Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX running Junos Evolved Software

Alert Description

Junos Software Service Release version 21.4R1-S2-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 21.4R1-S2-EVO is now available.

21.4R1-S2-EVO - List of Fixed issues

PR NumberSynopsisCategory: "agentd" software daemon
1641949[Telemetry] Filtering option for components name(CHASSIS, SIB) fails with /components/component sensor subscription.
Product-Group=evo
On the EVO platform, subscription with FRU filter on leafs for path/components might not work.
PR NumberSynopsisCategory: PTX10003 Interface related issues
1615000PTX10003 Evo-aftmand process sees memory increasing linerally over days
Product-Group=evo
PTX10003 Evo-aftmand process sees memory increasing linearly over days
PR NumberSynopsisCategory: PTX10003 Platform related issues
1654762[PTX10003] SSD DGM28-B56D81BCBQ || RE 0 SSD Primary minimum supported firmware version mismatch
Product-Group=evo
PTX10003 may show alarm "RE # SSD Primary minimum supported firmware version mismatch" if the routing-engine is installed with Innodisk SSD.
PR NumberSynopsisCategory: PFE COS features on BT based platforms
1649612Null pointer during resiliency 'get-state' commands if an ASIC raises a fatal interrupt when evo-cda-bt did not start properly.
Product-Group=evo
PR is for PTX-10004/8/16 EVO (FPCs that use BTchip). Trigger involved an ASIC having a fatal (or major?) interrupt (alarm), that HW fault triggers 'get-state' script, which issues cli-pfe "show cda qpoll interfaces xxx", which used a null pointer because something killed the ASIC during the 'get-state' script. Maybe the 'get-state' script took too long and the system proceeded to restart the ASIC. Since we do not have reproduction of this race, it is unknown how rare this core would be; leaving risk as 'Major'. Disabling the 'get-state' script for all ASIC errors impacts serviceability in other ways, so that is not a good workaround. Leaving Workaround: Not-possible.
PR NumberSynopsisCategory: Express BT PFE L3 Features
1651932An error might be seen when the member link on an AE bundle is deleted
Product-Group=evo
On all EVO PTX platforms, gRPC connection between the "evo-aftmand" process and the "cda" process maybe disconnect with the messages "[Error] CDA: exprGrpcAsyncApi: failed cq read", and "GOAWAY with error code ENHANCE_YOUR_CALM". When the disconnection happens, the Junos Evolved system can no longer retrieve status or programs forwarding ASICs. This is a catastrophic failure.
1652651P2MP traffic loss might be seen when link protected LSP revert back to the primary path
Product-Group=evo
On EVO PTX, P2MP traffic drop might be seen when Resource Reservation Setup Protocol (RSVP) signaled LSP reverts back to the Primary path. When the primary link is down packet drop (~10ms) might be seen which is as expected. But when the primary link is UP again and the Label-Switched Path (LSP) reverts from the backup path to the primary path a small packet drop (~1ms) is observed.
1657532The evo-aftmand-bt crash might be observed on EVO platforms
Product-Group=evo
On all EVO platforms, when the same firewall filter is applied to an ingress as well the egress direction, the evo-aftmand-bt crash might be observed, if the firewall filter is activated or deactivated a few times(4-5 times).
1657584PTX10008 EVO : Family MPLS Firewall filter not working on ingress
Product-Group=evo
PTX10008 EVO JNP10K-LC1201 line card does not support family MPLS firewall filter on egress due to hardware limitation. Although it is not supported on egress, we can configure it on the egress of an interface with 'fast-lookup-filter' option. If we switch the family MPLS filter configuration from egress to ingress, it will lose the functionality. This issue only occurs when the 'fast-lookup-filter' is attached to the ingress of an interface, because the option is not supported on ingress. The family MPLS firewall filter on ingress will recover the functionality by restarting the FPC on which the filter is configured. After code fix, 'fast-lookup-filter' is no-op on ingress family MPLS firewall filter, so that we can still configure the filter to the ingress.
