription requests were sent to the UDM. One request used TSI as the NRF for the UDM, while the other used LOCAL for the remaining NFs.

Doc Impact:

There is no doc impact.

4 25.1.100
37585269 Error Message needs to be corrected on the Console GUI while configuring Consumer Info configuration

An incorrect error message appeared on the CNC Console when configuring Consumer Info configuration.

Doc Impact:

There is no doc impact.

4 25.1.100
37505826 SCP CNCC, NF Discovery Response Cache Configuration Rule screen should a have visible column for added Exclude Discovery Query Parameters

On the CNC Console, the NF Discovery Response Cache Configuration Rule section did not have a column to view added Exclude Discovery Query parameters.

Doc Impact:

There is no doc impact.

4 25.1.100
37407899 SCP returns incorrect error while modifying NRF Profile on SCP

When modifying an NRF profile on SCP, an incorrect error message was returned.

Doc Impact:

There is no doc impact.

4 25.1.100
37309676 dnnList missing from pcfInfo in PCF profile on CNCC GUI

In SCP 24.2.1, the dnnList field was missing from the pcfInfo section in the PCF profile when viewed on the CNC Console.

Doc Impact:

There is no doc impact.

4 25.1.100
37273615 SCP returns 500 internal error in case of action parameter missing from approuting options REST API request

When the action parameter was missing from the approuting options REST API request, SCP returned a 500 internal error.

Doc Impact:

There is no doc impact.

4 25.1.100
37043138 Getting ocscp_nf_setid as UNKNOWN instead of nf_setid of PCF in the metric ocscp_metric_http_rx_res_total

The ocscp_metric_http_rx_res_total metric displayed ocscp_nf_setid as UNKNOWN instead of the expected nf_setid of PCF.

Doc Impact:

There is no doc impact.

4 24.3.0
36714066 SCP OCI Recovery Validity Period Description in Console UI needs to be updated.

The description for SCP OCI Recovery Validity Period on the CNC Console required an update.

Doc Impact:

There is no doc impact.

4 24.2.0
38043000 Service Group Configuration for CHF

In SCP 24.3.0, the service group configuration for CHF was found to be incorrect.

Doc impact:

Removed the "Configuring Service Groups Parameters" section from Oracle Communications Cloud Native Core, Service Communication Proxy User Guide.

4 24.3.0
37304141 nsiList values showing as NULL on CNCC GUI despite being set in SCP

The nsiList values appeared as NULL on the CNC Console, even though they were correctly set in SCP.

Doc Impact:

There is no doc impact.

4 25.1.100
37976004 SCP ATS Overall Results Report Misspells Feature as Featue

In SCP-ATS 25.1.100, the Overall Results Report incorrectly spelled "Feature" as "Featue."

Doc Impact:

There is no doc impact.

4 25.1.100
37966147 http and https port default needs to be updated in SCP installation guide

Oracle Communications Cloud Native Core, Service Communication Proxy Installation, Upgrade, and Fault Recovery Guide contained incorrect default port information for HTTP and HTTPS.

Doc impact:

Updated the port numbers of scpProfileInfo.scpInfo.scpPorts.https and scpProfileInfo.scpInfo.scpPorts.http Helm parameters in the "Global Parameters" section of Oracle Communications Cloud Native Core, Service Communication Proxy Installation, Upgrade, and Fault Recovery Guide.

4 25.1.100
37869819 Put request for NFServiceConfig doesn't trigger reconfiguration for old NFType/NFService

A PUT request for NFServiceConfig failed to trigger reconfiguration when the request involved an older NFType or NFService.

Doc Impact:

There is no doc impact.

4 25.1.100
37930930 SCP User Guide - Table A-1 HTTP Status Code Supported on SBI

The HTTP status codes supported on the SBI interface were not correctly updated in Oracle Communications Cloud Native Core, Service Communication Proxy User Guide.

Doc impact:

Updated the "Table A-2 Additional Status Codes Applicable for Reroute Condition List (reRouteConditionList) " with correct HTTP status codes in Oracle Communications Cloud Native Core, Service Communication Proxy User Guide.

4 25.1.100

Note:

Resolved bugs from 24.2.4 and 24.3.0 have been forward ported to Release 25.1.200.

Table 4-33 SCP ATS 25.1.200 Resolved Bugs

Bug Number Title Description Severity Found in Release
38128249 SCP0015 WS1.5 failed SCP_Subscription_SubscriptionWithNRFforNfTypeUDM_P0 - 062725 The test case failed while validating the nrf_subscription_delete request.

Doc Impact:

There is no doc impact.

3 25.1.100
38128999 SCP0015 WS1.5 failed SCP_EgressRateLimitingRelease16_AUSF_P0 - 062725 The scenario scenario-1_RateLimitingEgressAlternateRouteReverseLookup failed due to the metric metricfAUSF3 returning a value of 601 instead of 600. All the configurations were correct, but the test case failed due to the metric count exceeding the expected value.

Doc Impact:

There is no doc impact.

3 25.1.100

4.2.10 SEPP Resolved Bugs

Release SEPP 25.1.204

Table 4-34 SEPP 25.1.204 Resolved Bugs

Bug Number Title Description Severity Found in Release
39427362 SEPPConnectionFailureN32IGWAlert label did not expose the error_reason label in the metric.

The SEPPConnectionFailureN32IGWAlert did not expose the expected error_reason label.

Doc Impact:

There is no doc impact.

3 25.1.201
39522482 PN32F returned a 504 Gateway Timeout error in an incorrect format.

PN32F returned a 504 Gateway Timeout response in a non-JSON/problem-details format when PLMN egress gateway pods were down, causing remote-end error-handling and debugging issues.

Doc Impact:

There is no doc impact.

3 25.1.203
39253432 CAT 2 support for two-digit MNC values represented with a leading zero A backward-compatibility option was added for N32-c PLMN validation so an MNC such as 031 could match the configured value 31, while retaining existing CAT2 behavior. The n32cHandshakeStrictMncMatchEnabled flag was added to custom-values.yaml.

Doc Impact:

Added the new parameter in the cn32f and pn32f sections of Oracle Communications Cloud Native Core, Security Edge Protection Proxy Installation, Upgrade, and Fault Recovery Guide.

3 25.1.201

Release SEPP 25.1.203

Table 4-35 SEPP 25.1.203 Resolved Bugs

Bug Number Title Description Severity Found in Release
38544007 SEPP Cat-2 validation on CSEPP failing with PLMN MNC validation with 2 digits.

Cat-2 validation failed for servingNetworkName when a 2-digit MNC was represented with leading zero padding as mnc042 (Example: 5G:mnc042.mcc999.3gppnetwork.org). In this case, SEPP did not correctly normalize and validate the PLMN during body checks, causing valid inbound roaming requests to fail Cat-2 PLMN validation. The issue occurred only in this specific edge-case scenario; all other Cat-2 validation scenarios with 2- and 3-digit MNCs behaved as expected. This was a separate edge case and not a gap in the original fix.

Doc Impact:

There is no doc impact.

(Back ported form 25.2.200 Release)
3 25.1.201
38808302 Configuration guidance requested for DNS-SRV and N32 Ingress traffic.

A DNS-SRV/Remote SEPP Set handling inconsistency was reported where inbound traffic from a SEPP that was not in the Remote SEPP Set (but shared the same virtual host) returned HTTP 500, and outbound behavior was also unclear. This configuration and processing inconsistency affected DNS-SRV–based Remote SEPP routing, particularly in N32 ingress scenarios, where traffic from a valid peer sharing the same virtual host could be incorrectly rejected.

Doc Impact:

There is no doc impact.

(Back ported form 25.2.200 Release)
3 25.1.201
38943638 OCSEPP 25.1.202 Roaming Hub SEPP sending plmnIdList with null value in the n32c-handshake.

In SEPP 25.1.202, the N32C handshake payload incorrectly sent plmnIdList as null. This was flagged as non-compliant with 3GPP TS 29.573, which expected plmnIdList to be an array type (that is, the field should have been absent or set to []). As a result, the handshake message structure could be interpreted as invalid by peers performing strict schema validation.

Doc Impact:

There is no doc impact.

3 25.1.201
38850450 SEPP 25.1.201 - RSS config allowed not matching Remote SEPP Name resulting in routing behavior. The Primary SEPP name configured in RSS was compared using case-sensitive matching, so entries such as GROUPSEPP, groupsepp, and GroupSEPP were not consistently treated as the same value. As a result, the correct route was not selected and routing/N32f flow could fail.

Doc Impact:

There is no doc impact.

(Back ported form 25.2.200 Release)
4 25.1.201
38816683 OCSEPP | REST Specification Guide | Table 2-16 Logging Rest API needs to be corrected and updated. The REST Specification Guide contained a typo in the Logging REST API example where the endpoint path was incorrectly shown as cn32 instead of cn32c, and it lacked example commands for several common services. As a result, users could have followed incorrect endpoints or had insufficient guidance to perform standard logging operations via the REST API.

Doc Impact:

Updated Logging REST API in the Oracle Communications Cloud Native Core, Security Edge Protection Proxy REST Specification Guide.

(Back ported form 25.2.200 Release)
4 25.1.203

Release SEPP 25.1.202

Table 4-36 SEPP 25.1.202 Resolved Bugs

Bug Number Title Description Severity Found in Release
38360262 Multipart Message boundary req header format causing 500 internal error in pn32f.

The PN32F microservice rejected multipart messages with certain formats of the boundary req header value and returned a 500 Internal Server Error. Support for all special characters in the multipart boundary was added.

Doc Impact:

There is no doc impact.

2 25.1.201
38343926 SEPP 24.3.2 //25.1.200 does not honor NF profile capacity parameter set by user

The NRF client did not honor the SEPP Profile capacity value specified by the user and instead defaulted it to 100.

By default, the NFProfile was set in Helm mode; therefore, the load and capacity variables were fetched from the perf-info service instead of the NFProfile. As a result, the default value of 100 was updated in the NFProfileUpdate and sent to the NRF. The code was updated to pick the correct value.

Doc Impact:

Addd the new three parameters in the perf-info section of Oracle Communications Cloud Native Core, Security Edge Protection Proxy Installation, Upgrade, and Fault Recovery Guide.

3 24.3.2
38404940 Proactive status feature enabled but requests are no being sent.

The SEPP Egress Gateway was not sending out the Proactive Health Check OPTIONS request, even though it was part of the RS Profile in the DB. When the proactive monitoring feature was enabled for a peer and the config-mgr-svc pod was restarted, the parameters "healthApiPath" and "healthApiMethod" were removed from the peer configuration of the N32 Egress Gateway.

This issue occurred because, when the config-mgr-svc pod was restarted, the application synced with the gateway peers again after 120 seconds. During this sync, the config-mgr did not include the health API parameters, which led to their removal from the peer configuration.

Doc Impact:

There is no doc impact.

3 25.1.200
38489528 Several SEPP metrics not working correctly with standardized dashboard json prometheus feeds for grafana.
There were discrepancies and issues with the metrics in the
ocsepp_dashboard_25.1.200
file. The file was updated with the correct labels for the affected metrics.

Doc Impact:

Updated the metrics dashboard name in the Oracle Communications Cloud Native Core, Security Edge Protection Proxy User Guide.

3 25.1.201

Release SEPP ATS 25.1.202

Table 4-37 SEPP ATS 25.1.202 Resolved Bugs

Bug Number Title Description Severity Found in Release
38391070 SEPP and SEPP ATS 25.1.201 Package Concern.

When performing a yaml safe load of the Entry-Definitions in the TOSCA meta while processing the CSAR, the following error occurred:

ERROR: A character '\t' was found that could not start any token in "Definitions/ocats_ocsepp.yaml", line 42, column [number].

Doc Impact:

There is no doc impact.

3 25.1.201

Release SEPP 25.1.201

Table 4-38 SEPP 25.1.201 Resolved Bugs

Bug Number Title Description Severity Found in Release
38187650 CAT1 Feature Alerts are not coming in Prometheus GUI after sending invalid calls.

Alerts for the Cat-1 NRF Service API Query Parameters Validation feature were not triggering, despite error thresholds being exceeded during testing. This was due to the alert interval being incorrectly set to one minute in the alert configuration file.

Doc Impact:

Updated the alert expressions of Cat-1 NRF Service API Query Parameters Validation alerts in the Oracle Communications Cloud Native Core, Security Edge Protection Proxy User Guide.

3 25.1.100
38201407 SEPP mediation use case not mediating HTTP Status Code

The requirement was to mediate the HTTP status code for a response with "400 Bad Request" and convert it to "200 OK". The pn32f microservice sent the "x-original-status" header along with the 400 Bad Request to the mediation layer, which successfully updated the header and returned the response to pn32f. However, pn32f did not update the HTTP status code based on the new "x-original-status" value; instead, it simply appended the new "x-original-status" header without changing the original status code.

Doc Impact:

Added a note about the x-original-status header to the Custom Headers section of 5G SBI Message Mediation Support feature in Oracle Communications Cloud Native Core, Security Edge Protection Proxy User Guide.

3 25.1.100
38211747 SEPP 25.1.200 GA Package has incorrect cnDBTier CV file - RC4 File used instead In the 25.1.200 SEPP GA Artifacts/Scripts directory, the cnDBTier custom values file in use was ocsepp_dbtier_25.1.200_custom_values_25.1.200.yaml, which was incorrectly based on a pre-GA version. As per the deployment standards and release guidelines, the correct GA version of the cnDBTier custom values file should have been used.

Doc Impact:

There is no doc impact.

4 25.1.200
38198678 namespace hardcoded to sepp-namespace for pod status check alerts

In the SEPP User Guide,a note should have instructed users to update the sepp-namespace in alert file to the actual namespace where SEPP was deployed was missing. The absence of this information prevented all newly added alerts from being raised correctly.

Doc Impact:

Added a note to the Alert Configuration section of the Oracle Communications Cloud Native Core, Security Edge Protection Proxy User Guide.

4 25.1.200

Release SEPP ATS 25.1.201

Table 4-39 SEPP ATS 25.1.201 Resolved Bugs

Bug Number Title Description Severity Found in Release
38196990 ATS feature files are failing on ATS release 25.1.200 with Webscale 1.3(k8 1.20)

ATS feature files were failing on ATS Release - 25.1.200. For PSEPP side cases, a Kubernetes service was created to retrieve the ipFamilies configuration from the stubserver-1 service. Based on this configuration, a new service was created with the same IP family settings. However, since Kubernetes version 1.20 did not support dual-stack networking, the ipFamilies field was not populated in the stubserver-1 service. This resulted in a KeyError when attempting to access service_yaml['spec']['ipFamilies']. The code was fixed to work on Kubernetes versions that did not support dual-stack networking.

Doc Impact:

There is no doc impact.

2 25.1.200

Release 25.1.200

Table 4-40 SEPP 25.1.200 Resolved Bugs

Bug Number Title Description Severity Found in Release
37738503 SEPP returns 500 error, instead of configured one, when timestamp format does not meet the requirement

When the Cat-3 Previous Location Check feature was enabled, the authentication-status response from the UDR included a timestamp in the format "timeStamp": "2018-01-02T08:17:14Z", which did not include milliseconds. As a result, the SEPP returned a 500 Internal Server Error instead of the expected 406 status code.

Doc Impact:

There is no doc impact.

3 25.1.100
37744123 Intermittent NPE reported in pn32f logs at 10 TPS when Cat3 time check is enabled

A Null Pointer Exception was intermittently reported in pn32f logs when the Cat-3 Time Check for Roaming Subscribers feature was enabled and traffic was at 10 transactions per second (TPS).

Doc Impact:

There is no doc impact.

3 25.1.100
37669351 Need assistance to test Health Check Feature

When the peer monitoring configuration was modified, the SCP Health Check request rate increased. This behavior could be tracked using an alert expression rate(oc_egressgateway_peer_health_ping_request_total {namespace=~"namespace"}[2m]).

