Pod

Available as Markdown and JSON. Pod is also available over MCP.

Reported issues for oraclemcp

Pod holds 16 of 25 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to oraclemcp.

Most discussed

oracle_query on policy-heavy schema always times out: per-call RLS/VPD probe (ALL_POLICIES) blows the 30s budget

Summary

On a policy-heavy schema, every oracle_query is cancelled at the 30s request budget ({"error_class":"TIMEOUT","message":"request cancelled: Cancelled"}) even for a trivial SELECT 1 FROM dual. Root cause is the per-call RLS/VPD visibility probe (ALL_POLICIES) that oracle_query attaches to every result: on a schema with many active VPD policies that probe alone exceeds the 30s budget and takes the whole read down with it. The database is healthy and plain SELECTs…

Read the thread · 2026-09-28 · open · 0 comments

Connection-failure diagnosability: 'driver detail suppressed', connect trace stops at read ACCEPT, misleading first hint

Field-test report (error-clarity / diagnosability). Observed on OCI connect attempts during the 0.11.0 adoption; the gap is general to connection failures. Sanitized.

Summary

When a connection fails (seen on OCI Autonomous DB profiles), the failure is hard to diagnose:

  1. The client gets Oracle connection failed; driver detail suppressed — the underlying Oracle/driver error is hidden, and there's no documented switch to reveal it.
  2. The suggested ORACLEDB_TRACE_CONNECT=1 trace stops…

Read the thread · 2026-09-23 · open · 0 comments

OCI ADB wallet: default musl build rejects stock wallet (cwallet.sso unsupported / ewallet.pem legacy 3DES-PKCS12)

Field-test report. First observed at v0.7.2 (default musl build); please confirm current status on 0.11.0 (see note). Sanitized.

Summary

The default musl build could not consume a stock, unmodified OCI Autonomous Database wallet:

Read the thread · 2026-09-23 · open · 0 comments

OCI Autonomous DB: post-ACCEPT auth/TTC handshake fails in oraclemcp-driver-cx (on-prem 19c + python-oracledb thin both work)

Field-test report (not a fresh code-traced repro). Observed across install-test rounds up to the 0.11.0 adoption. Sanitized of host/schema/profile names.

Summary

Against an OCI Autonomous Database (mTLS wallet, TCPS EZConnect descriptor), the thin driver oraclemcp-driver-cx 0.9.2 completes TLS + wallet load (cwallet.sso) + TNS ACCEPT, but then fails the post-ACCEPT auth / TTC handshake. On-prem Oracle 19c connects fine with the same driver, so this is specific to…

Read the thread · 2026-09-23 · open · 0 comments

Read-only guard bypass: oracle_sample_rows skips the VPD/purity proof and result-masking

Read-only guard bypass. Reported publicly at the maintainer's direction; see SECURITY.md for the normal private-disclosure path. Confirmed from source at commit 73973b2 (v0.11.0). No database data included.

Summary

oracle_sample_rows reads VPD/policy-protected tables and views that oracle_query refuses, and returns rows without applying the profile's result-masking policy. On a read-only, masking-enforced profile this exposes protected rows and unmasked column values.…

Read the thread · 2026-09-23 · open · 0 comments

Read-only guard bypass: view/VPD/policy objects reachable via a subquery (EXISTS/IN)

Read-only guard bypass. Reported publicly at the maintainer's direction; see SECURITY.md for the normal private-disclosure path. Confirmed from source at commit 73973b2 (v0.11.0). No database data included.

Summary

On a read-only profile, a SELECT can reach a view, a VPD/policy-protected table, or an object with a virtual-column / policy-function dependency — all of which oracle_query refuses at top level — simply by referencing it inside a subquery (EXISTS, IN,…

Read the thread · 2026-09-23 · open · 0 comments

Second serve instance refuses pre-handshake on audit-log lock; client sees only 'Connection closed'

Version

0.11.0 (commit 73973b2).

What happens

Each MCP client session launches its own oraclemcp serve. Starting a second instance for the same user/host fails: the child exits before the MCP handshake with

refusing to start: audit log .../audit/audit.jsonl is locked by another oraclemcp instance (pid N); refusing to fork the hash-chain

on stderr, exit code 2. The MCP client sees only the process die with nothing on stdout → CONNECTION_CLOSED / "Connection…

Read the thread · 2026-09-23 · open · 0 comments

'call timeout of 0 ms exceeded' from head-of-line blocking on the pinned-session mutex

Version

0.11.0 (commit 73973b2). Driver: oraclemcp-driver-cx =0.9.2.

What happens

While one oracle_query is running long, a second oracle_query fails immediately with call timeout of 0 ms exceeded. The "0 ms" is misleading — it is not a zero timeout, it's an already-expired deadline.

