Thursday, February 19, 2009

What Does ABEND 414-04 Mean?

Ran into this one recently and I thought I'd share. Essentially, a volume can be set to READ ONLY. This is something outside the scope of any security product that might be running on the system, meaning you may have RACF permissions to a data set, but if the volume on which that data set resides is READ ONLY, you'll get the 414 abend. The solution is to get your system programmer to un-read only the volume so you can write to it.

RANDOM APF AUTH GOODNESS

From the console (or from SDSF), use this command to display a list of data sets that are currently APF authorized:

D PROG,APF

From the console (or from SDSF), to dynamically APF authorize a data set:

SETPROG APF,ADD,DSNAME=dsname,VOLUME=volser

Note that if you are using the TSO 'CALL' command to execute your compiled programs, you'll get an error if the program you're attempting to execute is APF authorized. To rectify this, you need to either execute the program via JCL, or add the module to TSO Parmlib member IKSTSOxx and re IPL.

Wednesday, February 18, 2009

How to set AC=1 when using ISPF foreground processing


When you are writing APF authorized code (see this post for more details on what APF is), you may want to link-edit the module using the handy-dandy ISPF panels (option 4.7). Unfortunately, the pubs are not as clear as they could be as to the syntax of how to set the AC = 1 option when using the panels. Well, here's a screen shot of what you need to put there and what it looks like.

Thursday, February 12, 2009

APF AUTHORIZED, SUPERVISOR STATE, AND KEY 0

Understanding how the mainframe manages authorized and non-authorized code is crucial for anyone performing system-level tasks. The concepts are simple, but understanding how they relate to one another can get dicey. This post is geared towards someone who needs to write authorized mainframe code.

The system considers a task authorized when the executing program has the following characteristics:

  • It runs in supervisor state (bit 15 of the program status word (PSW) is zero).

  • It runs with PSW key 0 to 7 (bits 8 through 11 of the PSW contain a value in the range 0 to 7).

  • All previous programs executed in the same task were APF programs.


Here are the three things you need to know about:

APF AUTHORIZED: APF stands for A.uthorized P.rogram F.acility. It allows for the system programmer (for those of you who are new to the field, in mainframe-land a system programmer is like a system-administrator) to identify data sets and programs that are allowed to perform sensitive system functions. There are two components to APF authorization. The first is link-editing a module (program) with the AC 1 option set. By using the AC 1 option, we are making the module eligible to be APF authorized. The second component is to place the module into an APF authorized library. APF-authorized programs must reside in one of the following authorized libraries (data set):

  • SYS1.LINKLIB

  • SYS1.SVCLIB

  • SYS1.LPALIB

  • Authorized libraries specified by your installation.


Now that we've got our module properly link-edited and placed in an authorized library, we can move onto PSW key and system state. Normally, the system will run in what's referred to as “problem state”. This means there is a set of instructions that are unavailable. Only when the user is in supervisor state are these privileged instructions available. APF authorized programs are permitted to put the system into supervisor state. THIS IS IMPORTANT ---> APF AUTHORIZED PROGRAMS DO NOT RUN IN SUPERVISOR STATE AUTOMATICALLY! APF AUTHORIZATION ONLY ALLOWS FOR THE SYSTEM TO BE PLACED SUPERVISOR STATE.

So now that we're in supervisor state, there's one more thing we need to think about. Every page of storage (a page is 4 kilobytes) has a key associated with it. Keys 0-7 are considered protected, and 8-15 are considered unprotected. If a page of storage is protected, module attempting to access it must be authorized. The system needs to be in supervisor state in order to change the default PSW key from 8 to one that is authorized.

So, let's review. To create a program that is capable of executing privileged instructions and accessing protected storage, it needs to be APF authorized (link edited with the AC 1 option and placed in an APF authorized library), it needs to use the MODESET macro to place the system in supervisor state, and it needs to use the SPKA instruction to change the PSW key to 0-7 (whatever is appropriate).

Well, that's about it. I hope it helps. Here's a link that provides a bit more info if you need it.

