Owner's manual

Working with Patterns
Safeguard User’s Guide 422089-020
9 - 5
Safeguard Pattern Configuration
Safeguard Pattern Configuration
Use the Safeguard configuration attribute CHECK-DISKFILE-PATTERN to enable,
disable, and control the search order for pattern and non-pattern protection records.
OFF
Specifies no pattern searches will occur. This configuration is equivalent to
Safeguard versions prior to G06.25.
LAST
Specifies that non-pattern searching will occur first, using non-pattern based
protection records, as in Safeguard versions prior to G06.25. If that search returns
NORECORD then pattern based protection records will be searched.
FIRST
Specifies that pattern based protection records will be searched first. If that search
returns NORECORD then non-pattern based protection records will be searched.
ONLY
Specifies that only pattern based protection records will be searched. Non-pattern
protection records will be ignored.
MID
Specifies that pattern based protection records will be searched:
°
After the diskfile protection record search returns NORECORD when Direction-
Diskfile is set to Filename-First.
°
Before the diskfile protection record search, when the Direction-Diskfile is set
to VOLUME-FIRST, and the VOLUME and SUBVOLUME protection record
search returns NORECORD.
Safeguard searches patterns so that the most specific p
attern is used, and behaves
similar to Direction-Diskfile = Filename-First and Combination-Diskfile = First-ACL.
Introducing a new method to determine access control impacts the multilevel method
used today. Rather than try to merge the pattern method into each level, you will make
each method mutually exclusive, but able to coexist. You will provide a global control
that will specify which method is to be used first. Only when the primary method
returns NORECORD will the secondary method be used. This access result will be
combined with the result returned from the SEEP in accordance with existing policy. To
maintain backwards compatibility, this control will also disable pattern matching
entirely.
Note. The MID option is supported only on systems running J06.08 and later J-series
RVUs and H06.19 and later H-series RVUs.