Root cause (confirmed in code)

The second request blocks on self.state.lock(cx) behind the long query (dispatch/mod.rs:12118; the comment at :12124 notes the mutex wait counts…

Read the thread · 2026-09-23 · open · 0 comments

Most recent

Long queries emit no progress and notifications/cancelled is ignored (client told cancelled while query succeeds server-side)

Version

0.11.0 (commit 73973b2).

What happens

During a long-running oracle_query, the client receives no progress for the whole duration, and notifications/cancelled is ignored — the statement is never cancelled server-side. In two observed cases the client was told {"error_class":"TIMEOUT","message":"request cancelled: Cancelled"} after ~31s, but the audit log shows the same query SUCCEEDED (rows returned) — i.e. the client believes the read was cancelled while it…

Read the thread · 2026-09-23 · open · 0 comments

call_timeout_seconds=0 silently disables BOTH per-call and whole-request timeouts; Some(0) mappings disagree

Version

0.11.0 (commit 73973b2). Driver: oraclemcp-driver-cx =0.9.2.

What happens

Setting a profile's call_timeout_seconds = 0 — the natural way to say "no per-round-trip limit" — silently also removes the whole-request timeout, so a query can run unbounded (observed: a query ran >30 minutes until the MCP client aborted it). The three timeout mappings also disagree on what Some(0) means.

Root cause (confirmed in code)

call_timeout_seconds = 0 maps to None in two…

Read the thread · 2026-09-23 · open · 0 comments

Pinned session never recovers after idle: protocol-desync errors not classified as connection-lost + no keepalive default

Version

0.11.0 (commit 73973b2). Driver: oraclemcp-driver-cx =0.9.2.

What happens

After the pinned stdio session sits idle (minutes to a couple of hours), the next tool call fails, and keeps failing on every retry, with one of:

Read the thread · 2026-09-23 · open · 0 comments

SCN capability probe runs on every call and is never cached (32% of audited traffic; fails 142/142 where ungranted)

Version

0.11.0 (commit 73973b2)

What happens

The SCN capability probe (scn_capability_probe, the internal DBMS_FLASHBACK.GET_SYSTEM_CHANGE_NUMBER / current-SCN check) runs before every tool call and its result is never cached. In a real two-day audit log it accounted for 142 of 441 entries (32%) and failed 142/142 on databases where that capability isn't granted — including on the very first call after startup, so it is not an idle-only symptom.

Why it matters

1.…

Read the thread · 2026-09-23 · open · 0 comments

oracle_describe_view on a nonexistent view returns success with empty data

Version

0.11.0 (commit 73973b2)

What happens

oracle_describe_view on a view that does not exist returns success with empty data instead of an object-not-found error:

{"columns": [], "name": "SOME_MISSING_VIEW", "owner": "SOME_OWNER", "view": null}

Observed on three names that were confirmed (via a separate read-only path) not to exist in that schema. A caller can't distinguish "view exists but has no columns" from "view does not exist", and view: null is a silent…

Read the thread · 2026-09-23 · open · 0 comments

Generated-read guard refusal downgraded to INTERNAL, losing PolicyDenied/ForbiddenStatement class

Version

0.11.0 (commit 73973b2)

What happens

When the generated-read guard (used by oracle_describe, oracle_sample_rows, oracle_get_source, etc.) refuses a statement, the refusal reaches the client as a generic INTERNAL error instead of the real PolicyDenied / ForbiddenStatement class and message.

Root cause (confirmed in code)

GuardedGeneratedReadConn::before_query maps a refusal envelope to DbError::Internal(format!("{:?}: {}", class, msg)) via…

Read the thread · 2026-09-23 · open · 0 comments

oracle_get_source rejects VIEW while get_ddl accepts it; object_type is a free string, not an enum

Version

0.11.0 (commit 73973b2)

What happens

Root cause…

Read the thread · 2026-09-23 · open · 0 comments

Error misclassification: argument errors and ORA-01555 -> CONNECTION_FAILED; server-owned SQL failure -> SYNTAX_ERROR

Version

0.11.0 (commit 73973b2)

What happens

Several failures are given the wrong error_class and a misleading suggested_tool:

  1. Argument errors reported as connection failures. oracle_get_source {"object_type": "VIEW"} → {"error_class":"CONNECTION_FAILED","message":"unsupported source object type: \"VIEW\"","suggested_tool":"oracle_connection_info"}. It's a bad argument, not a connection problem. Same pattern for other validation messages: search_source,…

Read the thread · 2026-09-23 · open · 0 comments

The remaining reports are on the project's issue tracker.