Previous Topic: Implementing Diagnose LimitingNext Topic: Setting up Diagnose Limiting Validation


Selecting Diagnose Codes for CA ACF2 for z/VM Validation

Before you write the diagnose limiting rules, select the diagnose codes that CA ACF2 for z/VM includes or excludes from validation.

Diagnose Codes You Can Exempt from Validation

You can determine that executing certain diagnose codes requires no validation because they are commonly used by VM Class G users. Such diagnose codes include:

x’0C’

Stores the VM time information in the user’s virtual storage.

x’18’

Performs input or output operations to a direct access device. System performance can be greatly affected if x’18’ executions are logged.

x’20’

Specifies channel command word (CCW) chain to execute on a tape, disk, or unit record device. System performance can be greatly affected if x’20’ executions are logged.

x’54’

Controls the function of the PA2 function key.

x’58’

Communicates with IBM 3270 display stations.

Diagnose Codes Recommended for Validation

You should restrict execution of the following diagnose codes:

x’30’

Reads one page of the system error recording area

x’34’

Reads the system dump spool file

x’3C’

Updates the VM directory

x’84’

Replaces the specified data in any VM directory entry.

These are only a few of the diagnose codes you can choose to validate. You should review all diagnose codes for security concerns and implement diagnose instruction control as necessary.