PR NumberSynopsisCategory: EVO Class of Services
1652342Show Class-of-service Interface may not show the Classifier bind info on an IFL with only Inet/Inet6 (without family mpls or not with any rewrite rules)
Product-Group=evo
Show Class-of-service Interface may not show the Classifier bind info on an IFL with only Inet/Inet6 (without family mpls or not with any rewrite rules). Show issue, Classifier will be still present and functional. No impact to the traffic
PR NumberSynopsisCategory: EVO Netstack DDoS (ddosd and JTD)
1649034EVO platforms might throw error logs like [Error] Jexpr: getDdosTableEntry unsupported proto:0x0
Product-Group=evo
In EVO platforms while collecting debug logs, the following errors might be seen which do not have any functionality impact: [Error] Jexpr: getDdosTableEntry unsupported proto:0x0. These can mostly be noticed when the platform boots up.
PR NumberSynopsisCategory: Issues related to evo operations - libevo infra, typeinfo ..
1657797The rpd might fail on backup RE on EVO platforms
Product-Group=evo
On all EVO chassis platforms with NSR(Nonstop-routing) enabled, the rpd(routing protocol daemon) on backup RE might fail to start upon system bootup. This will impact the redundancy, as the routing might not happen on backup RE, if switchover happens.
PR NumberSynopsisCategory: Lacp related problems and issues.
1647145The lacpd may not come up on one of the links in the AE bundle
Product-Group=evo
On EVO platforms during lacpd process restart, child IFD indexes from the port options IFD based data which gets stored in kernel by lacpd, might not get reused due to old indexes weren't freed. When this occurs, new indexes may be generated repeatedly which could cause the port numbers exhaustion problem in AE (Aggregated Ethernet interface) bundle.
PR NumberSynopsisCategory: Configd, ffp issues
1617667PTX10001-36MR :: configd publish deleted anomalies seen while running p2mp rsvp eoam test
Product-Group=evo
After configuring and deleting the "chassis aggregated-devices" and "set chassis ae aggregated-ether-options" configuration stanza, you may see objects show up in the output of the "show platform object anomaly"
1619974The addition/deletion of the gRPC configuration may cause a memory leak in the EDO app
Product-Group=evo
On Junos Evolved platforms, addition and deletion of gRPC related configuration might lead to memory leak in EDO Application.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1642743Ignore the syslog - UI_MOTD_PROPAGATE_ERROR: Unable to propagate login announcement (motd) to /var/etc/motd.junos
Product-Group=evo
An unharmful syslog error message [UI_MOTD_PROPAGATE_ERROR: Unable to propagate login announcement (motd) to /var/etc/motd.junos] is seen in EVO in case someone configures "system login announcement". There is no functional impact and the error message can be ignored.
PR NumberSynopsisCategory: SNMP, mib2d issues
1636338Junos OS Evolved: A remote attacker may cause a CPU Denial of Service by sending genuine traffic to a device on a specific IPv4 port. (CVE-2022-22183)
Product-Group=evo
An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker who is able to connect to a specific open IPv4 port, which in affected releases should otherwise be unreachable, to cause the CPU to consume all resources as more traffic is sent to the port to create a Denial of Service (DoS) condition. Please refer to https://kb.juniper.net/JSA69516 [juniper.net] for more information.
PR NumberSynopsisCategory: Express PFE FW Features
1618211Match on v6-prefix for prefix lengths <= 64 bits is not working. Prefix-lens of [128-65] work fine.
Product-Group=evo
With Junos Evolved version 21.3R1 or later, a filter matching on IPv6-prefix for prefix lengths <= 64 bits does not work. Workaround Exists.
1638487NPU util sensor to include FLT consumption for ZX and BT based PTX devices.
Product-Group=evo
NPU util and backpressure sensors are include to indicate the FLT utilization for the ZX and BT based PTX devices. The CLI used is show npu utilization stats filter pfe <>
1649324Firewall counters might not increment for a longer time
Product-Group=evo