Doc Impact:

There is no doc impact.

Related Bug:

Gateway bug: 37727221

3 24.3.1
37755073 Too many TCP connections from SEPP to UDM

The PLMN Egress Gateway established a very high number of TCP connections towards the outbound Network Function UDM. This issue occurred because the PLMN Egress Gateway was opening a new TCP connection with almost every new request when the Jetty idle timeout was set to 0.

Doc Impact:

Added the note to the jettyIdleTimeout parameter in the "Timer Parameters" section in Oracle Communications Cloud Native Core, Security Edge Protection Proxy Installation, Upgrade, and Fault Recovery Guide.

Related Bug:

Gateway bug: 37765399

3 24.3.1
37680589 SEPP TUH header path for deregistration notification does not work

SEPP failed to perform TUH (Topology Recovery) for NFInstanceId in the deregistration notification header path from the UDM to the AMF. SEPP did not perform TUH on the header path for the deregistration-notification callback.

Doc Impact:

Updated the path configurations in the "Topology Hiding" section in Oracle Communications Cloud Native Core, Security Edge Protection Proxy User Guide.

3 24.2.1
37514476 Message schema validation failing in SEPP

With the Cat-0 SBI Message Schema Validation feature enabled, the SEPP blocked requests sent from the visiting AMF to the Home UDM through the SEPP for the /nudm-sdm/v2/{supi} endpoint, returning a 406 error. The issue was raised because the SEPP's message validation schema was expected dataset-names to be enclosed in square brackets ([]). A similar issue was observed for the /nnrf-disc endpoint. However, according to 3GPP TS 29.501, dataset-names it is defined as an array of simple types, and the specification does not require square brackets or double quotes for formatting.

Doc Impact:

There is no doc impact.

3 24.2.0
37499126 Ratelimit failing when header contains srcinfo

The header validation failed when the source information was included in the header. However, the validation succeeded when only the origin PLMN was present in the header.

Failing Header:

3gpp-sbi-originating-network-id: 310-014; src: SEPPsepp001.sepp.5gc.mnc014.mcc310.3gppnetwork.org

Working Header:

3gpp-sbi-originating-network-id: 310-014

Doc Impact:

There is no doc impact.

3 23.1.1
37623689 SEPP 24.3.0 ATS CV file should not expose password

The ATS custom values file previously exposed passwords in the custom-values.yaml file. This issue was resolved by updating the ATS charts to ensure passwords are no longer exposed.

Doc Impact:

There is no doc impact.

3 24.3.0
37916233 Update the SEPP ATS Guide. to add the withEnv configurations in the pipeline script

An error occurred when using customized ATS pipelines for SEPP NewFeatures and Regression. To resolve this issue, specific environment variables must be configured.

Doc Impact:

Added the following environment variables in Oracle Communications Cloud Native Core, Automated Test Suite User Guide:

withEnv([
  'TestSuite=Regression',
  'Execute_Suite=SEPP',
  'FilterWithTags=true,false',
  'Fetch_Log_Upon_Failure=NO',
  'Select_Features_Option=All',
  'Configuration_Type=Custom_Config'
])
3 25.1.100
37870171 CNDB metrics and alerts are not being fetched in Prometheus for the Hardhead1 cluster, and the corresponding namespace is not visible in the Grafana dashboard

Prometheus was not collecting CNDB-related metrics, which prevented CNDB alerts from firing.

Doc Impact:

Updated the traffic.sidecar.istio.io/excludeInboundPorts: "8081,8080 exclusion in CNDB pods, as specified in Oracle Communications Cloud Native Core, cnDBTier User Guide in Oracle Communications Cloud Native Core, Security Edge Protection Proxy Installation, Upgrade, and Fault Recovery Guide.

3 25.1.100
37587256 Request guidance on how to accommodate for 2 and 3 digit MNCs for CAT2 screening in SEPP

In the Cat-2 Network ID Validation feature, rules were defined to filter specific requests. When configuring these rules, the length of the Mobile Network Code (MNC) had to be specified as either 2 or 3. Since there was only one rule for both directions, if the MNC lengths differed between the two countries, the filtering rule failed to work for one direction.

Doc Impact:

Updated the "Cat -2 Network ID Validation Feature" section with information about fetching MNC length from PLMN table in Oracle Communications Cloud Native Core, Security Edge Protection Proxy User Guide.

3 24.3.0
38059326 Overload is enabled by default in CV, causing exceptions in IGW pod logs
By default, the following flag was enabled in the ocsepp_custom_values_<version>.yaml:
overloadManager:
  enabled: true
  nfType: 'sepp'
  ingressGatewaySvcName: n32-ingress-gateway
  ingressGatewayPort: 80

This caused multiple exceptions in the n32-ingress-gateway pods because the feature was enabled, but the necessary configurations were not present.

Doc Impact:

The default value for the overloadManager.enabled is changed to false in Oracle Communications Cloud Native Core, Security Edge Protection Proxy Installation, Upgrade, and Fault Recovery Guide.

3 25.1.100
37855789 coherence service log level change is not exposed via REST and CNCC

The log level for the Coherence service could not be changed through REST or CNC Console because the configuration option was not exposed. This prevented users from adjusting the log level as needed.

Doc Impact:

There is no doc impact.

3 25.1.100
37670498 ERROR LOG in SEPP config manager pod and Performance pod

Continuous Error logs were observed in the SEPP config-manager pod and performance pod.

  • Config Manager Pod Logs: The pod continuously generated ERROR logs related to connector/J, suggesting the use of autoreconnect=true due to client timeout issues.
  • Performance Pod Logs: The pod was incorrectly sending curl requests to the n32-igw service on port 80, which was not exposed by the service.

Doc Impact:

There is no doc impact.

4 24.2.1
37720757 different validation for mcc on CNCC and REST for MCC Exception list

Different validation rules for the Mobile Country Code (MCC) were applied in CNC Configuration and REST API for the MCC Exception list. While CNC Configuration performed the validation correctly, the REST API accepted MCC values starting with 0, when triggered directly, which was incorrect.

Doc Impact:

There is no doc impact.

4 25.1.100
36605004 OCSEPP: During installation SEPP 24.1.0 unwanted warnings are observed.

During SEPP deployment, warnings were thrown, although the deployment was successful. These warnings originated from the mediation common service and were related to attempts to overwrite table values with non-table data for the following configurations:

  • ocsepp.k8sResource.container.prefix
  • ocsepp.k8sResource.container.suffix
  • ocsepp.nf-mediation.global.k8sResource.container.prefix
  • ocsepp.nf-mediation.global.k8sResource.container.suffix

Doc Impact:

There is no doc impact.

4 24.1.0
37475488 Get request for non-existing trigger list has different behavior for Cat3 and Cat0/Cat1/Cat2

A GET request for a non-existing list had inconsistent behavior across different categories. For Category 3 (Cat-3), SEPP responded with a 404 Not Found status, while for Categories 0, 1, and 2 (Cat-0/Cat-1/Cat-2), it responded with a 200 OK status.

Doc Impact:

There is no doc impact.

4 25.1.100
37531696 coherence service logs are being printed at the DEBUG level even though the log level is set to INFO.

Coherence service logs were being printed with the label DEBUG despite the log level being set to INFO in both ocsepp_custom_values_<version>.yaml file and deployment configurations. This resulted in unnecessary flooding of logs.

Doc Impact:

Updated the default value of coherence-svc.log.root and coherence-svc.log.sepp parameters to ERROR in the Coherence section in Oracle Communications Cloud Native Core, Security Edge Protection Proxy Installation, Upgrade, and Fault Recovery Guide.

4 25.1.100
37553652 GET request for topology hiding header config is responded with status code 201

A GET request for the topology hiding header configuration returned an HTTP status code of 201. According to the specification, the status code for a GET request should be 200 OK instead of 201. This discrepancy caused the HTTP response status code to deviate from the expected behavior.

Doc Impact:

Added the REST API details for header and body GET request for configuring Topology Hiding feature in Oracle Communications Cloud Native Core, Security Edge Protection Proxy REST Specification Guide.

4 25.1.100
37647484 Next-hop header with wrong value

The next-hop header for n32f traffic did not contain the correct Fully Qualified Domain Name (FQDN). Upon analysis, it was determined that the x-next-hop header, a custom header, was not being used in n32f traffic routing. As a result, this header was removed when n32f traffic was exchanged to resolve the issue.

Doc Impact:

There is no doc impact.

4 24.3.1
37713281 "Blocklist Refresh Time Unit" default value is blank even though it is mandatory

The Blocklist Refresh Time Unit field had a blank default value, despite being a mandatory field. This caused the Cat-3 Time Check options page to fail to save when using default configurations. The issue stemmed from the absence of a default value for this field.

Users were unable to save the Cat-3 Time Check for Roaming Subscribers options page with default values due to the missing default value for "Blocklist Refresh Time Unit."

Doc Impact:

Updated the Cat-3 Time Check for Roaming Subscribers feature section with information about blocklist functionality In Oracle Communications Cloud Native Core, Security Edge Protection Proxy User Guide.

4 25.1.100
37713498 Default value of "Average Flight Velocity (km/hr)" should be realistic value

The default value for "Average Flight Velocity (km/hr)" was set to 1,20,000, which was unrealistic and could lead to misconfiguration. The default value was updated to a more realistic figure to prevent potential issues.

Doc Impact:

The default value of Average Flight Velocity is set as 12000 km/hr in the Cat-3 Time Location Check for Roaming Subscribers section of Oracle Communications Cloud Native Core, Security Edge Protection Proxy User Guide and Oracle Communications Cloud Native Core, Security Edge Protection Proxy REST Specification Guide.

4 25.1.100
37720181 detail and cause attribute shall be updated in response if mcc is invalid

In the Cat-3 Time check feature, when a wrong MCC (Mobile Country Code) was provided in the configuration, the response included misleading information in the cause and detail attributes. The response incorrectly stated that the MCC could be between 0 and 3, which was not accurate.

Doc Impact:

There is no doc impact.

4 25.1.100
37834640 content-type http header is being sent in case TimeCheck is failed with 200 response code

During a failed Cat-3 Time Check scenario, the system incorrectly sent a Content-Type HTTP header with a 200 response code. The issue occurred when an authentication request with SUPI was sent to the UDR, but the request failed due to the UDR being down, resulting in an exception. The SEPP returned a 200 OK response as configured for the consumer. While the response body was empty, the presence of the Content-Type header misleadingly suggested that a body was included.

Doc Impact:

There is no doc impact.

4 25.1.100
37854672 Critical alert criteria for Cat3 Time check feature shall be updated

Critical alert criteria for Cat-3 Time Check feature shall be updated. Critical alert criteria for Cat3 Time check feature shall be updated. Only minimum criteria shall be there, not the upper limit for critical alert. If the failures are more than 3000 in the given window, then the critical alert won't be raised. Hence the upper limit shall be removed.

Alert names: pn32fTimeUnauthLocChkValFailAlrtCritical and pn32fTimeUnauthLocChkExcepFailAlrtCritical

Criteria for critical alerts:
  • ocsepp_time_unauthenticated_location_exception_failure_total offset 2m) <= 3000
  • ocsepp_time_unauthenticated_location_validation_failure_total offset 2m) <= 3000

The critical alert criteria for the Cat-3 Time Check feature were updated. The criteria now include only a minimum threshold, removing the upper limit for critical alerts. If the number of failures exceeds 3000 within the specified window, a critical alert will not be raised. This change applies to the alerts named pn32fTimeUnauthLocChkValFailAlrtCritical and pn32fTimeUnauthLocChkExcepFailAlrtCritical.

The updated criteria for critical alerts are as follows:

  • ocsepp_time_unauthenticated_location_exception_failure_total (offset 2m) <=3000
  • ocsepp_time_unauthenticated_location_validation_failure_total (offset 2m) <=3000

Doc Impact:

Updated the expressions of the following alerts in the "Cat-3 Time Check for Roaming Subscribers Alerts "section of Oracle Communications Cloud Native Core, Security Edge Protection Proxy User Guide:

  • pn32fTimeUnauthLocChkValFailAlrtCritical
  • pn32fTimeUnauthLocChkExcepFailAlrtCritical
4 25.1.100
37880515 peer_domain dimention is not getting dumped in "ocsepp_time_unauthenticated_location_blacklist_requests_total"

In previous releases, the metric ocsepp_time_unauthenticated_location_blacklist_requests_total did not include the peer_domain dimension, despite the User Guide specifying that it should be present. This issue was resolved by adding the peer_domain value to the metric, ensuring compliance with the documentation.

Doc Impact:

There is no doc impact.

4 25.1.100
38011729 SEPP GET configuration returns 201 Created for TH query

During testing of SEPP release 25.1.100, it was observed that a GET command to a specific REST API resource incorrectly returned a 201 Created response code. This behavior is unexpected, as a GET request should typically return a 200 OK response code when the resource is successfully retrieved.

Doc Impact:

Updated the REST API details in the "Topology Hiding" section in Oracle Communications Cloud Native Core, Security Edge Protection Proxy REST Specification Guide.

4 25.1.100
37902132 Missing "s" on response for ocsepp_pn32f_response_total

In the sepp_Customconfigtemplates_24.3.1.zip file, the metric name ocsepp_pn32f_response_total was incorrectly spelled without the final "s" in the files ocsepp_dashboard.json and ocsepp_dashboard_promha.json. The correct metric name should be ocsepp_pn32f_responses_total. This issue was present in the following lines:

  • ocsepp_dashboard.json:

    • Line 1291: "expr": "(sum(ocsepp_pn32f_response_total)/sum(ocsepp_pn32f_requests_total))*100"
    • Line 1539: "expr": "sum(irate(ocsepp_pn32f_response_total[2m]))"
  • ocsepp_dashboard_promha.json:

    • Line 5563: "expr": "sum((ocsepp_pn32f_response_total{namespace=~\"$Namespace\"}))by(app,status_code)"

Doc Impact:

There is no doc impact.

4 24.3.1
37987985 Apply CNCESSEPP-849 fix to all cat3 time check metrics

The peer_domain dimension was added to all Cat-3 Time Check for Roaming Subscribers metrics, and the correct value was populated for this dimension. This update ensures that the metrics accurately reflect the peer_domain information.

Doc Impact:

There is no doc impact.

4 25.1.100
37719644 response for an invalid value of "avgFlightVelocity" in the configuration is incorrect

When an invalid value for the avgFlightVelocity parameter was provided in the configuration, the system incorrectly returned a 400 response code instead of the configured response code. Additionally, the Content-Type header in the response was set to application/json, whereas it should have been application/problem+json to comply with the expected format for error responses.

Doc Impact:

There is no doc impact.

4 25.1.100
37713670 response for an invalid value of "messageFilteringOnUnAuthLocationEnabled" in the configuration is incorrect

When an invalid value for the messageFilteringOnUnAuthLocationEnabled parameter was provided in the configuration, the system incorrectly returned a 400 response code instead of the configured response code. Additionally, the Content-Type header in the response was set to application/json, whereas it should have been application/problem+json to comply with the expected format for error responses.

Doc Impact:

There is no doc impact.

4 25.1.100
38047999 Description shall be updated for SoR Config Allowed List config

The REST API documentation contained inaccuracies in the table describing the SoR Config Allowed List. Specifically:

  1. The description for the PUT method row was incorrectly stated as "Configures Mediation trigger point configuration for given data."

    This description does not align with the purpose of the SoR Config Allowed List.

  2. In section 2.21, the term "Allowed List" was used instead of the correct term "Trigger Rule List."

The document was updated to correct these issues, ensuring accurate and consistent terminology.

