Hi Alan, > This isn't how DIAGNOSE instructions work. Instead of worrying about > converting user privclass to IBMCLASS and associating with the running > DIAGNOSE, it's done in the more primitive hindbrain of CP. > Architecturally, a DIAGNOSE is associated a SINGLE privilege class (or > privclass ANY). They aren't supposed to change behavior based on > privilege class (directory OPTION, maybe, but not privclass). > > DIAGNOSE 2FC is violating that architecture. I would suggest a PMR so > that you can discuss with Development whether that violation is Right and
> Proper. I guess the challenge with DIAG 2FC is that not every issuer is necessarily supposed to see guest information beyond themselves. So while I agree with your assessment I see reasoning in the approach taken ... Best regards Ingo Linux on 390 Port <[email protected]> wrote on 20.05.2016 17:19:01: > From: Alan Altmark <[email protected]> > To: [email protected] > Date: 20.05.2016 17:19 > Subject: Re: [LINUX-390] hyptop question > Sent by: Linux on 390 Port <[email protected]> > > On Friday, 05/20/2016 at 06:41 GMT, Karl Kingston <[email protected]> > wrote: > > > For z/VM, the guest virtual machine must have privilege class B > > > or, preferably, a locally-defined privilege class that contains > > > diagnose 2fc. > > > > How does one do this? Don't like giving my linux guests access to > CLASS > > B so I would like to make my own class and give that to the user. > > Well, isn't this embarrassing... (blush) (look down) (kick rock) You > can't. I keep forgetting that DIAGNOSE instructions are architecturally > different than commands. > > (For a fascinating description of how CP commands and DIAGNOSE > instructions are processed, keep reading!) > > The system supports privclass-qualified versions of a command. When you > enter a command, the highest level (A->9) for which you have the assigned > privilege class will run. That is, if a command has a class B version and > a class G version, then if you have class ABG, the command will be > qualified as class B. If you had class AG, then the command will be > qualified as class G. That's the last time CP looks at the issuer's > privclass. The system instead looks at the command qualifier. We refer > to the command qualifier as the "IBMCLASS". That is, the IBM-defined > privilege class associated with the version of the command that's running. > The MODIFY COMMAND command lets you change the association between the > user privclass and the IBMCLASS. > > This all gets resolved before the command actually runs, eliminating any > need for CP to worry about user privclass. He just cares about the > IBMCLASS of the command that's running. This allows a single entry point > to handle the command. > > This isn't how DIAGNOSE instructions work. Instead of worrying about > converting user privclass to IBMCLASS and associating with the running > DIAGNOSE, it's done in the more primitive hindbrain of CP. > Architecturally, a DIAGNOSE is associated a SINGLE privilege class (or > privclass ANY). They aren't supposed to change behavior based on > privilege class (directory OPTION, maybe, but not privclass). > > DIAGNOSE 2FC is violating that architecture. I would suggest a PMR so > that you can discuss with Development whether that violation is Right and > Proper. > > Alan Altmark > > Senior Managing z/VM and Linux Consultant > Lab Services System z Delivery Practice > IBM Systems & Technology Group > ibm.com/systems/services/labservices > office: 607.429.3323 > mobile; 607.321.7556 > [email protected] > IBM Endicott > > ---------------------------------------------------------------------- > For LINUX-390 subscribe / signoff / archive access instructions, > send email to [email protected] with the message: INFO LINUX-390 or visit > http://www.marist.edu/htbin/wlvindex?LINUX-390 > ---------------------------------------------------------------------- > For more information on Linux on System z, visit > http://wiki.linuxvm.org/ > ---------------------------------------------------------------------- For LINUX-390 subscribe / signoff / archive access instructions, send email to [email protected] with the message: INFO LINUX-390 or visit http://www.marist.edu/htbin/wlvindex?LINUX-390 ---------------------------------------------------------------------- For more information on Linux on System z, visit http://wiki.linuxvm.org/
