IBM Support

PM47302: HFS VIOLATIONS WHEN SYNC-TO-OS THREAD IS ENABLED, AND APPLICATION ATTEMPTS TO LOAD NATIVE DLL.

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Application utilizes sync-to-osthread in order to push a user
    identity onto the operating system thread.  The application also
    accesses a native dll. When the classloader is searching the
    application for the native dll, a security violation occurs
    because the HFS was searched under the identity of the user, and
    not the identity of the application server.
    
    An example violation may look like the following:
    
    ---------
    
    ICH408I USER(USER   ) GROUP(SOMGROUP ) NAME(   )
      /WebSphere/Base/AppServer/profiles/default/installedApps/cell
      /Application.ear/WebApplication.war/WEB-INF/classes
      CL(DIRSRCH ) FID(00028BCE000202950000000000000000)
      INSUFFICIENT AUTHORITY TO LSTAT
      ACCESS INTENT(--X)  ACCESS ALLOWED(OTHER      ---)
      EFFECTIVE UID(0000000001)  EFFECTIVE GID(0000000100)
    ICH408I USER(USER   ) GROUP(SOMGROUP ) NAME(   )
      /WebSphere/Base/AppServer/profiles/default/installedApps/ce
    ll/Application.ear/WebApplication.war/WEB-INF/lib/Utility.jar
      CL(DIRSRCH ) FID(00028BCE000202950000000000000000)
      INSUFFICIENT AUTHORITY TO LSTAT
      ACCESS INTENT(--X)  ACCESS ALLOWED(OTHER      ---)
      EFFECTIVE UID(0000000001)  EFFECTIVE GID(0000000100)
    CH408I USER(USER   ) GROUP(SOMGROUP ) NAME(    )
     /WebSphere/Base/AppServer/profiles/default/installedApps/ce
    ll/Application.ear/WebApplication.war/WEB-INF/lib/Utility.jar
     CL(DIRSRCH ) FID(00028BCE000202950000000000000000)
     INSUFFICIENT AUTHORITY TO LSTAT
     ACCESS INTENT(--X)  ACCESS ALLOWED(OTHER      ---)
     EFFECTIVE UID(0000000001)  EFFECTIVE GID(0000000100)
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server for z/OS V7.0                        *
    ****************************************************************
    * PROBLEM DESCRIPTION: When the "sync to OS thread" function   *
    *                      is enabled, native library loads can    *
    *                      fail when using application class       *
    *                      loaders.                                *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    When "sync to OS thread" is enabled on z/OS, the server ID must
    be put on the thread stack before filesystem operations are
    allowed to take place.  This was not occurring for native
    library loads in the WAS application class loaders, and HFS
    violations could result.
    

Problem conclusion

  • The server identity push was included in the WAS application
    class loader's findLibrary method.
    
    APAR PM47302 is currently targeted for inclusion in Service
    Level (Fix Pack) 7.0.0.21 of WebSphere Application Server V7.0.
    
    Please refer to URL:
    //www.ibm.com/support/docview.wss?rs=404&uid=swg27006970
    for Fix Pack availability.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PM47302

  • Reported component name

    WEBSPHERE FOR Z

  • Reported component ID

    5655I3500

  • Reported release

    700

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2011-09-07

  • Closed date

    2011-11-28

  • Last modified date

    2012-02-03

  • APAR is sysrouted FROM one or more of the following:

    PM40926

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE FOR Z

  • Fixed component ID

    5655I3500

Applicable component levels

  • R700 PSY UK74996

       UP12/01/18 P 1201

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS7K4U","label":"WebSphere Application Server for z\/OS"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.0","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
10 February 2022