Firewall counters may not be displayed increment for some time, on config operations such as adding/modifying a new term to the existing filter using multiple commits in a scaled scenario.
PR NumberSynopsisCategory: FIB telemetry daemon
1653942When fib-streaming is enabled and two or more collectors are involved, fibtd core may be observed due to a timing sync issue
Product-Group=evo
On all junos and EVO platforms, when two or more collectors have subscribed to gAFT sensors on the device, fibtd daemon(forwarding information base processing daemon) observes a core and initial sync with the collectors are lost. This will cause the device to stop streaming telemetry data.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1635009Multipath route getting formed for a VPN prefix due to incorrect BGP route selection logic
Product-Group=evo
On all Junos OS and Junos OS Evolved platforms running BGP, when a specific route is received from multiple places under a VRF, multipath route is getting formed even though the BGP route selection algorithm has the active route with higher local preference. Once multipath is formed, the traffic forwarding is happening based on that, and it may result in some traffic going to an unwanted path. Please refer to KB37775 [juniper.net] for more details.
PR NumberSynopsisCategory: PTX10008 EVO Resiliency Improvement
1625305JNP10008-SF3, SIB-JNP10004 and JNP10016-SF3 memory errors handling improvement
Product-Group=evo
This software change improves the SIB3 shared memory error handling. The improved behavior is as follows. Once the software detects a SIB3 multi-bit uncorrectable ECC memory error event, the SIB3 will be offline immediately. The software will no longer attempt to recover the suspected SIB3 by rebooting it. The software does not provide an option to keep the SIB3 offline persistent across reboots via configuration. . (https://kb.juniper.net/TSB18257 [juniper.net])
PR NumberSynopsisCategory: PTX10K specific platform PRs
1654455PTX10008 EVO : show snmp mib get CLI returns incorrect value on jnxLED MIB OIDs
Product-Group=evo
Executing 'show snmp mib get' CLI returns incorrect value on jnxLED MIB OIDs on PTX10008 EVO
PR NumberSynopsisCategory: PTX10K Timing/Sync-E issues tracking
1631300PTX10016 PCIe Bus Error associate to PTP FPGA device during chassis reboot
Product-Group=evo
During system boot-up, you may see a cosmetic PCIe Bus Error message indicated on pcieport 0000:00:02.2 as below, "pcieport 0000:00:02.2: PCIe Bus Error: severity=Corrected, type=Physical Layer, id=0012(Receiver ID)"
1649358PTX10008 EVO SyncE clock 'hold-off-time' configuration not working due to incorrectly computed timer value
Product-Group=evo
On PTX10008 EVO, the SyncE clock 'hold-off-time' configuration does not work due to an incorrectly computed timer value. Only default Hold-off 1000 ms works correctly.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1624562The core files may not get deleted using CLI "file delete /var/core/*/vmcore*"
Product-Group=evo
File delete with regex may fail, if using filename without regex it works.
1627323Junos Fusion Satellite EX4300 upgrade fails from MX104
Product-Group=evo
Junos Fusion Satelite EX4300 upgrade is performed from MX104 as AD with dual REs. The upgrade may get stuck and not responding.
1637552During the ephemeral configuration database changes, mgd core files might be generated
Product-Group=evo
On all Junos platforms, mgd core files might be generated when the ephemeral configuration database changes.
1641025Unable to access configure exclusive mode after mgd process is killed
Product-Group=evo
On all Junos OS and Junos OS Evolved devices, when copy-config, get-configuration, and discard-change RPCs run in two parallel NETCONF sessions and the database is also accessed in parallel by two NETCONF sessions, it leads to database corruption and mgd-related services might crash.
PR NumberSynopsisCategory: Express ZX PFE L3 Features
1648133High inter-packet delay and throughput performance degrade for PFE sensors
Product-Group=evo
In a high scaled system profile, if there are a large number of SR(Segment Routing) routes, and also SR route sensors are configured to stream at low intervals, It might see an overall performance drop of PFE sensors.
 