Doc Impact:

Updated the following in Oracle Communications Cloud Native Core, Security Edge Protection Proxy REST Specification Guide:

  • Updated the name of the REST API as SOR Config Trigger Rule List.
  • Updated the description of PUT method in SOR Config Trigger Rule List.
4 25.1.100
38048136 Deleting a non-existing SoR trigger list returns 400 instead of 404

When the DELETE RES API was used to delete a non-existing SoR trigger list, a mismatch was observed between the HTTP response status code and the error message in the response body. The HTTP response status code returned was 400 (Bad Request), while the error message in the response body indicated a 404 (Not Found) status. The error message specifically stated, "404 NOT_FOUND 'sor trigger list Name is missing in DB'."

Doc Impact:

There is no doc impact.

4 25.1.100

Note:

Resolved bugs from 24.3.1 have been forward ported to Release 25.1.100.

4.2.11 UDR Resolved Bugs

Release 25.2.201

Table 4-41 UDR 25.2.201 Resolved Bugs

Bug Number Title Description Severity Found in Release
38732491 UDR Export Tool fails to export subscriber records when profile field contains comma (JSON parsing error)UDR Export Tool fails to export subscriber records when profile field contains comma (JSON parsing error)

The Subscriber Export Tool failed to export subscriber records when a profile field value contained a comma. During export processing, the Subscriber Export Tool incorrectly treated a normal string field as a JSON array and generated a JSON parsing error.

Doc Impact:

There is no doc impact.

2 25.1.201
38420558 Certificate expired ALERT missing in alert.yaml file

The certificate expiry alert was missing in the alert.yaml file for UDR.

Doc Impact:

There is no doc impact.

3 24.2.4
39338837 On the SH interface receiving PUA 5105 diameter response.

UDR returned Profile Update Answer (PUA) result code 5105 for a Profile-Update-Request (PUR) with the correct sequence number after session termination.

Doc Impact:

There is no doc impact.

3 24.2.6

Note:

Resolved bugs from 25.2.100 have been forward-ported to Release 25.2.201

4.2.12 Common Services Resolved Bugs

4.2.12.1 ATS Resolved Bugs

Release 25.1.200

Table 4-42 ATS 25.1.200 Resolved Bugs

Bug Number Title Description Severity Found in Release
37882146 Require refinement in istio-proxy container applogs When application logs were collected for the istio-proxy container, all the logs appeared in a single line, making them unreadable.

Doc Impact:

There is no doc impact.

4 25.1.100
4.2.12.2 ASM Configuration Resolved Bugs

Release 25.2.100

There are no resolved bugs in this release.

4.2.12.3 Alternate Route Service Resolved Bugs

Release 25.1.201

There are no resolved bugs in this release.

Release 25.1.200

There are no resolved bugs in this release.

4.2.12.4 Egress Gateway Resolved Bugs

Release 25.1.201

Table 4-43 Egress Gateway 25.1.201 Resolved Bugs

Bug Number Title Description Severity Found In Release
37574756 Metric occnp_oc_egressgateway_http_requests_total Shows NFServiceType & NFType as "UNKNOWN" for update_notify Request
The
occnp_oc_egressgateway_http_requests_total
metric displayed the
NFServiceType
and
NFType
fields as "UNKNOWN" for
update_notify
requests.

Doc Impact:

There is no doc impact.

3 25.1.200

Release 25.1.200

Table 4-44 Egress Gateway 25.1.200 Resolved Bugs

Bug Number Title Description Severity Found In Release
37685576

Flooded with IRC Exception warn messages in EGW

After editing the traffic.sidecar.istio.io/excludeInboundPorts or traffic.sidecar.istio.io/excludeOutboundPorts values in Egress Gateway deployment and service, occasional IllegalReferenceCountException warning messages were observed, though the issue was not consistently reproducible across multiple runs.

Doc Impact:

There is no doc impact.

2 24.2.11
37828830

Stream ID exhaustion in Jetty will result in stale and unused connection

Jetty experienced stream ID exhaustion, leading to the retention of stale and unused connections.

Doc Impact:

There is no doc impact.

2 25.1.200
37732048 EGW re-route is not happening to alternate SCP, it is re-routing to the same SCP where the error response was received

Egress Gateway failed to re-route requests to an alternate SCP after receiving an error response from the initial SCP.

Doc Impact:

There is no doc impact.

2 25.1.200
37766559 EGW not rerouting request, reporting 'Host already tried' and returning 503 as all peers are ineligible

Egress Gateway failed to reroute a request because it had already attempted the designated host, resulting in a "Host already tried" error.

Doc Impact:

There is no doc impact.

2 25.1.200
37403771

NRF upgrade failed with igw post upgrade hooks in error state

During the NRF upgrade, the process encountered an issue where the Ingress Gateway post-upgrade hooks entered an error state.

Doc Impact:

There is no doc impact.

2 23.4.10
37480520 After successful update of certificate in NRF k8S by OCCM by recreate process new certificate validity is not used in TLS handshake by NRF GWDuring the recreation process initiated by OCCM to update the certificate in the NRF Kubernetes environment, the new

During the recreation process initiated by OCCM to update the certificate in the NRF Kubernetes environment, the new certificate's validity was not utilized in the TLS handshake by NRF.

Doc Impact:

There is no doc impact.

2 25.1.100
37009578

Fix to provide an option to enable use of APIGW custom Jetty code instead of Jetty Library APIs for the Peer Monitoring feature

The Peer Monitoring feature relied on Jetty Library APIs instead of Gateway Services custom Jetty code.

Doc Impact:

There is no doc impact.

2 23.4.4
37559723

EGW not pegging metric occnp_oc_egressgateway_peer_health_status when DNS entries changed untill SCP health status change

The Egress Gateway failed to update the
occnp_oc_egressgateway_peer_health_status
metric when DNS entries were modified, resulting in stale health status information.

Doc Impact:

There is no doc impact.

3 25.1.200
37603838 Metric oc_egressgateway_peer_health_ping_request_total does not increment when switching between dynamic and static peer configuration
The metric
oc_egressgateway_peer_health_ping_request_total
failed to increment when switching between dynamic and static peer configurations.

Doc Impact:

There is no doc impact.

3 25.1.200
37611042

EGW Not Sending Error Response Body for 406 NOT_ACCEPTABLE During SBI Routing.

Egress Gateway did not send error response body for 406 NOT_ACCEPTABLE during SBI routing.

Doc Impact:

There is no doc impact.

3 25.1.100
37642234

After restarting EGW pods multiple times, Prometheus is not showing EGW outgoing connections.

After restarting Egress Gateway pods multiple times, Prometheus failed to display the outgoing connections from the Egress Gateway.

Doc Impact:

There is no doc impact.

3 24.2.4
37529542 Requests rejected by EGW local rate limiting not reflected in main EGW request metrics

Requests that were rejected due to local rate limiting by Egress Gateway were not accurately recorded in the main Egress Gateway request metrics.

Doc Impact:

There is no doc impact.

3 24.2.10
35923113 Incorrect peer Health Status when peerConfiguration consists of virtualHost and peerMonitoring is enabled

Egress Gateway displayed an incorrect peer health status when the peer configuration included a virtual host and peer monitoring was enabled.

Doc Impact:

There is no doc impact.

3 23.3.3
37733235 EGW Peer monitoring service is not working as expected

Egress Gateway peer monitoring service failed to function as intended.

Doc Impact:

There is no doc impact.

3 25.1.200
37780691 Metric oc_egressgateway_http_responses_total - Dimension errorReason changed from "All peers are Unhealthy." to "All peers are Ineligible."
In the
oc_egressgateway_http_responses_total
metric, the
errorReason
dimension incorrectly displayed "All peers are Unhealthy."

Doc Impact:

There is no doc impact.

3 25.1.200
37306243 Incorrect user-agent info sent by EGW , when access-token request sent towards NRF. (But when subsequent request sent towards Producer NF's , EGW properly sent the User-Agent info)

When sending an access-token request to NRF, Egress Gateway incorrectly sent the user-agent information.

Doc Impact:

There is no doc impact.

3 24.2.0
37527834 BlackListing of a Peer (configured as IP:port) in sbiRouting is not happening when reroute attempts is 0

When a peer was configured as an IP:port in sbiRouting, blacklisting did not occur even though the reroute attempts were set to 0.

Doc Impact:

There is no doc impact.

3 25.1.200
37527954 when 3gpp-sbi-target-apiroot and oc-alternateroute-attempt headers are sent in the request the peer selection is inconsistent with oc-alternateroute-attempt header value.
When both
3gpp-sbi-target-apiroot
and
oc-alternateroute-attempt
headers were included in the request, the peer selection did not consistently align with the value specified in the
oc-alternateroute-attempt
header.

Doc Impact:

There is no doc impact.

3 25.1.200
37528604 EGW selects low-priority SCP when higher-priority SCP is available after blacklisting SCP1

Egress Gateway selected a low-priority SCP instead of an available higher-priority SCP after blacklisting SCP1.

Doc Impact:

There is no doc impact.

3 25.1.200
37355062 occnp_oc_egressgateway_peer_health_status reports incorrect peer health from one pod

The occnp_oc_egressgateway_peer_health_status metric inaccurately reported the health status of a peer from one pod.

Doc Impact:

There is no doc impact.

3 23.4.3
37501092 Egress Gateway not retrying to sameNRF or Next NRF when "errorCodes: -1" for errorSetId: 5XX on retryErrorCodeSeriesForNex/SametNrf OauthClient configuration.

Egress Gateway failed to retry requests to the same NRF or the next NRF when encountering an error code of "-1" within the 5XX error set, as specified in the retryErrorCodeSeriesForNext/SameNrf OauthClient configuration.

Doc Impact:

There is no doc impact.

3 24.2.5
37451580 Metric not getting pegged after health ping request is sent towards a peer.

The metric failed to register after a health ping request was sent to a peer.

Doc Impact:

There is no doc impact.

4 24.2.9
35412487

[FORWARD PORTING] Scheduler resiliency feature

During Web-Scale upgrade, scaling down and then scaling up the AM-PCF caused the PCF-EGW to return 500 errors.

Doc Impact:

There is no doc impact.

4 22.4.3
37617517

FQDN scheme probing with Alternate Route Service failed due to strict "scheme" check in EGW

FQDN scheme probing with Alternate Route Service failed because Egress Gateway enforced a strict check on the "scheme" parameter.

Doc Impact:

There is no doc impact.

4 24.2.12
37756514 Pod-protection :- Congestion Configuration refreshInterval default value showing 5000 instead of 500 and Observed NPE if we configure 50000ms

In the pod protection congestion configuration, the default value for refreshInterval was incorrectly displayed as 5000 milliseconds instead of 500 milliseconds.

Doc Impact:

There is no doc impact.

4 25.1.200

Note:

Resolved bugs from 24.2.5 and 25.1.100 have been forward ported to Release 25.1.200.
4.2.12.5 Ingress Gateway Resolved Bugs

Release 25.1.201

Table 4-45 Ingress Gateway 25.1.201 Resolved Bugs

Bug Number Title Description Severity Found In Release
37887251 GW POP25 not able to accept/discard request wrt percentages allocated to each route

The Ingress Gateway Pod Protection using Rate Limiting feature failed to accept or discard requests based on the predefined percentage allocations assigned to each route.

Doc Impact:

There is no doc impact.
2 25.1.200
37733322 PCF is sending Error Code 404 Not Found without any error cause if an invalid URI is present in AM-Create

Policy returned an HTTP 404 Not Found error code without including an error cause when an invalid URI was detected in the AM-Create request.

Doc Impact:

There is no doc impact.
3 25.1.200
37574756 Metric occnp_oc_egressgateway_http_requests_total Shows NFServiceType & NFType as "UNKNOWN" for update_notify Request
The
occnp_oc_egressgateway_http_requests_total
metric displayed the
NFServiceType
and
NFType
fields as "UNKNOWN" for
update_notify
requests.

Doc Impact:

There is no doc impact.

3 25.1.200
37893522 IGW pre upgrade hooks error when convertHelmRoutesToREST flag is set to true and POP25 configs are added in HELM values.yaml
During the pre-upgrade process, Ingress Gateway hooks encountered an error when the
convertHelmRoutesToREST
parameter was enabled.

Doc Impact:

There is no doc impact.

3 25.1.200
34609077 Security issue for reloading certificate

The exposed API (reload or certificate) at the public service port of Ingress Gateway was not secured.

Doc Impact:

There is no doc impact.
3 24.3.0

Note:

Resolved bugs from 24.2.0 have been forward ported to Release 25.1.201.

Release 25.1.200

Table 4-46 Ingress Gateway 25.1.200 Resolved Bugs

Bug Number Title Description Severity Found In Release
37820163 Pod-protection :- Pod protection feature is not functioning when IGW response with 4XX (400 and 404) Result code The pod protection feature failed to function when the Ingress Gateway responded with 4XX (400 and 404) result codes.

Doc Impact:

There is no doc impact.

2 25.1.200
37859082 Pod-protection :- one of the pod struct at congestion level3 state during 53K traffic with 3000 fillrate and 25 replicas During high congestion levels (level 3) with a traffic rate of 53K, a pod structure experienced issues when configured with a fill rate of 3000 and 25 replicas. This configuration led to unexpected behavior in the pod's operation under those specific conditions.

Doc Impact:

There is no doc impact.

2 25.1.200
37859129 Pod-protection :- During 12hrs of run for 53K traffic with fill rate 3000 and 25 replicas multiple exceptions are observed During a 12-hour test run with 53,000 traffic requests, a fill rate of 3,000, and 25 replicas, the pod-protection system encountered multiple exceptions.

Doc Impact:

There is no doc impact.

2 25.1.200
37852033 REST call podProtectionByRateLimiting API failed to update the configuration The REST call to the
podProtectionByRateLimiting
API failed to update the configuration due to an internal processing error.

Doc Impact:

There is no doc impact.

2 25.1.200
37697053 When overload control feature with Local discard is enabled there is approximately 1 percent extra traffic discard as set by the load level When the overload control feature with Local discard was enabled, it increased traffic discard, resulting in approximately 1% more traffic being discarded than the configured load level.

Doc Impact:

There is no doc impact.

2 25.1.200
37359902 Success percentage drops to 47-52% during in-service upgrade/rollback of IGW from 24.3.3 to 25.1.0 and vice-versa During in-service upgrade or rollback between Ingress Gateway 24.3.3 and 25.1.0, the success percentage dropped to 47-52%.

Doc Impact:

There is no doc impact.

2 25.1.100
37669166 IGW is adding wrong format of sbi-timer headers which is causing parsing error in NRF-Discovery at 1 CPS impacting NRF performance Ingress Gateway incorrectly formatted sbi-timer headers, which resulted in parsing errors within the NRF-Discovery module.

Doc Impact:

There is no doc impact.

2 25.1.200
37828830 Stream ID exhaustion in Jetty will result in stale and unused connection Jetty experienced stream ID exhaustion, leading to the retention of stale and unused connections.

Doc Impact:

There is no doc impact.

2 25.1.200
37601685 IGW - High CPU when reset streams are triggered High CPU usage occurred when reset streams were triggered due to inefficient resource management during the reset process.

Doc Impact:

There is no doc impact.

2 24.2.12
37480520 After successful update of certificate in NRF k8S by OCCM by recreate process new certificate validity is not used in TLS handshake by NRF GW During the recreation process initiated by OCCM to update the certificate in the NRF Kubernetes environment, the new certificate's validity was not utilized in the TLS handshake by NRF.

Doc Impact:

There is no doc impact.

2 25.1.100
37487536 OCI/LCI header support not working with default configuration In the default configuration, the OCI or LCI header support failed to function as intended.

Doc Impact:

There is no doc impact.
2 25.1.100
37780732 Pod-protection :-Denied traffic is rejected even though congestion level is not reached When the Pod Protection feature was enabled, traffic was incorrectly denied even though the congestion level had not been reached.

Doc Impact:

There is no doc impact.

2 25.1.200
37506720 Overload Discard Percentage for NRF Microservices When a single Ingress Gateway microservice acted as a front end for both the NRF Access Token and Discovery microservices, the global configuration for sampling interval and token fetching was not performant due to the significant difference in incoming traffic volume between the two microservices.

