SR-policy node associations (application-only)

GET /api/v1/bgpls/policies/{id}/associations is an authenticated live reader, not in published OpenAPI or restricted-key access. Returns observation, routing_domain_id, headends, endpoint, ordered lists[].segments and note. Each association has address, status (matched/unknown/ambiguous/stale/ unsupported), reason and scoped owners with device/area/PI IDs and observation timestamp. Exact source observation identity; no hash-only merge. Reads policy and domain evidence in one repeatable-read snapshot. 400 invalid UUID/history, 404 withdrawn/missing, 422 above 10000 area-node observations, 500 storage or corrupt data. An unavailable source is a stale result, not an installed failure.

BGP-LS SRv6 observations: GET /bgpls/objects also accepts type=srv6_sid. Node/link/prefix/SID rows may carry srv6 with capability flags, algorithms, node/link MSD, locator, prefix flags, End SID, End.X adjacency, peer context, raw attributes and error evidence. Withheld/stale semantics remain. GET /devices/{deviceID}/srv6 may additionally return data.end_sids (SID, behavior, flags, structure, MTID, algorithm). These remain advertised facts, not installed-state assertions.

BGP-LS optional SRv6 decode errors are scoped to srv6.error; they do not mark valid IGP/TE attributes withheld or discarded. Whole-attribute discard keeps its existing flags. Notification channel test failures consistently return the standard nested error envelope.