Monday, January 26, 2009

Random TSO Goodness

Lately I've been missing MS-DOS. Not because DOS was amazing, but because I know where things are and how to get things done. The PATH command is a good example. In DOS, you could use the PATH command to help DOS find programs you wanted to run. It created a list of directories to search through before it gave up and said something like BAD COMMAND OR FILENAME. You could put this command inside a file called AUTOEXEC.BAT, which was the name of a program that would get run every time the computer started. This way, you could save time as you didn't have to type out or go to the directory in which the program you wanted to execute resided.

In mainframe land, however, things are a bit more complicated.

In mainframe land, the equivalent of a BAT file (short for BATCH) is something called a CLIST. CLIST stands for Command Listing, and is a lot like a DOS batch file in that it provides a user the means to execute several commands at once. In other words, instead of issuing ten commands separately, you could make a list and all you had to do was type in the name of the list. So how do we save ourselves time like we did on our old DOS system?

There are two commands that you can issue on the mainframe that are roughly equivalent to the DOS PATH command. They are TSOLIB and ALTLIB.

TSOLIB is used for load modules, which are programs that have been compiled and link-edited. We issue this command against load modules to have it added to the STEPLIB data set. STEPLIB is a library that will be at the head of a load module search. So, when we want to run our "hello world!" program we lovingly wrote in C, we add it to the STEPLIB so the mainframe knows where to find it, thus saving us the trouble of pecking out it's location in the file system.

ALTLIB will do basically the same thing, but is used for CLISTs and uncompiled REXX programs. These are scripting languages and thus don't have load modules. By default, the mainframe will look in a dataset called SYSPROC for CLISTs. ALTLIB will add other data sets to that search, thus saving us time.

Now, it's important to remember that, like the PATH command in DOS, these changes all go away the minute you log off (or in the case of DOS, reboot the system). So, we need to find a way to have the system re-implement these changes every time we log in. We need a mainframe equivalent to AUTOEXEC.BAT.

On the logon screen , there is a field labeled COMMAND. From there you can issue any TSO command you want, including a CLIST that contains all your ALTLIB and TSOLIB statements in it.

There ya go. Hope it helps :-)

Thursday, August 21, 2008

How to search for PDS members in ISPF

I've just discovered a really simple way to find stuff on the mainframe. Let's say you are looking for a file called INDEX and you only know the high level qualifier of the dataset it's in. After you do your DLIST (ISPF option 3.4) of the HLQ (hlq.** for example), you type

member index

at the command line. The system will show you all the data sets where a file called INDEX resides. You can also use wildcards. So, for example, let's say there are lots of files you want to find, all starting with INDEX (INDEX00, INDEX01, INDEX02, etc). Then you'd type

member index*

and you'll be shown all the files that begin with the word index. Cool huh? The only thing I've noticed is that if your data set has been migrated, this won't work. You'll have to recall the data set before you do your search.

Hope you find it useful :-)

Wednesday, August 6, 2008

Master the Mainframe and GDDM

The Master the Mainframe contest is just around the corner and as I'm on the contest team this year, I was asked to come up with a coding challenge. The one I came up with last year was a simple ISPF macro challenge I ripped from the pubs (ISRBOX) and added a few bugs too. This year I wanted to do something spectacular so I dug deep and dove into IBMs Graphical Data Display Manager, or GDDM for short.

What's so cool about GDDM? Well my friends, it allows the mainframe to display graphics and interact with things like mice and light pens and all sorts of other cool peripherals. ISPF can be made to act like a simple GUI with a point and click interface. It is also the means by which OS/2 displayed it's windows and such. With the advent of the web, however, this feature became somewhat depricated and nobody, to my knowledge, really uses it anymore.

So what am I doing messing around with this thing? Well, as fun as looking at endless streams of green text can be (and believe me, it's a hoot), I figured some colorful graphics might be a nice change of pace. I decided to create an implementation of Mandelbrot Set. The man who discovered this method, BenoƮt Mandelbrot, was an IBM fellow so it seemed fitting.

So I got to coding, pestered my co-workers when I got stuck or when the math got over my head, and finally I was able to get the thing working. It should be noted that I got some help, especially with the zooming bit, from here.

So I get the stupid thing working,


it looks amazing, it zooms (sortof) at the click of a mouse, I get my ooohs and aaaahs. After all that, it can't be included in the contest because none of the TN3270 emulators on the market (save the IBM one) can handle host graphics. No host graphics means no GGDM. The contestants won't be using the IBM TN3270 program so they won't be able to see the image.