Doc Impact:

There is no doc impact.

2 24.2.11
37365106 Pod Protection using Rate Limiting :- ASM enabled :- 401 unauthorized metric not updated in "oc_ingressgateway_http_responses_total" When the Pod Protection using Rate Limiting feature was enabled with ASM, the oc_ingressgateway_http_responses_total metric failed to update with the 401 unauthorized response count.

Doc Impact:

There is no doc impact.

3 25.1.100
37603838 Metric oc_egressgateway_peer_health_ping_request_total does not increment when switching between dynamic and static peer configuration The metric
oc_egressgateway_peer_health_ping_request_total
failed to increment when switching between dynamic and static peer configurations.

Doc Impact:

There is no doc impact.

3 25.1.200
36091942 errorCodeSeriesId that is already in use at global level / routes level configuration should not be allowed to be removed using PUT/PATCH Ingress gateway incorrectly allowed the removal of an
errorCodeSeriesId
that was already present at the global or route level configuration through PUT or PATCH requests.

Doc Impact:

There is no doc impact.

3 23.4.2
37855426 Pod-protection :- Observed Internal server error During pod-up if traffic comes more than fill rate - "Internal Server Error errorMessage: Cannot invoke \"ocpm.cne.gateway.util.congestion.CongestionLevel.value" An internal server error occurred during pod startup when incoming traffic exceeded the fill rate, causing the system to fail to invoke the congestion level value method.

Doc Impact:

There is no doc impact.

3 25.1.200
37882318 Issues while switching from HELM based routesConfig to REST based using convertRestToHelm flag When switching from HELM-based routesConfig to REST-based configuration using the convertRestToHelm parameter, Ingress Gateway encountered issues, leading to unexpected behavior.

Doc Impact:

There is no doc impact.

3 25.1.200
37526295 In IGW:25.1.100, after enabling the CCA header a WARN log should be printed for the case where issue at age (iat) is greater than present time. After enabling the CCA header, the system failed to print a WARN log when the issue at age (iat) was greater than the present time.

Doc Impact:

There is no doc impact.

3 25.1.100
35983677 NRF- Missing mandatory "iat claim" parameter validation is not happening in CCA header for feature - CCA Header Validation In the CCA Header Validation feature, the system failed to validate the mandatory "iat claim" parameter, which was absent in the header.

Doc Impact:

There is no doc impact.

3 23.2.0
37864290 IGW accepting traffic above fillRate for POP25 When the FillRate was set to 1000 and deniedRequestAction was left unspecified, Ingress Gateway received 1050 TPS on the /nnrf-nfm/v1/nf-instances/ path.

Doc Impact:

There is no doc impact.

3 25.1.200

37451885

IGW Helm Charts do not pass Yaml Lint During a YAML lint scan initiated, the CNC Console identified compliance issues in Ingress Gateway Helm charts.

Doc Impact:

There is no doc impact.

3 25.1.100
37515236 Pod Protection using Rate Limiting :- ASM enabled :- HTTP request metrics is not getting pegged but Http response are updated when IGW reject with " Scheduler unavailable " When Pod Protection with Rate Limiting was enabled in ASM, HTTP request metrics were not updated, even though HTTP response metrics were correctly updated when the Ingress Gateway rejected requests with a "Scheduler unavailable" error.

Doc Impact:

There is no doc impact.

3 25.1.100
37808385 Pod-protection :- Deniedaction-priority taking out of range values in REST Mode but same its working in HELM Configuration In the REST mode, the Pod Protection feature incorrectly refused actions due to out-of-range values in the action-priority configuration. This issue did not occur in the HELM configuration, where the same settings functioned as expected.

Doc Impact:

There is no doc impact.

3 25.1.200
37780770 Pod-protection :-CongestionConfig.levels.res ources.onset should be more than abatement In the Pod Protection configuration, the
CongestionConfig.levels.resources.onset
value was set to be less than the
abatement
value.

Doc Impact:

There is no doc impact.

3 25.1.200
36833538 User-Agent feature flag is enabled from CV file even we set the configMode as REST instead of HELM The userAgent parameter was incorrectly enabled from the custom values file when the configuration mode was set to REST, rather than HELM.

Doc Impact:

There is no doc impact.

3 24.2.4
37483564 Null Pointer Exception in pegging response_processing_latency in IGW A null pointer exception occurred while processing response latency in Ingress Gateway.

Doc Impact:

There is no doc impact.

3 23.4.6
36672456 WARNING level displayed as BLANK on Discard Policy CNCC Screen On the Discard Policy CNC Console screen, the WARNING level was displayed as blank instead of showing the appropriate warning message.

Doc Impact:

There is no doc impact.

3 24.2.0
37114469 Multiple warning messages in CNCC logs Multiple warning messages were observed in the CNC Console logs.

Doc Impact:

There is no doc impact.

3 22.4.4
35217312 Plaintext HTTP/1.1 attack on N32 IGW leads to high memory consumption A plaintext HTTP/1.1 attack on the N32 Ingress Gateway caused high memory consumption.

Doc Impact:

There is no doc impact.

3 22.3.1
37333191 Pod Protection using Rate Limiting :- "oc_ingressgateway_http_responses_total" metrics are not updated when call is rejected by ratelimiting The oc_ingressgateway_http_responses_total metric was not updated when a call was rejected due to rate limiting in the Pod Protection feature.

Doc Impact:

There is no doc impact.

3 25.1.100
37369197 Pod Protection using Rate Limiting :- ASM enabled :- Error reason for Pod protection by rate limiting is not updated for default error profile. When Pod Protection using Rate Limiting was enabled with ASM, the error reason for pod protection by rate limiting was not updated for the default error profile.

Doc Impact:

There is no doc impact.

4 25.1.100
37417212 Pod Protection using Rate Limiting :- ASM enabled : Rest Configuration is success for ERROR Profile which is not defined in values file When ASM was enabled for Pod Protection using Rate Limiting, the REST configuration for the ERROR profile succeeded despite the profile not being defined in the values file.

Doc Impact:

There is no doc impact.

4 25.1.1000
37416293 Pod Protection using Rate Limiting :- ASM enabled : Fill rate is allowing decimal value during helm but same is rejecting in REST configuration

When configuring Pod Protection using Rate Limiting with ASM enabled, the Helm interface allowed you to enter decimal values for the fill rate.

Doc Impact:

There is no doc impact.

4 25.1.1000
36704055 Adding load level as dimension in ingressgateway_route_overloadcontrol_discard metrics

It was difficult to determine the specific load level causing traffic discards due to absence of the load_level dimension in the ingressgateway_route_overloadcontrol_discard metric.

Doc Impact:

There is no doc impact.

4 24.2.0
35983660 NRF- Incorrect "detail" value in CCA Header Response when missing mandatory "exp/aud claim" for feature - CCA Header Validation

Ingress Gateway incorrectly populated the "detail" value in the CCA header response when a mandatory "exp/aud claim" was missing, leading to misleading error information.

Doc Impact:

There is no doc impact.

4 23.2.0
37756514 Pod-protection :- Congestion Configuration refreshInterval default value showing 5000 instead of 500 and Observed NPE if we configure 50000ms

In the pod protection congestion configuration, the default value for refreshInterval was incorrectly displayed as 5000 milliseconds instead of 500 milliseconds.

Doc Impact:

There is no doc impact.

4 25.1.200
37751980 Pod-protection :- Some of the pod protection for rate limiting metrics are not showing in prometheous

Some pod protection metrics for rate limiting were not displayed in Prometheus due to missing configurations in the monitoring setup.

Doc Impact:

There is no doc impact.

4 25.1.200

Note:

Resolved bugs from 24.2.0 have been forward ported to Release 25.1.200.
4.2.12.6 Common Configuration Service Resolved Bugs

Release 25.1.201

There are no resolved bugs in this release.

Release 25.1.200

Table 4-47 Common Configuration Service 25.1.200 Resolved Bugs

Bug Number Title Description Severity Found In Release
37563087

Traffic routing done based on deleted peer/peerset and routes

Traffic was routed based on deleted peer or peer set routes.

Doc Impact:

There is no doc impact.

2 25.1.100
4.2.12.7 Helm Test Resolved Bugs

Release 25.2.1xx

There are no resolved bugs in this release.

4.2.12.8 App-Info Resolved Bugs

Release 25.2.1xx

There are no resolved bugs in this release.

4.2.12.9 Mediation Resolved Bugs

Release 25.2.100

There are no resolved bugs in this release.

4.2.12.10 NRF-Client Resolved Bugs

Release 25.1.202

Table 4-48 NRF-Client 25.1.202 Resolved Bugs

Bug Number Title Description Severity Found In Release
38090009 Nrf Client Discovery and Management Pod showing multiple restarts during uptake of NRF-Client 25.1.201 During the deployment of multiple management Pods associated with the Leader Pod, an error occurred due to discrepancies in the libraries used. 2 25.1.201

Release 25.1.201

Table 4-49 NRF-Client 25.1.201 Resolved Bugs

Bug Number Title Description Severity Found In Release
38079766 24.2.7 NPE seen in nrf-client-nfmanagement during SM performance run in Policy (24.2.6) Heart beat process have an special case so we are trying to clean up a given map structure some times it is no created properly, after the fix, we managed correctly and the NPE is not happening. 3 24.2.7
37680409 Upgrading PCF from 23.4.6 to 24.2.4 Leads to -mangement pods stuck in Crashloopback (NRF-client 25.1.200) Issues while upgrading NRF client from 23.6 to 24.2.x versions 2 24.2.4
37746681 NRF-Client Sends continuous PUT/PATCH requests to NRF when UDR is in SUSPENDED state When the NF changes from running to not running, NRF-client enters into an endless cycle of PUT and PATCH request part of the heartbeat process. This overloads with many requests. 2 25.1.100
37823559 Upgrade fails from PCF 24.1.0 to 24.2.0 " Error creating bean with name 'hookService' defined in URL" (25.1.200) While upgrading NRF-client some how there are multiple records in the common config hook db, this generates issues while completing the hook process. Until now the workaround was to manually delete the duplicate records. 2 24.2.0

Release 25.1.200

There are no resolved bugs in this release.

4.2.12.11 Perf-Info Resolved Bugs

Release 25.2.1xx

There are no resolved bugs in this release.

4.2.12.12 Debug Tool Resolved Bugs

Release 25.2.1xx

There are no resolved bugs in this release.

4.3 Known Bug List

The following tables list the known bugs and associated Customer Impact statements.

4.3.1 BSF Known Bugs

Release 26.1.201

Table 4-50 BSF 26.1.201 Known Bugs

Bug Number Title Description Customer Impact Severity Found in Release
39207585 Mate site is not listed in the migration completion query The Custom Query list used to check migration completion status for the v2 table may not list the mate site. During PCF binding table migration in a BSF GR deployment, the PCF Binding migration completion query displays only the local site ID. The migration completion percentage for the mate site cannot be viewed from either site. Binding processing, migration, service traffic, and data integrity are not affected. The impact is limited to operational visibility.

Workaround: There is no workaround.

3 25.2.200

4.3.2 CNC Console Known Bugs

Release 25.1.204

There are no known bugs in this release.

Release 25.1.203

CNC Console 25.1.203 is a Critical Patch Update. Critical Patch Updates provide security patches for supported Oracle on-premises products. They are available to customers with valid support contracts. For more information, see Critical Patch Updates, Security Alerts, and Bulletins.

There are no known bugs in this release.

Release 25.1.202

There are no known bugs in this release.

Release 25.1.201

There are no known bugs in this release.

Release 25.1.200

There are no known bugs in this release.

4.3.3 cnDBTier Known Bugs

Release 25.1.201-6

Bug Number Title Description Customer Impact Severity Found in Release
38857144 Cluster Disconnect observed when horizontal scaling was performed for ndbappmysqld pods A cluster disconnect is observed during database upgrade from 25.2.100 to 25.2.101 when horizontal scaling is performed on ndbappmysqld pods.

Cluster may disconnect while scaling ndbappmysqld and ndbmysqld pods during the addition of a georedundant site.

Workaround:

Updated the procedures in the “Horizontal Scaling of ndbappmysqld pods” and “Addition of cnDBTier georedundant Site” sections in Oracle Communications Cloud Native Core, cnDBTier User Guide.

2 25.2.100
39244432 db-replication-svc may initialize with partial channel details when ASM sidecar is not ready In some environments, db-replication-svc may start before the istio-proxy sidecar is fully ready and initialize with only partial primary or secondary channel details.

Operations that require both primary and secondary channel details, such as switchover or skip error, may fail.

Workaround:

Restart the db-replication-svc pod. In most cases, the service initializes successfully after restart once connectivity to mysql-connectivity-svc is available. If the issue persists, configure a DestinationRule to disable TLS for traffic from db-replication-svc to mysql-connectivity-svc.

2 25.2.100

Release 25.1.201-5

Table 4-51 cnDBTier 25.1.201-5 Known Bugs

Bug Number Title Description Customer Impact Severity Found in Release
38857144 Cluster Disconnect observed when horizontal scaling was performed for ndbappmysqld pods A cluster disconnect is observed during database upgrade from 25.2.100 to 25.2.101 when horizontal scaling is performed on ndbappmysqld pods.

Cluster may disconnect while scaling ndbappmysqld and ndbmysqld pods during the addition of a georedundant site.

Workaround

Updated the following procedures in cnDBTier documentation: “Horizontal Scaling of ndbappmysqld pods” and “Addition of cnDBTier georedundant Site” in Oracle Communications Cloud Native Core, cnDBTier User Guide

2 25.2.100
39244432 db-replication-svc may initialize with partial channel details when ASM sidecar is not ready In some environments, db-replication-svc may start before the istio-proxy sidecar is fully ready and initialize with only partial primary or secondary channel details.

Operations that require both primary and secondary channel details, such as switchover or skip error, may fail.

Workaround

Restart the db-replication-svc pod. In most cases, the service initializes successfully after restart once connectivity to mysql-connectivity-svc is available. If the issue persists, configure a DestinationRule to disable TLS for traffic from db-replication-svc to mysql-connectivity-svc.

2 25.2.100

Release 25.1.201-4

Table 4-52 cnDBTier 25.1.201-4 Known Bugs

Bug Number Title Description Customer Impact Severity Found in Release
38857144 Cluster Disconnect observed when horizontal scaling was performed for ndbappmysqld pods A cluster disconnect is observed during the upgrade of the database from version 25.2.100 to 25.2.101 when horizontal scaling was performed on the ndbappmysqld pods. Cluster gets disconnected during the scaling of the ndbappmysqld and ndbmysqld pods during the addition of Geo redundant site.

Workaround

Updated the following procedures in cnDBTier documentation:
  • "Horizontal Scaling of ndbappmysqld pods" in Oracle Communications Cloud Native Core, cnDBTier User Guide
  • "Restoring Georeplication (GR) Failure" in Oracle Communications Cloud Native Core, cnDBTier Installation, Upgrade, and Fault Recovery Guide
2 25.2.100

Release 25.1.201-3

There are no known bugs for this release.

Release 25.1.201-2

There are no known bugs for this release.

Release 25.1.201-1

There are no known bugs for this release.

Release 25.1.201

Table 4-53 cnDBTier 25.1.201 Known Bugs

Bug Number Title Description Customer Impact Severity Found in Release
38199454 DB Entries on Site-1 and Site-2 are not in sync after doing an in service upgrade from PCF 24.2.6 to 25.1.200 on a 2 site GR setup After performing an in-service upgrade from PCF version 24.2.6 to 25.1.200 on a 2-site Geo-Replication (GR) setup, database entries between Site-1 and Site-2 are not in sync. Replication delay is observed. 2 24.2.6

Release 25.1.200

Table 4-54 cnDBTier 25.1.200 Known Bugs

Bug Number Title Description Customer Impact Severity Found in Release
37859029 dbtscale_ndbmtd_pods failed when ndb backup triggered while scaling in progress dbtscale_ndbmtd_pods failed when ndb backup is triggered while scaling in progress. Unable to scale the data nodes when backup is in progress.

