I have a firewall rule that adds an ip to an address-list with a timeout of 00:02:00 (2 minutes). Before the 6.38 upgrade, when the timeout was reached, the entry was removed from the address-list. That is not happening any more. I now have an address-list of over 100,000 entries.
I see this was to have been fixed in 6.39.x but it is still not working.
I am running such a config with 8 hour timeout and I don’t see that problem.
Maybe it is related to the shorter timeout you use or another config peculiarity?
I had set up some NAT rules a while back that added to the address list. The default on NAT for the time out is “none dynamic”. I simply changed this to a time and all is working.