...probably should've looked into that before I spent all that time coding the thing.

Oh well. As there isn't much good information on the web about GDDM I thought I'd post the code, written in C, for the Mandelbrot Generator. In order to use GDDM, you're going to have to play with your JCL and include some libraries so this compiles/links properly.

*NOTE* There are [] around the includes so Blogger doesn't think it's some sort of tag

#include [stdio.h]
#include [string.h]
#include [admucina.h]
#include [admtstrc.h]
#include [admucinf.h]
#include [admucing.h]
#include [admucins.h]


#pragma linkage(asread,OS)
#pragma linkage(chhatt,OS)
#pragma linkage(chhead,OS)
#pragma linkage(gsuwin,OS)
#pragma linkage(gschar,OS)
#pragma linkage(gsseg,OS)
#pragma linkage(gssati,OS)
#pragma linkage(gsscls,OS)
#pragma linkage(gsenda,OS)
#pragma linkage(gsarea,OS)
#pragma linkage(gsqcho,OS)
#pragma linkage(gsqloc,OS)
#pragma linkage(gspat,OS)
#pragma linkage(gsenab,OS)
#pragma linkage(gssaga,OS)
#pragma linkage(gsmove,OS)
#pragma linkage(gscol,OS)
#pragma linkage(gsline,OS)
#pragma linkage(gsview,OS)
#pragma linkage(gslw,OS)
#pragma linkage(gsflw,OS)
#pragma linkage(gsarc,OS)
#pragma linkage(fsinit,OS)
#pragma linkage(fsterm,OS)

#define width 320
#define height 200

main ()
{

/*SETUP THE GDDM ENVIRONMENT**********************/
float xoff, yoff, oldcx, oldcy;
int temp;
float scale;
int flag;
int number;
float cx = -0.5;
float cy = 0;
int inwin;
int type;
int val;
int count;
int id_type;
int id_id;
double x,y;
double xstart,xstep,ystart,ystep;
double xend, yend;
double z,zi,newz,newzi;
double colour;
int iter,input;
long col;
int i,j,k;
int inset;
int fd;

fsinit();
flag = 0;
gsenab (1,0,1);
gsenab (1,1,1);
gsenab (2,1,1);
gsuwin(0,640,0,480);
gsms(9);

xstart = -2;
xend = 1;
ystart = -1;
yend = 1;
xoff = 0;
yoff = 0;
iter = 200;
scale = 1;
xstep = ((xend-xstart)/width) * scale;
ystep = ((yend-ystart)/height) * scale;

/*DISPLAY AND ZOOM LOOP***************************/

while (flag == 0)
{
flag = 1;

x = xstart;
y = ystart;

for (i=0; i
{

for (j=0; j
{
z = 0;
zi = 0;
inset = 1;

for (k=0; k
{
/* z^2 = (a+bi)(a+bi) = a^2 + 2abi - b^2 */
newz = (z*z)-(zi*zi) + x;
newzi = 2*z*zi + y;
z = newz;
zi = newzi;

if(((z*z)+(zi*zi)) > 4)
{
inset = 0;
colour = k;
k = iter;
}

}

if (inset)
{
gscol(-1);
}
else
{

while (colour > 7)
{
colour = colour / 8;
}

gscol(colour);
}

x += xstep;

/*DRAW YOUR FRACTAL!******************************/
gsmark (j,i);

}

y += ystep;
x = xstart;

}

/*SEND THE GDDM DATA TO THE SCREEN****************/

gsread(1,&id_type,&id_id);

if (id_type == 2)
{

scale = scale * 0.75;
flag = 0;
oldcx = cx;
oldcy = cy;

gsqloc(&inwin,&cx,&cy);


if (cx > 320)
{
cx = 320;
}

if (cy > 200)
{
cy = 200;
}

cx = (cx * xstep) - 2 + xoff;
cy = (cy * ystep) - 1 + yoff;

xoff = (xoff + (cx - oldcx));
yoff = (yoff + (cy - oldcy));

xstart = cx + (-1.5 * scale);
xend = cx + 1.5 * scale;
ystart = cy + (-1 * scale);
yend = cy + 1 * scale;

xstep = xstep * scale;
ystep = ystep * scale;

}

}

fsterm();
}

Enjoy (and good luck to this years Master the Mainframe contestants!)