Workaround:

Perform one of the following workarounds:

  • Use the dbtscale_ndbmtd_pods script from the separate patch included in the cnDBTier scripts package version 25.1.200.0.1.
  • Follow the manual procedures for scaling the data nodes.
  • If data nodes are restarting during the re partitioning of the tables, then run the dbt_reorg_table_partition script after the restart to ensure all table partitions are reorganized across the data nodes.
2 25.1.100
38204306 dbtremovesite script exits with ERROR - DBTIER_SCRIPT_VERSION (25.1.100) does not match DBTIER_LIBRARY_VERSION (25.1.200) The dbtremovesite script exits with an error due to a file mismatch issue. Due to the script failure, site migration may fail.

Workaround:

  • A separate release of tools folder will be delivered which includes this dbtremovesite script.
  • Perform the following steps:
    1. Navigate to the folder <csar_extract>/Artifacts/Scripts/tools/bin.

      cd <csar_extract>/Artifacts/Scripts/tools/bin

    2. Run the following commands:
      chmod 755 dbtremovesite 
      export OCCNE_VERSION=<substitute DBTierversion> 
      sed -e 's/<\${OCCNE_VERSION}>/'${OCCNE_VERSION}'/' -i dbtremovesite 
2 25.1.200
dbtscale_ndbmtd_pods script exited with 'Create Nodegroup FAILED' for wrong nodegroup In a two site, ASM enabled, backup encrypted and password encrypted setup, the horizontal data pod scaling failed while using the dbtscale_ndbmtd_pods script and exited with 'Create Nodegroup FAILED" error. Scaling of data nodes will not be successful as the new data nodes will still be in the beginning phase.

Workaround:

Perform one of the following workarounds:
  • Use the dbtscale_ndbmtd_pods script from the separate patch included in the cnDBTier scripts package version 25.1.200.0.1.
  • Follow the manual procedures for scaling the data nodes.
2 25.1.100  
38144181 Add the additional replication error numbers, 1091 and 1826 to the list of replication errors and remove the error number 1094 from the list Added the following new error numbers to the list of replication errors:
  • 1091 (Can't DROP – column/key doesn't exist)
  • 1826 (Duplicate foreign key constraint name)

Removed the error "1094 - Unknown command" from the list.

During georeplication process, when the errors 1091 or 1826 occur in the replication channel, the replication fails.

Workaround:

Configure the following replication errors 1091 and 1826 in the replicationskiperrors.replicationerrornumbers section of the custom_values.yaml file:
  • 1091 (Can't DROP – column/key doesn't exist)
  • 1826 (Duplicate foreign key constraint name)
With this, when either of the error occurs, they will be skipped and georeplication process in continued.
3 23.4.2
37859265 dbtscale_ndbmtd_pods disrupted by ndbmtd pod restart Schema re-partitioning fails when other data nodes are restarting, requiring the dbt_reorg_table_partition script to be re-executed after the restart. Repartitioning of the tables will fail.

Workaround:

Perform one of the following workarounds:
  • Use the dbtscale_ndbmtd_pods script from the separate patch included in the cnDBTier scripts package version 25.1.200.0.1.
  • Follow the manual procedures for scaling the data nodes.
  • If data nodes are restarting during the repartitioning of the tables, then run the dbt_reorg_table_partition script after the restart to ensure all table partitions are reorganized across the data nodes.
3 25.1.100
38236749 DR getting stuck for fatal scenario on prefix enabled 4-site single-channel IPv6 setup Georeplication recovery is stuck if 2 sites are uninstalled in a 4-site scenario and respective IP’s are removed from remote site IP

Workaround:

Perform one of the following workarounds depending upon the Fixed IP’s used for the remote site IP:
  • If fixed IPs are used, then do not remove them from the remote site IP.
  • If dynamic IPs are used, then any dummy IP can be used for the remote site IP.
   
38199454 DB Entries on Site-1 and Site-2 are not in sync after doing an in service upgrade from PCF 24.2.6 to 25.1.200 on a 2 site GR setup After performing an in-service upgrade from PCF version 24.2.6 to 25.1.200 on a 2-site georeplication (GR) setup, database entries between Site-1 and Site-2 are not in sync. Replication delay is observed.

Workaround:

There is no workaround.

2 24.2.6
38220013 dbtrecover Script is affecting db-monitor-svc. Intermittently after running georeplication recovery, db-mon-svc has deadlock threads. Db-mon-svc API and metric scraping are not working until it gets restarted.

Workaround:

Restart the DB Monitor service after georeplication recovery is completed.
3 25.1.100

4.3.4 CNE Known Bugs

Release 25.1.201

There are no known bugs in this release.

Release 25.1.200

Table 4-55 CNE 25.1.200 Known Bugs

Bug Number Title Description Customer Impact Severity Found in Release
36740199 bmCNE installation on X9-2 servers fail Preboot execution environment (PXE) booting occurs when installing Oracle Linux 9 (OL9) based BareMetal CNE on X9-2 servers. The OL9.x ISO UEK kernel installation hangs on X9-2 server. When booted with OL9.x UEK ISO, the screen runs for a while and then hangs with the following message "Device doesn't have valid ME Interface". BareMetal CNE installation on X9-2 servers fails.

Workaround:

Perform one of the following workarounds:

  • Use x9-2 server based BareMetal CNE.
  • Use CNE 24.3.1 or older version on X9-2 servers.
2 23.4.0
38106756 CNE self upgrade failed due to multus Race condition When performing CNE upgrade with CNLB-enabled option, upgrade fails intermittently because of a race in Multus that will prevent the pod from starting.

CNE upgrade with CNLB-enabled option fails.

There is no impact on LBVM- based deployments.

Workaround:

Run the following command on all the nodes:

sudo rm -R /opt/cni/bin/multus-shim

3 25.1.200

OSO Known Bugs

Release 25.1.201

There are no known bugs in this release.

Release 25.1.200

There are no known bugs in this release.

4.3.5 NRF Known Bugs

Release 25.1.206

NRF 25.1.206 is a Critical Patch Update. Critical Patch Updates provide security patches for supported Oracle on-premises products. They are available to customers with valid support contracts. For more information, see Critical Patch Updates, Security Alerts, and Bulletins.

There are no known bugs in this release.

Release 25.1.205

NRF 25.1.205 is a Critical Patch Update. Critical Patch Updates provide security patches for supported Oracle on-premises products. They are available to customers with valid support contracts. For more information, see Critical Patch Updates, Security Alerts, and Bulletins.

There are no known bugs in this release.

Release 25.1.204

Table 4-56 NRF 25.1.204 Known Bugs

Bug Number Title Description Customer Impact Severity Found in Release
39050962 Incorrect discovery response w.r.t smf slice selection and incorrect value for preferredTaiMatchInd

While processing NFDiscover Service operation for SMF NF type with DNN and Preferred TAI, SMF profiles are returned in the NFDiscover response, partially matched with different smfinfo element in smfInfoList for tai and dnn attributes.

Consumer network functions will receive SMF profiles whose SMFInfoList includes SMFInfo entries that partially match the TAI and DNN attributes.

Workaround:

There is no workaround.

3 25.1.203

Release 25.1.203

NRF 25.1.203 is a Critical Patch Update. Critical Patch Updates provide security patches for supported Oracle on-premises products. They are available to customers with valid support contracts. For more information, see Critical Patch Updates, Security Alerts, and Bulletins.

Table 4-57 NRF 25.1.203 Known Bugs

Bug Number Title Description Customer Impact Severity Found in Release
38671036 Incorrect dimension name "SubscriptionIdType" for SLF Request/Response metric

The metrics ocnrf_SLF_tx_requests_total and ocnrf_SLF_rx_responses_total have an incorrect dimension SubscriptionIdType with values as SUPI and GPSI.

The correct dimension name should be SubscriberIdType.

The metric is pegged with dimension as SubscriptionIdType as SUPI or GPSI can be misleading. But this does not have an impact on the KPIs.

Workaround:

There is no workaround.

3 25.1.202

Release 25.1.202

Table 4-58 NRF 25.1.202 Known Bugs

Bug Number Title Description Customer Impact Severity Found in Release
38327826 NRF uses only own site data when GeoRedundancy feature is enabled.

When the overrideReplicationCheck Helm flag is set to true, NRF operates as a standalone site during the initial configuration of geoRedundancy or when sites are reconfigured. In this scenario, NRF assumes replication is up across all sites, regardless of their actual replication status. However, following a fresh installation, the mated sites may not yet be configured using geoRedundancyOptions, leading to inaccurate replication assumptions.

NRF sites will function as stand alone and will use only own site state data for service operations.

Workaround:

After updating the geoRedundancyOptions on the site, perform a rolling restart of the cache data service, discovery, registration, subscription, access token, artisan, auditor, and configuration pods. This ensures that the new configuration is properly loaded.

3 25.1.200
38179022 Outgoing signalling messages from NRF-egressgateway getting failed while using IPv6 address in slfhost

Outgoing signaling messages fail when the destination host address is configured with an IPv6 value on the Egress Gateway microservice. This issue occurs because the NRF backend microservices send the IPv6 address without square brackets. The problem impacts the following use cases: NRF to SLF, NRF to NRF Forwarding, and NRF Growth.

Signaling messages fail when the host address is configured with an IPv6 value for the defined use cases.

Workaround:

There is no workaround.

3 25.1.200

Release 25.1.200

Table 4-59 NRF 25.1.200 Known Bugs

Bug Number Title Description Customer Impact Severity Found in Release
38327826 Message copy feature: Access token request generated at EGW towards NRF not being sent to kafka properly There is an issue with the access token request generated at the Egress Gateway. The response message received at the Egress Gateway from the access token microservice is being fed into Kafka, but the request message is not being sent to Kafka. Both the request and response messages need to be fed into the same Kafka partition for the same transaction. The response message received at Egress Gateway from Access Token microservice is being fed into Kafka, while the request message is not being sent in Kafka.

Workaround:

There is no workaround.

3 25.1.200
37412089 For NFSetId case-sensitive validation, registration request is getting accepted for NID having value not compliant to fixed length of 8 digit hexadecimal number as per 3GPP. For NFSetId case-sensitive validation, registration request is getting accepted for NID having value not compliant to fixed length of 8 digit hexadecimal number as per 3GPP. NRF will accept the NFRegister/NFDiscover service operations request with non-compliant NFSetID containing NID digits.

Workaround:

NFs should use correct length of NID digits as per 3GPP for NFRegister/NFDiscover service operations request.

3 23.4.6
37760595 Discovery query results in incorrect match with preferred-locality=US%2bEast NRF is returning NFProfile ordered at first position with locality matching with space (that is, US East) while query contains + (that is, US+East). NFProfiles in response may be ordered with space first then followed by other localities.

Workaround:

Locality attribute should not have space or plus as special characters. Or if query have %252B as encoded character then NFProfile with + will match that is, US+East.

3 24.2.4
36366551 During NRF upgrade from 23.3.1 to 23.4.0 restart observed in NRF ingress-gateway with exit code 143 randomly

During NRF Upgrade from 23.3.1 to 23.4.0, sometime it is observed that NRF ingress-gateway pods restarts. The issue happens only when both the Primary and Secondary Coherence Leader pods gets upgraded at the same time during rolling Update.

This can happen randomly, but when happens, the pod comes up automatically after restart. No manual step is required to recover the pod.

Workaround:

The ingress-gateway section of the NRF custom values yaml, the rollingUpgdate.maxUnavailable and rollingUpdate.maxSurge needs to set to 5%. This will ensure only one Pod of ingress-gateway updates at a time. However, this will increase the overall upgrade time of all the ingress-gateway pods.

3 23.4.0
37965223 Error Codes are not picked from errorCodeProfile configuration for Pod protection with rate limit Error Codes are not picked from errorCodeProfile configuration for Pod protection with rate limit. When Ingress Gateway rejects the requests, it takes the error code from Helm attribute errorCodeProfiles instead of REST.

Workaround:

Update the error code for ERR_POD_PROTECTION_RATE_LIMIT in the helm attribute ingressgateway.errorCodeProfiles.

3 25.1.200
37965589 The Ingress gateway pod restarted and went into crashloopbackoff when 10k traffic was sent to a single pod

The Ingress gateway pod restarted and went into crashloopbackoff when 10k traffic was sent to a single pod.

The ingress gateway Pod Protection using rate limiting feature was enabled.

To simulate high burst of traffic, 10k TPS was sent to a single IGW pod. The Ingress Gateway pod restarted and the pod went into crashloopbackoff state.

The issue is observed with ASM enabled.

The side car container crashed due to OOM.

Workaround:

Traffic cannot reach to 10k.

3 25.1.200
37604778 TLS1.3 Handshake is failing between NRF and SCP

TLS1.3 Handshake is failing between NRF and SCP

as SCP was sending Session resumption extensions towards NRF (Ingress Gateway).

TLS v1.3 will not work if Client is sending session resumption extensions.

Workaround:

Client should not send Session Resumption extension.

3 24.2.3
38104210 NFUpdate - Partial update dnnUpfInfoList and dnnSmfInfoList are accepting string value instead of object NFUpdate - Partial update dnnUpfInfoList and dnnSmfInfoList are accepting string value instead of object

dnnUpfInfoList and dnnSmfInfoList will have wrong information as per 3GPP.

This is fault insertion case, when string values are used instead of the DnnSmfInfoItem and DnnUpfInfoItem object.

Workaround:

dnnSmfInfoItem and dnnUpfInfoItem attributes shall be used as per 3GPP during patch to avoid this issue.

3 25.1.100
37412138 Error response generated by NRF needs to be corrected when registration request is sent with incorrect order for mcc and mnc Error response generated by NRF needs to be corrected when registration request is sent with incorrect order for mcc and mnc.

No Impact on signaling message processing.

Only error message details doesn't include correct error reason.

Workaround:

There is no workaround available.

4 23.4.6
38103938 log4j2_events_total metric is not getting pegged log4j2_events_total metric is not getting pegged. Metric for log4j is not pegged.

Workaround:

There is no workaround available.

4 25.1.200
38103958 Congestion Config CNC Console GUI screen not working correctly Congestion Config CNC Console GUI screen not working correctly. CNC Console GUI is not working for congestion config.

Workaround:

There is no workaround available.

4 25.1.200

4.3.6 NSSF Known Bugs

Release 25.1.202

NSSF 25.1.202 is a Critical Patch Update. Critical Patch Updates provide security patches for supported Oracle on-premises products. They are available to customers with valid support contracts. For more information, see Critical Patch Updates, Security Alerts, and Bulletins.

There are no known bugs in this release.

Release 25.1.201

Table 4-60 NSSF 25.1.201 Known Bugs

Bug Number Title Description Customer Impact Severity Found in Release
37591102 OCNSSF:24.2.x:snmp MIB Complain from SNMP server SNMP traps are not being raised because of issue with the mib file. There is no impact on traffic.

Workaround:

Update the Mib file with the scope shared.

3 24.2.0
37681032 NSSF 24.2.1: Missing Edit Option for nsconfig Logging Levels in CNCC GUI When an empty packet is forcefully added to the traffic (negative scenario), 0.045% of the traffic is discarded with a 503 error. Minimal traffic loss: only 0.045% of traffic is lost in an error scenario.

Workaround:

There is no workaround.

3 24.2.1
37773632 [10.5K TPS] when we are deleting all CNDB pods, ns-selection 2 pods have stuck in a 1/2 state. In the scenario where all CNDB pods are deleted, the NSSF NsSelection pods get stuck. Minimal impact on traffic during CNDB recovery When all CNDB pods are deleted, the traffic from NsSelection pods is not distributed properly, causing some pods to become stuck.