 

21.4R1-S2-EVO - List of Known issues

PR NumberSynopsisCategory: "agentd" software daemon
1621347On scaling system, load override and commit of baseline cfg can cause RPD sensors uninstallation to fail
Product-Group=evo
On scaling system, load override and commit of baseline cfg causes RPD to spin high on CPU. As GRPC config is removed aswell, sensors needs to be uninstalled. But RPD is not responding to these telemetry sensors uninstallation requests. So sensors uninstallation fails. Later when GRPC is enabled back on box and same sensor profile( cfg .json file used with jtimon) is requested from collector, RPD is sending pkts with higher sequence numbers(Because sensor was not removed from RPD earlier) and this is considered as drops by collectors which rely on sequence-numbers.
1653129fibtd is not sending updates to one of the gaft collectors under certain conditions
Product-Group=evo
When using the fidtd process to update multiple collectors, the fibtd process may stop sending updates if one of the collectors is restarted.
1665516Na-grpcd process can core during longevity flap tests
Product-Group=evo
Due to race condition happening at the time of streaming and simultaneous disconnection of clients, na-grpcd can core at rare ocassions. This will cause temporary outage of streaming telemetry services. The service will self recover upon restart of the process.
PR NumberSynopsisCategory: PFE COS features on BT based platforms
1657848PTX10008/16's shapers Applied over Multiple Queues Under a Port
Product-Group=evo
On PTX-10008 and all its derivative platforms, it would not be able to support more than 2 queues being shaped under a port, using configuration knobs like "exact" & "rate-limit". The minimum transmit-rate for the shaped queues is suggested to be >=5% of the port line rate, else it can possibly impact the overall throughput of the port.
1657883Limitations with Interface level shapers.
Product-Group=evo
When an interface level shapers are applied, it may not draw accurate scheduler accuracy for all the queues under a port.
PR NumberSynopsisCategory: Issues related to debug utilties - objmon,objshell/Dashboard
1649647[CCL] debug-collector not collecting backup re logs when SSH "root-login" config set to "deny"
Product-Group=evo
The "request system debug-info" operational command will fail to get information from other REs in the chassis on systems with multiple routing engines unless the SSH root logins are allowed.
PR NumberSynopsisCategory: EVO linux defects & enhancement requests
1646610Device can panic with VMCORE in high memory pressure situations where kernel memory allocation fails.
Product-Group=evo
Device can panic with vmcore under high memory pressure situations when kernel memory allocation fails on memdup_user().
PR NumberSynopsisCategory: Junos Evolved socket replication
1660685RPD after kill -9 < bfd_pid>, seeing JSR backup registration failed for task BGP_64510.100.160.24.79 error: Returned Generic Error Invalid argument
Product-Group=evo
Without the PR fix, error logs from rpd/kernel corresponding to "JSR backup registration failed" may be observed, however, it self recovers and there is no functional issue expected.
PR NumberSynopsisCategory: Configd, ffp issues
1641960[configd][app]: Observing configd object-info anomalies at net::juniper::config:: chassis:: ChassisAggregatedDevices, net::juniper:: config::interface:: IFDCGigetherOptions, net::juniper ::config:: interface:: IFDCAEOptions
Product-Group=evo
After a config change, the "configd" is still holding on to the shared pointer in DDS preventing complete cleanup of the deleted EVO object. There is no functional impact.
1643192Observing configd object-info anomalies at net::juniper :: config :: interface :: IFDCEtherOptionsCommon
Product-Group=evo
When the configuration related to the "aggregated-ether-options" hierarchies is configured and then deleted, then it leads to these anomalies.
1658688CCL:NGPR: configd core during configd app restart test
Product-Group=evo
When cconfigd restarts, it may fail to do so if the previous instance of cconfigd is in process of exiting. The cconfigd will reattempt the restart. There is no impact on the system operation.
PR NumberSynopsisCategory: Express PFE FW Features
1647237[firewall] [generic_evo] : EVO-Brackla :: filter counter name/action changes are taking more than a min to be effective after committed
Product-Group=evo
Filter counter name/action changes may take up-to a min to be effective after committed under heavy load.
1648923Google_NGPR_FT : EVO-Brackla : Filter is not hit, after removing unsupported match from the filter config
Product-Group=evo
Filter is not hit, after trying to program unsupported combination of match types in filter config.
165865021.4R1-S2-EVO the evo-aftmand process core dump during aggressive AE flap test
Product-Group=evo
21.4R1-S2-EVO evo-aftmand core dump and FPC reset is seen during aggressive AE flap test
PR NumberSynopsisCategory: All Guardian (ACX7509) Linecard (FPC) related issues
1631193[interface] [Guardian] 4x100g channels not coming up after multiple iterations Tx lase disabled alarm on
Product-Group=evo
issue is not specific to guardian and issue is common to EVO platform. We need more time to analyse this issue with optic vendor and fixing in 21.4 is risky now And we have below work around for this issue and will fix this issue in next release 22.1 Work around: Port disable/Enable will bringup the link.
PR NumberSynopsisCategory: MPLS Point-to-Multipoint TE
1654226Route stays Up but LSP state is blown off from the downstream node after there is a second failure on the primary LSP link
Product-Group=evo
After a link-protected LSP undergoes local reversion, the PLR reinstates local (link) protection successfully. However, the LP-MP does not properly detect that its Phop node has signaled itself as the PLR. This causes the downstream node not to properly consider itself as LP-MP. Hence, when there is a second failure on the same link connecting these two nodes, the LSP state is blown off from the downstream node. The downstream node deletes the LSP state and drops traffic arriving on the bypass.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1612487On backup RE during GRES, you may see "RPD_KRT_KERNEL_BAD_ROUTE: krt unsolic client.128.0.0.5+62000: lost ifl 0 for route" warning messages
Product-Group=evo
Several warning messages show up while the RPD process restarts during performing GRES on a system running Junos EVO.
PR NumberSynopsisCategory: Express ZX PFE L3 Features
1655653Multiple rewrite rules AE: (mpls-any and mpls-inet-both-non-vpn are NOT supported on Brackla/Scapa) The order of applying the Rewrite rules is not correct. Non-VPN rewrite rule is getting effect for the VPN traffic
Product-Group=evo
Multiple rewrite rules AE: (mpls-any and mpls-inet-both-non-vpn are NOT supported on PTX running BT ASIC). The order of applying the Rewrite rules is not correct. The non-VPN rewrite rule is getting effect for the VPN traffic - See https://www.juniper.net/documentation/us/en/software/junos/cos/topics/concept/cos-rewriting-mpls-and-ipv4-packet-headers.html

Modification History

First publication 2022-06-01