Workaround:

Delete the stuck pods; newly spawned pods can take traffic.

3 25.1.200
37776049 Dynamic log level updating Using CNCC for various micro services for NSSF. "LogDiscarding" Option is coming while fetching configured log level via REST but in CNCC while configured that option is not present The NsConfig log level is not being updated at runtime. There is no impact on traffic; however, debuggability becomes difficult if the NsConfig service log level needs to be changed during runtime.

Workaround:

A Helm parameter is available to change the NsConfig log level. The parameter can be modified to update the log level as needed

3 25.1.200

Release 25.1.200

Table 4-61 NSSF 25.1.200 Known Bugs

Bug Number Title Description Customer Impact Severity Found in Release
37048499 GR replication is breaking post rollback to of CNDB 24.2.1

The cnDBTier replication mechanism is experiencing performance degradation during rollbacks under high transaction volumes, leading to potential transaction ordering inconsistencies and constraint failures on the secondary site. Additionally, any binlog instruction failure is disrupting the replication channel.

For the Network Service Selection Function (NSSF), the NsAvailability functionality is encountering a replication channel break when rolling back an upgrade from 24.2.x to 24.3.x if an availability delete and an availability update are occurring within a few seconds.

During the rollback of an upgrade from 24.2.x to 24.3.x, the Network Service Selection Function's (NSSF) Availability functionality may experience a replication channel break. This can occur when an availability delete and an availability update happen within a short time frame of a couple of seconds. As a result, the replication channel may be disrupted.

Workaround:

To recover the replication channel, follow these steps:
  • See the "Resolving Georeplication Failure Between cnDBTierTier Clusters in a Two Site Replication" section in Oracle Communications Cloud Native Core, cnDBTierTier Installation, Upgrade, and Fault Recovery Guide.
  • Follow the replication channel recovery procedure as described in the guide.
24.3.0 2
37763453 Error code 500, instead 4XX, when NSSF receives duplicated incorrect Authorization When the NSSF receives a request with a duplicated and incorrect Authorization header, it returns an HTTP 500 Internal Server Error instead of the expected 4XX error. When an incorrect authentication token is provided, the Internet Gateway (IGW) does not respond with an error message. However, there is no loss of traffic.

Workaround:

There is no workaround.

3 24.3.0
37762864 [10.5K TPS] nrf-client discovery and management pod has restarted when all cnDBTier pod faults using chaos-mesh When all cnDBTier pods are subjected to a pod fault using chaos-mesh, the nrf-client discovery and management pod unexpectedly restarts. This issue occurs in a specific test environment with distributed traffic and replication channel configurations. When the Cloud Native Database (cnDBTier) is forcefully kept in a stuck state, the Network Repository Function (NRF) client pods may enter a state of continuous restart. However, there is no impact on traffic once the cnDBTier pods recover.

Workaround:

There is no workaround.

3 25.1.200
37731732 Autopopulation with 3NRFs: Even though candidate AMF doesn't have same plmn as amfset it is storing in database and is getting resolved when amf resolution is called During AMF resolution, the system includes candidate AMFs with different PLMNs in the AMF set, even though they should only include AMFs with the same PLMN. When the Cloud Native Database (cnDBTier) is forcefully kept in a stuck state, the Network Repository Function (NRF) client pods may enter a state of continuous restart. However, there is no impact on traffic once the cnDBTier pods recover.

Workaround:

There is no workaround.

3 25.1.200
37684563 [10.5K Traffic—without Replication Break] While 7K burst traffic to site1, NSSF reduced the success rate by 3.528% with 500 and 503 error code and then recovered it When transferring traffic from Site2 and Site3 to Site1, the NSSF experiences a temporary drop in success rate by 3.528%, with 500 and 503 error codes. When traffic is moved from one site to another, there may be an intermittent loss of traffic. The impact is minimal, resulting in approximately 3.5% of traffic loss for a few seconds, after which the traffic recovers.

Workaround:

There is no workaround.

3 25.1.200
37684124 [10.5K Traffic] while adding the empty frame in all requests, NSSF rejected the ns-selection traffic, dropping 0.045% with a 503 error code When adding an empty frame to all ns-selection and ns-availability requests, the NSSF rejects a small percentage of traffic (0.045%) with a 503 error code. This issue occurs during high traffic loads. There is minimal impact on traffic, resulting in approximately 3.5% of traffic loss for a few seconds, after which the traffic recovers.

Workaround:

There is no workaround.

3 25.1.200
37639879 oauth failure is not coming in oc_ingressgateway_http_responses_total metrics The oauth failure is not coming in oc_ingressgateway_http_responses_total metrics but it seen in the oc_oauth_validation_failure_total metric. There is no impact on traffic.

Workaround:

There is no workaround.

3 25.1.200
37623199 If an accept header is invalid, NSSF should not send a notification to AMF. it should send 4xx instead of 500 responses to the nsssai-auth PUT and DELETE configuration. When an invalid Accept header is provided, the NSSF responds with 500 status codes for nssai-auth PUT and DELETE requests instead of sending 4xx responses as expected. This issue leads to incorrect database operations and unnecessary notifications to the AMF. There is no impact on traffic.

Workaround:

There is no workaround.

3 25.1.200
37606284 With DNS SRV feature enabled for selection of NRF, NSSF fails to establish connection with NRF When an invalid Accept header is provided in requests to the NSSF, it incorrectly sends a 500 response for PUT operations and a 204 response for DELETE operations on the
nsssai-auth
configuration. Instead, it should send a 4xx response without performing any database operations or triggering notifications to the AMF.
There is no impact on traffic.

Workaround:

There is no workaround.

3 25.1.200
37216832 [9K TPS Success] [1K TPS Slice not configured in DB] NSSF is sending the success responses for slice which has not configured in database and failure response of slice which has configured in database for pdu session establishment request. NSSF sends success responses for PDU session establishment requests targeting an unconfigured slice (0.4% of 1K TPS traffic) while sending failure responses (403 and 503) for requests targeting valid, configured slices (9K TPS traffic). This issue occurs during PDU session establishment, despite initial registration, UE configuration, and handover selection working correctly for invalid slices. There is minimal impact on traffic.

Workaround:

There is no workaround.

3 24.3.0
37184196 3-site GR setup ASM and Oauth Enabled : 10.5K TPS Traffic on SITE1 : during restoration of site (post Failover for 18 hours), new NsAvailability PUT is not syncing to site which is recovered In a 3-site setup with ASM and OAuth enabled, during the restoration of a site after an 18-hour failover, the NsAvailability PUT request for a specific slice is not syncing to the recovered site. This occurs when 10.5K TPS traffic is running on the remaining active site (SITE-1), and the replication channels are restored. As a result, Ns-Selection for the slice on the recovered site (SITE-2) fails, even though Ns-Selection on the active site (SITE-1) is successful. There is minimal impact on traffic.

Workaround:

There is no workaround.

3 24.3.0
37136539 [dnsSrvEnabled: false] [peer Health monitoring: disabled] NSSF is not sending the notification towards peer2 host if peer1 is down NSSF fails to send notifications to the peer2 host when peer1 is down, and both dnsSrvEnabled and peer monitoring are disabled. In the provided configuration, the host nssf-scp-3-scp-worker.ocnssf-scp-3 (peer1) is down, but the egress gateway does not route notifications to the peer2 host as expected. There is a loss of notification message in a specific corner case when static routing is being used.

Workaround:

Enable dnsSrv and use virtual FQDNs.

3 24.2.1
37136248 If dnsSrvEnabled is set to false and peer1 is used as a virtual host, the egress gateway will not sending the notifcation to peer2 host and peer health status is empty When dnsSrvEnabled is set to false and peer1 is configured as a virtual host, the egress gateway fails to send notifications to the peer2 host. As a result, the peer health status remains empty. Wireshark analysis reveals a 400 Bad Request error for the notification attempt. There is no impact on traffic, as with retrial, the message gets to the correct node.

Workaround:

There is no workaround.

3 24.2.1
37099843 Upgrade 3 Site GR Setup, while upgrading NSSF and cnDBTier, we observed that the Ns-availability success rate dropped 0.07%, 0.77%, and 1.19%, respectively, for each site, and we got 500, 503, and 403, 408 error codes. During the upgrade process of a 3-Site GR Setup, the Ns-availability success rate experiences a drop of 0.07%, 0.77%, and 1.19% for each site, respectively, when upgrading NSSF and cnDBTier. This issue is accompanied by error codes 500, 503, 403, and 408. There is minimal impact on traffic during upgrade, resulting in approximately 0.25 to 1% of messages being lost.

Workaround:

There is no workaround.

3 24.3.0
36734417 NSSF 2 Site GR :IN service solution Upgrade : 1.25K TPS : traffic loss of 0.259% and 0.027% at Site 1 and Site 2 during the NSSF upgrades, with latency of roughly 1.43 seconds and 886 ms. During the upgrade process of a 2-Site GR Setup, traffic loss is observed at Site 1 and Site 2, with a loss of 0.259% and 0.027%, respectively. This is accompanied by increased latency, reaching 1.43 seconds at Site 1 and 886 milliseconds at Site 2. The issue occurs while upgrading NSSF. There is minimal impact on traffic during upgrade, resulting in approximately 0.25% of messages being lost.

Workaround:

There is no workaround.

3 24.2.0
36662054 NSSF-CNCC: Ingress pod: Discard Policy mapping configured without mandatory param The CNCC GUI is experiencing an issue where the Discard Policy mapping can be configured without mandatory parameters. This is due to a lack of validation checks, allowing users to save the mapping without providing essential information. There is no impact on traffic.

Workaround:

The operator can configure with proper values.

3 24.1.0
36552026 KeyId, certName, kSecretName, and certAlgorithm invalid values are not validating in the oauthvalidator configuration. NSSF is not properly validating certain parameters in the oauthvalidator configuration, specifically KeyId, certName, kSecretName, and certAlgorithm. Invalid values for these fields are being accepted without triggering an error or validation message. There is no impact on traffic.

Workaround:

While configuring OAuth validator configuration, the operator needs to use proper values.

3 24.1.0
36285762 After restarting the NSselection pod, NSSF is transmitting an inaccurate NF Level value to ZERO percentage. After restarting the NSselection pod, the NSSF system is incorrectly reporting an NF Level value of zero percent. This issue is observed when retrieving the NSselection request for EPS to 5G selection, and it results in the absence of ocnssf-selection data in the response. The system should accurately reflect the NF Level, especially when there is load information available. There is no impact on traffic.

Workaround:

There is no workaround.

3 23.4.0
36265745 NSSF is only sending NF-Instanse/NF-Service load level information for multiple AMF Get Requests The NSSF system is inconsistently providing NF-Instance and NF-Service load level information in response to AMF Get Requests. In some cases, only the NF-Instance load level is sent, while in others, only the NF-Service load level is included. There is no impact on traffic.

Workaround:

There is no workaround.

3 23.4.0
35971708 while pod protection is disabled, OcnssfIngressGatewayPodResourceStateMajor alert is not clear and resource metric is not updating to -1 When disabling pod protection, the system fails to update the resource metric to -1 and does not clear the OcnssfIngressGatewayPodResourceStateMajor alert. This results in an incorrect view, as the congestion alert is cleared, but the resource alerts remain visible. The issue suggests a potential problem with the system's ability to accurately reflect resource-related changes. There is no impact on traffic.

Workaround:

There is no workaround.

3 23.3.0
35922130 Key Validation is missing for IGW pod protection parameter name configuration The system is not correctly processing certain keys in the provided curl commands. Specifically, the keys 'actionSamplingPeriod', 'name', 'cpu', and 'pendingMessage' are not being handled as expected. There is no impact on traffic.

Workaround:

Configure NSSF with proper values as per the Oracle Communications Cloud Native Core, Network Slice Selection Function REST Specification Guide.

3 23.3.0
35921656 NSSF should validate the integer pod protection parameter limit. The system is not properly validating integer parameters in the provided curl commands. Specifically, the parameters 'monitoringInterval', 'stateChangeSampleCount', 'actionSamplingPeriod', and 'incrementBy' are not being checked for valid values. There is no impact on traffic.

Workaround:

The operator can configure and make sure the values configured must be as per Oracle Communications Cloud Native Core, Network Slice Selection Function REST Specification Guide.

3 23.3.0
35888411 Wrong peer health status is coming "DNS SRV Based Selection of SCP in NSSF" When peer monitoring is enabled and dnsSrvEnabled is disabled, the system displays incorrect peer health status. With an invalid SCP IP configured as a host and a virtual host with valid data, the health status shows the invalid SCP as healthy, which is incorrect. The health status for the peer configured via the virtual host is missing and should also be indicated as unhealthy. There is no impact on traffic flow, as a non-responsive SCP is not being considered for status.

Workaround:

There is no workaround.

3 23.3.0
35860137 In Policy Mapping Configuration in Ingress Gateway, For the samplingPeriod parameter, max value of parameter validation should be necessary. In the Policy Mapping Configuration of the Ingress Gateway, the maximum value for the samplingPeriod parameter is not being validated correctly. When a user sets an extremely high value for this parameter, the system accepts it without any error or validation. There is no impact on traffic flow.

Workaround:

There is no workaround.

3 23.3.0
37622760 NSSF should send 415 responses to ns-selection and ns-availability requests if their content type is invalid. NSSF is not responding with the correct error code when receiving ns-selection and ns-availability requests with invalid content types. Instead of sending a 415 response as per the 3GPP specification, it returns a 500 error with an "UNSPECIFIED_NF_FAILURE" message. There is no impact on traffic flow.

Workaround:

There is no workaround.

4 25.1.200
37617910 If ns-selection and ns-availability are invalid Accept Header, NSSF should not send 404 responses of UnSubscribe and subscription patch request. it should be 406 error code and "detail":"No acceptable". When ns-selection and ns-availability requests are made with an invalid Accept header, the NSSF responds with a 404 error instead of the expected 500 error with the detail "No acceptable representation." This behavior is observed for both subscription deletion and patch requests. There is no impact on traffic flow.

Workaround:

There is no workaround.

4 25.1.200
37612743 If URLs for ns-selection and ns-availability are invalid, NSSF should return a 400 error code and title with INVALID_URI. When ns-selection and ns-availability requests are made with invalid URLs, the NSSF responds with a 404 error instead of the expected 400 error with the title "INVALID_URI." This issue is observed across various call flows, including UE Config, Subscription POST, Ns-Availability DELETE, unsubscription, Subscription Patch, and Availability PATCH. There is no impact on traffic flow.

Workaround:

There is no workaround.

4 25.1.200
37606772 3-site GR setup ASM and Oauth Enabled: 15K TPS Traffic on SITE1 : we observed the 503 SERVICE_UNAVAILABLE error code In a 3-site GR setup with ASM and OAuth enabled, when traffic is distributed across three NSSF instances and replication channels are brought down, the NSSF starts rejecting some traffic with a 503 "SERVICE_UNAVAILABLE" error code as the traffic load increases. There is minimal impact on traffic in an overload scenario.

Workaround:

There is no workaround.

4 25.1.200
37592343 Subscription Patch should be a part of Availability Sub Success (2xx) % panel in Grafana Dashboard The Grafana dashboard's Availability Sub Success (2xx) % panel does not include subscription patch requests. When the SUMOD feature is disabled in the NSSF ocnssf_custom_values.yaml file, subscription patch requests fail with a 405 error, and this information should be reflected in the dashboard to provide a comprehensive view of subscription success rates. There is no impact on traffic.

Workaround:

There is no workaround.

4 25.1.200
36881883 In Grafana, Service Status Panel is showing more than 100% for Ns-Selection and Ns-Avaliability Data The Service Status Panel in Grafana shows more than 100% for NS selection and availability data. There is no service impact.

Workaround:

There is no workaround.

4 24.2.0
36653494 If KID is missing in access token, NSSF should not send "Kid missing" instead of "kid configured does not match with the one present in the token" When the KID is missing in the access token, NSSF sends "kid configured does not match with the one present in the token" instead of indicating that the KID is missing. There is no impact on traffic, as the error code is proper.

Workaround:

There is no workaround.

4 24.1.0
35986423 Both IGW pod protection and overload feature enabled, NSSF is not clearing the overload alerts when overload feature disabled in runtime. NSSF does not clear overload alerts when the overload feature is disabled at runtime, even though IGW pod protection and overload feature were initially enabled. There is no impact on traffic.

Workaround:

There is no workaround.

4 23.3.0
35986361 NSSF will not modify the weight values in metrics simultaneously if the weight value changes. The weight metric has changed when any pod raises a new alarm. NSSF does not update the weight values in metrics simultaneously when the weight value changes, instead, the weight metric is updated only when a new alarm is raised. There is no impact on traffic, as NSSF takes care of the condition, but the alert is subsided only when there is a change in state.

Workaround:

There is no workaround.

4 23.3.0
35855377 The abatementValue less than onsetValue should be validated by NSSF in the Overload Level Threshold Configuration. NSSF does not validate that the abatement value is less than the onset value in the Overload Level Threshold Configuration, allowing invalid configurations to be successfully applied. There is no impact on traffic.

Workaround:

Configure NSSF with proper values as per Oracle Communications Cloud Native Core, Network Slice Selection Function REST Specification Guide.

4 23.3.0

4.3.7 OCCM Known Bugs

Release 25.1.202

OCCM 25.1.202 is a Critical Patch Update. Critical Patch Updates provide security patches for supported Oracle on-premises products. They are available to customers with valid support contracts. For more information, see Critical Patch Updates, Security Alerts, and Bulletins.

There are no known bugs in this release.

Release 25.1.201

There are no known bugs in this release.

Release 25.1.200

There are no known bugs in this release.

4.3.8 Policy Known Bugs

Release 26.1.201

Table 4-62 Policy 26.1.201 Known Bugs

Bug Number Title Description Customer Impact Severity Found in Release
38618989 Exported General Settings show incorrect values Exported General Settings can show parameters that do not match the CM UI. Enhanced Logging and Truncate Stack Trace fields can be duplicated or appear in the wrong configuration section.

Settings can show parameters in sections that do not match the CM UI. Enhanced Logging and Truncate Stack Trace fields can be duplicated or appear in the wrong configuration section. Running services, configuration processing, and CM UI behavior are not affected. Exported Swagger data can differ from the UI and confuse API or export consumers.

Workaround:

Use enhancedLogging.enableEnhancedLogging and enhancedLogging.enableLogUEIdentifierInfo for Enhanced Logging. Use truncateStackTrace.enableTruncateStackTrace and truncateStackTrace.stackTraceLines for Truncate Stack Trace. Ignore duplicated legacy fields under enhancedLogging.

3

25.2.200

39148659 UE UDR PATCH retries select an incorrect NF instance After a UE Policy Association Update, the UDR connector can blocklist or select the wrong UDR NF instance when retrying UE UDR PATCH requests. Retries can target an inappropriate instance before another available instance is selected.

UE Policy PATCH updates can fail intermittently during UDR failover and failover latency can increase when alternate routing is used

Workaround:

A configuration-only workaround does not fully resolve this issue. Remove failed or unhealthy UDR instances from NRF or profile availability quickly. Ensure DataSourceInfo.uri is populated by propagating 3gpp-Sbi-Target-apiRoot or the route URI. Increasing retry resiliency provides mitigation only.

3

25.2.200

39433380 AppInfo probes database replication status when the check is disabled AppInfo can probe the database replication status URI and log replication probe failures even when replicationStatusCheck is set to false, if the configured replication URI cannot be resolved.

AppInfo can report an incorrect replication status to the NF.

Workaround:

Configure replicationUri correctly.

3

26.1.200

39523948 PCF does not correctly reject invalid AppSessionContextReqData values PCF can accept Policy Authorization requests with invalid AppSessionContextReqData values or reject them with an incorrect status, cause, title, or missing invalidParams. Malformed fields can return 201 Created, 500, or ERROR_REQUEST_PARAMETERS instead of the expected 400 response.

Valid Policy Authorization requests are not affected. Malformed N5 Policy Authorization requests can be accepted or receive an incorrect 3GPP error response.

Workaround:

No workaround is required for valid traffic. Correct malformed requests at the AF before sending them to PCF.

3

26.1.200

39533145 PCF does not correctly reject invalid TypeMediaComponent values PCF can accept or incorrectly reject Policy Authorization requests with invalid optional TypeMediaComponent values. Malformed media-component fields can return 201 Created or a 400 response with an incorrect cause or title.

Valid Policy Authorization requests are not affected. Malformed N5 Policy Authorization requests can be accepted or receive an incorrect 3GPP error response.

Workaround:

There is no workaround required for valid traffic. Correct malformed requests at the AF before sending them to PCF.

3

26.1.200

39540953 PCF does not correctly reject invalid TypeMediaSubComponent values PCF can accept or incorrectly reject Policy Authorization requests with invalid optional TypeMediaSubComponent values. Malformed media-subcomponent fields can return 201 Created or a 400 response with an incorrect cause or title.

PCF does not return the expected 400 Bad Request, cause, and title for malformed Policy Authorization requests that include incorrect TypeMediaSubComponent values.

Workaround:

There is no workaround required for valid traffic. Correct malformed requests at the AF before sending them to PCF.

3

26.1.200

39629291 PCRF does not remove Event-Trigger AVPs from CCA-I responses PCRF can continue to send Event-Trigger AVPs in CCA-I responses when the configuration is intended to remove all event triggers, if the incoming request indicates ADC support.

The system does not support NO_EVENT_TRIGGERS or suppression of other native or default Event-Triggers by supported features or interfaces.

Workaround:

There is no workaround.

3

25.2.200

39729474 SM does not propagate message-priority headers to dependent Binding requests SM can omit the 3gpp-sbi-message-priority and oc-message-priority headers on RX-dependent Binding requests during PA Create and PA Delete flows.

SM does not propagate the received priority as an internal oc-message-priority header to dependent Binding requests. Binding Service still assigns its own congestion-control priority for dependent-context operations.

Workaround:

If you need different priority handling for dependent-context registration or deregistration traffic, configure the Binding Service advanced settings for those operation priorities.

3

26.1.200

39756967 Usage Monitoring enhanced logs show an unreadable error cause and escaped URI When Usage Monitoring receives a 400 response from PDS, enhanced logs can show an unreadable byte-array value for the error cause and a percent-encoded URI.

Logs provide less diagnostic value and make troubleshooting more difficult. No call failures or stale data are reported.

Workaround:

There is no workaround.
3

26.1.200

39759124 Data Limit Sorting Profile REST API accepts rules without an index The Data Limit Sorting Profile REST API can accept and store a sorting rule without an index. When the required profile name is missing, the API returns HTTP 400 with an empty response.

The API can store incomplete sorting-rule configurations and does not provide sufficient validation information.

Workaround:

There is no workaround.

3

26.1.200

39763764 Export Policy dialog is delayed The Export Policy dialog can take approximately 15–16 seconds to appear after you select the action in CNC Console or the local GUI. The UI provides no immediate processing indication.

The delay provides no immediate visual confirmation that the action is received or processing.

Workaround:

There is no workaround.

3

26.1.200

39776023 UPSI create REST API rejects an existing URSP rule name The UPSI create REST API can return HTTP 400 when you provide an existing URSP rule by name. Exported configurations reference URSP rules by name instead of by internal UUID.

UPSI REST configuration creation fails.

Workaround:

Use the URSP UUID when you create UPSI through the REST API.

3

26.1.200

39779771 Policy Library export returns HTTP 404 when no data exists The Policy Library export endpoint returns HTTP 404 when no Policy Library data exists, although the documented operation specifies HTTP 200.

Policy Library REST export returns HTTP 404

Workaround:

Policy Library is deprecated and no longer in use. It will be removed in a future release.

3

26.1.200

39795244 SM service assigns an incorrect priority to cleanup requests When a cleanup request has no oc-message-priority header, SM service sets priority 18 instead of the configured default priority 20 and propagates it to downstream services.

If downstream congestion control is enabled, downstream services accept or reject cleanup requests based on priority 18 instead of the intended default priority 20.

Workaround:

Set the required value by using the REQUEST_PRIORITY_FOR_SM_CLEANUP key in SM Service advanced settings. For example:

key: REQUEST_PRIORITY_FOR_SM_CLEANUP

value: 20

3

26.1.200

39797452 SM Update Notify message priority is inconsistent Internally generated SMF Update Notify requests do not retain the original 3gpp-sbi-message-priority header because they are created as new internal reauthorization requests.

Message Profile attribute filters that rely on the priority header do not match these requests, so the configured priority is not evaluated from the intended Message Profile rule.

Workaround:

Create a message-profile rule for:

{}Interface: Npcf_SMPolicyControl

Message type: Update Notify

Configure the rule with Request Priority Override = IfNotPresent.

This lets the profile apply its configured priority when the internally triggered SMF Update Notify does not carry the original 3gpp-sbi-message-priority header. For normal requests that do contain the header, the incoming 3GPP priority remains available and is not overridden by this fallback rule.

3

26.1.200

4.3.9 SCP Known Bugs

SCP 25.1.205 Known Bugs

There are no new known bugs in this release. Known bugs from 25.1.200 have been forward ported to release 25.1.205.

SCP 25.1.204 Known Bugs

There are no new known bugs in this release. Known bugs from 25.1.200 have been forward ported to release 25.1.204.

SCP 25.1.203 Known Bugs

There are no new known bugs in this release. Known bugs from 25.1.200 have been forward ported to release 25.1.203.

SCP 25.1.202 Known Bugs

There are no new known bugs in this release. Known bugs from 25.1.200 have been forward ported to release 25.1.202.

SCP 25.1.201 Known Bugs

There are no new known bugs in this release. Known bugs from 25.1.200 have been forward ported to release 25.1.201.

Release 25.1.200

Table 4-63 SCP 25.1.200 Known Bugs

Bug Number Title Description Customer Impact Severity Found in Release
38154297 trafficFeed_attempted_total metric in SCP is intermittently pegged with an unknown value for the NFServiceType dimension during Notification RxRequest During a pipeline run on a freeway setup, the trafficfeed_attempted_total metric was observed to be consistently pegged with the NFServiceType value set to "unknown" intermittently.

It has a minor observability impact due to the dimension service type being NA in the metric for a few requests.

Workaround:

None

3 25.1.200
38152282 Certificate Reload Issue in netty context after patching The SslProviderObject caused a NullPointerException during certificate reload in the Netty context, leading to a failure in context reload.

The certificates will not be updated for downstream connections on certificate reload.

Workaround:

Restart the SCP-Worker pod.

3 25.1.200
38112967 "ocscp_authority" dimension missing in "ocscp_metric_http_rx_res_total" metric

The ocscp_authority dimension is missing from the following metrics:

  • ocscp_metric_http_tx_req_total
  • ocscp_metric_http_rx_req_total
  • ocscp_metric_http_tx_res_total
  • ocscp_metric_http_rx_res_total

It has a minor observability impact due to a dimension invisible in one of the metrics.

Workaround:

None

3 24.3.0
38071919 Port is not derived from NFProfileLevelAttrConfig in case of ModelD Notification and SCP does AR using hardcoded port 80 When a Model-D notification is received, the port is not correctly derived from NFProfileLevelAttrConfig, resulting in SCP using a hard-coded port 80 for alternate routing.

The default port 80 is used irrespective of scheme for notification routing. Also, the port and scheme for the profile level FQDN or IP are not considered. The impact is limited to routing of non-default notification messages as part of Model-D.

Workaround:

None

3 25.1.200
38008367 Overlapping regex validation missing for apiSpecificResourceUri in routing config API The routing configuration REST API allows overlapping regex patterns in the apiSpecificResourceUri field, leading to ambiguous routing when a request matches multiple patterns.

There is conflicting routing config set selection in case of overlapping regex in apiSpecificResourceUri.

Workaround:

Overlapping regex should not be configured.

3 25.1.100
37995299 SCP not able to delete foreign SCP routing details post deregistration When a foreign SCP profile is unregistered, SCP fails to remove the associated routing details for certain profiles.

Some foreign SCP routing rules are not cleared if nfsetId is updated.

Workaround:

None

3 25.1.200
37970295 Worker pod restart observed due to coherence timeout when single cache pod is used When increasing the number of worker pods from 1 to 23 with only one cache pod in use, worker pods restart due to coherence timeout.

It does not have any impact as SCP redeployment is required to update nfsetid and not a recommended change.

Workaround:

None

3 25.1.200
37969345 topologysourceinfo REST API is not case sensitive for nfType When updating the Topology Source of an NF Type from LOCAL to NRF using the PUT method, the REST API successfully processes the request without errors, but SCP triggers an on-demand audit with nfType=udm, resulting in empty NF responses.

The REST API with a case not matching the 3GPP specified NFType would result in an empty response.

Workaround:

Provide NFType as per the 3GPP standard.

3 23.4.0
37951970 Unable to edit services of the Registered NF's even if TSI is changed to Local The services of the registered NFs cannot be edited even if Topology Source Information (TSI) is changed to Local.

The services of the registered NFs cannot be edited after Topology Source Information (TSI) is changed to Local.

Workaround:

Profiles can be deleted, and then updated profiles can be added.

3 25.1.200
37949191 ocscp_metric_nf_lci_tx_total metric is incrementing even when no LCI headers are received from peer NFs The ocscp_metric_nf_lci_tx_total metric incorrectly increments even when no LCI headers are received from peer NFs.

It has a minor observability impact.

Workaround:

None

3 25.1.200
37887650 Crash observed on SCP-Worker with traffic feed enabled with 2 trigger points when Traffic exceeds 7K req/sec When traffic feed is enabled with two trigger points, the SCP-Worker crashes if traffic exceeds 7K requests per second.

The SCP-Worker pod restarts when the traffic feed requests are overloaded.

Workaround:

Traffic is redistributed to other pods.

3 25.1.200
37622431 Audit failures observed during overload situation when traffic is operating at maximum rated capacity and surpasses the pod limits by 50%. When traffic is operating at maximum rated capacity and exceeds the pod limits by 50%, audit failures are observed while SCP is in the overload condition.

In overload conditions, SCP-Worker pod protection mechanism discards some of the internally generated NRF audit requests.

Workaround:

Audit is periodic in nature and eventually successful when the overload condition subsides.

3 25.1.100
37575057 Duplicate Routing when producer responses with location header in 3xx cases SCP performs duplicate routing when the producer NF responds with the location header in 3xx cases.

SCP will send requests to producer NF again if the producer NF in redirect URL and alternate routing rules are the same.

Workaround:

None

3 25.1.100
36757321 Observed 429's due to pod overload discards during upgrade from 24.1.0 to 24.2.0-rc.5 During an upgrade from SCP 24.1.0 to 24.2.0, five worker nodes consumed more than six vCPUs while handling 60K MPS, resulting in the generation of 429 errors.

Some discards might be observed during an upgrade in case of bursty traffic due to the SCP-Worker pod protection mechanism.

Workaround:

It is recommended to perform an upgrade during low traffic rate to avoid pod overload.

3 24.2.0
36600245 SCPIgnoreUnknownService Alerts is not getting raised for all the ignored services at SCP The SCPIgnoreUnknownService alert is not raised for all ignored services, with only the first ignored service triggering an alert.

An alert will not be raised for the first occurrence of an unknown service.

Workaround:

The INFO alert is raised from the second occurrence onward with minimal impact.

3 24.2.0
38188009 In case of scale down of NRF proxy/mediation pods, scp-worker map keep sending message to old IP Address of already deleted nrfproxy pod. SCP-Worker keeps sending messages to old IP addresses of already removed nrfproxy or mediation pods.

Some inter-microservices requests might be impacted if sent to stale destinations.

Workaround:

Restart SCP-Worker or other pod that displays this behavior where it's unable to establish any connection with other services so that the discovery of target service pods can be refreshed.

3 25.1.200
38098107 SCP is Not considering Version and Trailer fields from Jetty response SCP is not considering version and trailer fields from Jetty responses.

It does not have any impact as fields are not currently used.

Workaround:

None

4 25.1.200
38088638 Unexpected Increment in ocscp_metric_req_nf_unhealthy_total Metric During producer marked as OD in DS setup When AUSF is marked as an outlier after receiving 10 messages from SCP, the ocscp_metric_req_nf_unhealthy_total metric is incorrectly incremented three times instead of the expected two times.

It has a minor observability impact.

Workaround:

None

4 25.1.200
38079614 SCP All Services: Remove use of java.util.date and org.joda.time. Use java.time instead because of threadsafety and better method list.. SCP services relies on java.util.date and org.joda.time for date and time handling, which are not thread-safe and lack modern functionality.

It does not have any impact as it is a minor code enhancement.

Workaround:

None

4 25.1.200
38066384 INVALID_OR_EMPTY_DETAILS errors seen on SCP worker post upgrade of setup to 25.1.200-rc.53 from 25.1.100 INVALID_OR_EMPTY_DETAILS errors are observed on SCP-Worker after upgrading SCP from 25.1.100 to 25.1.200.

Occasional calls from the SCP-Worker pod to get routing rules (custom objects) from notifications have failed. These calls occur every 1 second. Therefore, changes in routing rules might take 1 second more to get realized on SCP-Worker.

Workaround:

None

4 25.1.200
38031000 SCP is selecting the alternate destination on the bases of NF_SET even alternateNFGroupRoutingOptions mode is DNS_SRV and altRoutingDnsSrvModeSupported flag is false When the alternateNFGroupRoutingOption mode is set to DNS_SRV and altRoutingDnsSrvModeSupported is false, SCP incorrectly selects an alternate route with the same setID.

In a specific configuration, SCP performs alternate routing based on NFSET, however, it should not happen, as the selected mode of alternate routing is DNS_SRV and altRoutingDnsSrvModeSupported set to false.

Workaround:

Keep service-based alternate routing as false.

4 25.1.200
38004328 Installation guide has incorrect definition of mediation_status parameter The mediation_status parameter was incorrectly set to true in the custom.values.yaml file configuration. This configuration is intended for production use, which may lead to unintended behavior or errors when deployed.

The SCP NF profile that is getting registered with NRF can have the mediation_status attribute, which is not required. It has no functional impact.

Workaround:

This attribute can be commented in the SCP deployment file.

4 25.1.100
37627403 Incorrect Message is getting populated when query parameters are given as nf-type="PCF" under NF Rule Profile Data Section When querying with the nf-type="PCF" parameter under the NF Rule Profile Data section, an incorrect error message is displayed, to check the NFTypes-NFServices table, even though PCF nf-type details are available in SCP.

It does not have any functional impact. Only error message correction is required.

Workaround:

None

4 25.1.100
37543889 SubscriptionInfo is getting ignored in case if User comments out customInfo in NRF Details. If the customInfo field is commented out in the NRF profile within the deployment values.yaml file and subscriptionInfo is set to true with a specified scheme, the code incorrectly ignores the provided scheme and instead extracts the scheme from ScpInfo.

This issue appears only if the customInfo section of NrfProfile is removed from the deployment file.

Workaround:

The subscriptionInfo parameter is documented in Oracle Communications Cloud Native Core, Service Communication Proxy Installation, Upgrade, and Fault Recovery Guide should not be deleted.

4 25.1.100
36926043 SCP shows unclear match header and body in mediation trigger points In the Mediation Trigger Points feature, SCP displays unclear text instead of the expected match header and body information.

It does not have any functional impact.

Workaround:

None

4 24.2.0

4.3.10 SEPP Known Bugs

Release 25.1.204

There are no known bugs in this release.

Release 25.1.203

There are no known bugs in this release.

Release 25.1.202

There are no known bugs in this release.

Release 25.1.201

There are no known bugs in this release.

Release 25.1.200

Table 4-64 SEPP 25.1.200 Known Bugs

Bug Number Title Description Customer Impact Severity Found In Release
37482876 429 error code is being returned despite 428 being configured for rate limiting at SEPP_25.1.0-rc1

The system returns a 429 error code when rate limiting is triggered. The expected behavior is to return error code 428 as defined in the global rate limiting policies. This inconsistency may cause issues in error handling and monitoring processes.

Base Bug on Gateway 37497519

Users receive a 429 error code instead of the configured value. This discrepancy prevents any automated actions or responses that rely on the expected error code from being triggered, potentially affecting service reliability and user experience.

Workaround:

There is no workaround available.

3 25.1.100
37818065 ERRORs being reported in SEPP plmn egw pod logs intermittently

PLMN Egress Gateway pods intermittently display a "Watcher exception" error, even in the absence of traffic. The error message indicates "too old resource version," with specific values varying, such as "464623931 (554740871)." This issue occurs unexpectedly and may impact the stability of the Egress Gateway pods.

Base Bug on Gateway 38082705

The PLMN egress gateway pod generates excessive and unnecessary log entries.

Workaround:

There is no workaround available.

4 25.1.100
38015469 SEPP 25.1.100 Custom Values does not expose all containerPortNames The ocsepp_custom_values_25.1.100.yaml file does not include all the required containerPortNames necessary for provisioning backendPortName in the CNLB annotations. This omission prevents the correct configuration of backend ports, potentially leading to connectivity issues. Users are required to manually add parameter and port configurations in the ocsepp_custom_values_25.1.100.yaml file.

Workaround:

Users must manually add the required port in the ocsepp_custom_values_25.1.100.yaml file.

4 25.1.100
37969620 Internal server error from SEPP when the payload is bigger than 262144 bytes

An internal server error in SEPP when the payload size exceeds 262,144 bytes and the Content-Type is not set to application/problem+json. The request gets rejected with a 500 Internal Server Error. The expected behavior is to reject such requests with an HTTP 413 Payload Too Large error, as requests with payloads larger than 262,144 bytes should not be routed through SEPP.

SEPP is able to process messages with size bigger than 262144.

The response generated is not in JSON format, and the server header is missing from the response.

Workaround:

There is no workaround available.

3 25.1.100

Table 4-65 SEPP 25.1.200 Gateway Known Bugs

Bug Number Title Description Customer Impact Severity Found In Release
35898970 DNS SRV Support- The time taken for cache update is not same TTL value defined in SRV record.

The time taken to update the cache does not align with the Time-To-Live (TTL) value defined in the SRV records. In some cases, the cache updates before the TTL expires, while in others, it updates after the TTL has passed.

Expected Behavior

The cache should update strictly according to the TTL value specified in the SRV records. For example, if the TTL is set to 60 seconds, the cache must update exactly after every 60-second interval, ensuring consistency with the defined TTL.

When the priority or weight of a record is changed, the cache update may take longer than the defined Time-To-Live (TTL) value. This delay causes the changes to reflect in the environment later than expected.

Workaround:

  1. After modifying the configuration, restart the n32-egress-gateway service.
  2. Restart the alternate-route-svc service to ensure all changes are properly applied.
3 23.4.0
35919133 DNS SRV Support- Custom values key "dnsSrvEnabled" does not function as decsribed

The description for the custom values key dnsSrvEnabled indicates it is a flag to control whether DNS-SRV queries are sent to CoreDNS. If the flag is set to true, DNS-SRV queries should be sent to CoreDNS. If the flag is set to false, DNS-SRV queries should not be sent to CoreDNS.

Issue:

Even when the flag is set to false and the setup is upgraded, the curl request still reaches CoreDNS.

Scenario:

The flag dnsSrvEnabled is set to false, and a peer configuration is created for a Virtual Fully Qualified Domain Name (FQDN). The expectation is that running a curl command should not resolve the Virtual FQDN because the flag is false, and the request should not reach CoreDNS. However, the request is still being sent to CoreDNS, contrary to the expected behavior.

For virtual Fully Qualified Domain Names (FQDNs), queries are always directed to CoreDNS, regardless of the configuration settings.

Workaround:

Do not configure records in coreDNS

Configuring records in CoreDNS may lead to unintended behavior.

3 23.4.0
36263009 PerfInfo calculating ambiguous values for CPU usage when multiple services mapped to single pod

In cgroup.json file, multiple services are mapped to a single endpoint. Calculation of CPU usage is ambiguous. This impacted the overall load calculation

In the cgroup.json file, multiple services are mapped to a single endpoint. This configuration leads to ambiguity in calculating CPU usage for individual services.

The overall load calculation is inaccurate.

Workaround:

There is no workaround available.

3 23.4.1
36672487 No error thrown while enabling Discard Policy Mapping to true when corresponding discard policy is deleted

No error is thrown when enabling Discard Policy Mapping to true for a discard policy that has been deleted.

Steps to Reproduce:

  1. Delete the discard policy named "Policy2" in the Overload discard policies of the n32 IGW.
  2. Enable Discard Policy Mapping to true for the policy name "Policy2".

The configuration is saved successfully without any error, even though the discard policy "Policy2" has been deleted.

If a user enables discard policy mapping but the corresponding discard policy does not exist, the system does not display an error message.

Workaround:

Users can configure overload discard policies using Helm configuration. This functionality is available and does not cause any known issues.

3 24.2.0
36605744 Generic error is thrown when wrong configuration is saved via GW REST APIs A generic error message ("Could not validate JSON") is displayed when an incorrect configuration is saved via the Gateway REST API or CNC Console Screen. The error message does not specify which mandatory parameter is missing or incorrectly configured, making it difficult for users to identify and resolve the issue. When a generic error occurs, users may find it difficult to identify and troubleshoot the root cause of the issue.

Workaround:

There is no workaround available.

3 24.2.0
36614527 [SEPP-APIGW] Overload Control discard policies not working with REST API and CNCC

Users are unable to edit or change the default values for Overload Control discard policies. An error is thrown stating, "ocpolicymapping does not contain this policy name" when attempting to save the configuration.

This behavior is observed both when using the CNC Console Screen and when attempting to update the configuration via the REST API.

Users cannot edit overload discard policies through the CNC Console. This limitation restricts the ability to modify these policies directly via the console interface.

Workaround:

Users can configure overload discard policies using Helm configuration.

3 24.2.0

4.3.11 UDR Known Bugs

Release 25.2.201

There are no new known bugs in this release. Known bugs from 25.2.100 have been forward ported to release 25.2.201.

4.3.12 Common Services Known Bugs

4.3.12.1 ATS Known Bugs

Release 25.1.200

There are no known bugs in this release.

4.3.12.2 ASM Configuration Known Bugs

Release 25.2.100

There are no known bugs in this release.

4.3.12.3 Alternate Route Service Known Bugs

Release 25.1.2xx

There are no known bugs in this release.

4.3.12.4 Egress Gateway Known Bugs

Release 25.1.2xx

Table 4-66 Egress Gateway 25.1.2xx Known Bugs

Bug Number Title Description Customer Impact Severity Found in Release
37751607 Egress gateway throwing NPE when trying to send oauth token request to "Default NRF Instance" when unable to find NRF instance to forward the request Egress Gateway failed to send requests to the configured primaryNrfApiRoot and secondaryNrfApiRoot endpoints specified in the configmap. Subsequently, it attempted to send an OAuth2 token request to the default NRF instance at "[http://localhost:port/oauth2/token]," but this request also failed. Egress Gateway displayed a NullPointerException. This issue occurs only when an invalid host and port are provided. The port is mentioned with string value as "port" instead of a numeric port value, for example, 8080.

Workaround:

You must provide the valid host and port for the NRF client instance.

3 25.1.200
37886642 Peer configuration and peer set configuration does not work properly in REST mode The REST API mode revealed issues with the
oc_egressgateway_peer_health_status
metric, where health status updates failed under various peer configuration changes, including dynamic-to-static transitions, FQDN updates, blank configurations, and static-to-dynamic switches. These inconsistencies resulted in incorrect health status data being displayed.
When peer and peerset are configured as blank through the REST mode, oc_egressgateway_peer_health_status of peers do not change. It remains at its previous state.

Workaround:

You must restart the Egress Gateway pods.

3 25.1.200
36730017 Register request towards alternate-route is giving incorrect response of 200 While performing the register request, Gateway Services received a 200 OK response, where the FQDN entry is not present in the DNS server. While performing Alternate Route Services register request, success response is received when the FQDN entry is absent in the DNS server.

Workaround:

There is no workaround available.

4 24.1.0
4.3.12.5 Ingress Gateway Known Bugs

Release 25.1.2xx

Table 4-67 Ingress Gateway 25.1.2xx Known Bugs

Bug Number Title Description Customer Impact Severity Found in Release
36464641 When feature Ingress Gateway POD Protection disabled at run time alerts are not getting cleared and metrics are getting pegged in NRF 23.4.0 When the Ingress Gateway Pod Protection feature is disabled at run time, alerts are not getting cleared and metrics are getting pegged in NRF 23.4.0. Alerts are not getting cleared and metrics would be pegged even when feature is disabled during run time.

Workaround:

There is no workaround available.

3 23.4.0
35526243 Operational State change should be disallowed if the required pre-configurations are not present Currently, the operational state at Ingress Gateway can be changed even if thecontrolledshutdownerrormapping and errorcodeprofiles are not present. This indicates that the required action of rejecting traffic will not occur. There must be a pre-check to check for these configurations before allowing the state to be changed. If the pre-check fails, the operational state should not be changed. Request will be processed by Gateway Services when it is supposed to be rejected.

Workaround:

There is no workaround available.

3 23.2.0
34610831 IGW is accepting incorrect API names with out throwing any error Ingress Gateway is accepting incorrect API names without displaying any error. If there is a typo in the configuration UDR, the command should get rejected. Otherwise, it gives the wrong impression that the configuration is correct but the desired behavior is not observed. The non-existing resource name would be pretended to be successfully updated in REST configurations.

Workaround:

There is no workaround available.

3 22.2.4
36605744 Generic error is thrown when wrong configuration is saved via GW REST APIs

When saving incorrect configurations through the Gateway Services REST API or CNC Console, a generic error, "Could not validate JSON", is displayed instead of providing specific details about the missing mandatory parameters.

A generic error makes it difficult for the user to troubleshoot the issue.

Workaround:

There is no workaround available.

3 24.2.0
37986338 For XFCC header failure case "oc_ingressgateway_http_responses_total" stats are not updated When deploying Ingress Gateway with XFCC header validation enabled in a three-route configuration (for create, delete, and update operations), and sending traffic without the XFCC header, Ingress Gateway rejected the traffic due to XFCC header validation failure. However, the
oc_ingressgateway_http_responses_total
metric was not updated, but the
oc_ingressgateway_xfcc_header_validate_total
metric was updated.
The metric will not be pegged when the XFCC header validation failure is observed.

Workaround:

There is no workaround available.

4 25.1.200
4.3.12.6 Common Configuration Service Known Bugs

Release 25.1.2xx

There are no known bugs in this release.

4.3.12.7 Helm Test Known Bugs

Release 25.2.1xx

There are no known bugs in this release.

4.3.12.8 Mediation Known Bugs

Release 25.2.100

There are no known bugs in this release.

4.3.12.9 NRF-Client Known Bugs

Release 25.1.2xx

There are no known bugs in this release.

4.3.12.10 App-Info Known Bugs

Release 25.2.1xx

There are no known bugs in this release.

4.3.12.11 Perf-Info Known Bugs

Release 25.2.1xx

There are no known bugs in this release.

4.3.12.12 Debug Tool Known Bugs

Release 25.2.1xx

There are no known bugs in this release.