A fix is available
APAR status
Closed as new function.
Error description
New Function for IBM z13(z13) D/T2964 compatibility support
Local fix
N/A
Problem summary
**************************************************************** * USERS AFFECTED: All installations running z/VM on an IBM z13 * * (z13) D/T2964 and all installations running * * z/VM on an IBM zEC12 or later machine * * desiring to use Message-Security-Assist * * Extension 5. * **************************************************************** * PROBLEM DESCRIPTION: * **************************************************************** * RECOMMENDATION: APPLY PTF * **************************************************************** Support required in z/VM for IBM z13 (z13) D/T2964.
Problem conclusion
Temporary fix
Comments
This APAR will provide support required for the IBM z13 (z13) D/T2964 and must be applied as part of installing z/VM on a z13. The following items are supported in z/VM 6.2 and z/VM 6.3: 1. New hardware facilities for guest use: Load/Store-On-Condition Facility 2 Load-and-Zero-Rightmost-Byte Facility Decimal-Floating-Point Packed Conversion Facility Delay Facility Message-Security-Assist Extension 5 2. Integer or Binary Floating Point for Capability Numbers Capability numbers have an inverse relationship to the speed of the machine, thus as machines get faster, there is need for fractional capability numbers. Accounting and monitor records will now report integer and binary floating point numbers for capability values while Q CAPABILITY will now report decimal numbers for capability values. 3. No guest zAAP support on z13: On the z13 the zAAP CPU type will not be supported either in real hardware or in the LPAR configuration. Similarly, z/VM will not allow guests to define this type, if the machine does not support it. 4. Guest support for the Crypto Express5S feature: This feature is exclusive to the z13. The Crypto Express5S can be configured in one of three ways using the Hardware Management Console (HMC) panels: IBM Common Cryptographic Architecture (CCA) coprocessor IBM Enterprise Public key Cryptography Standards (PKCS) #11 (EP11) coprocessor Accelerator Guests can be authorized in the z/VM directory for shared or dedicated access to the Crypto Express5S. When Crypto Express5S is configured as an accelerator or a CCA coprocessor, z/VM supports the device for shared or dedicated use. When Crypto Express5S is configured as an EP11 coprocessor, z/VM supports the device for dedicated use only. 5. Support for more AP Crypto features and more domains: z/VM supports an increase in the maximum number of domains per crypto feature from 16 to 256. It also supports an increase in the maximum number of crypto features, referred to as Adjunct Processors (APs), from 64 to 256. The z13 processor will provide support for up to 16 APs with 85 domains on each, using the new Crypto Express5S and the Crypto Express4S features. DIRECTXA will accept the larger AP and domain numbers on the CRYPTO statement in the z/VM user directory. The increase in the domain and AP numbers from two digits to three digits causes changes in the responses for the Q CRYPTO and Q VIRTUAL CRYPTO commands and in crypto error and informational messages. 6. Greater control over choice of crypto resources for shared use: A new CRYPTO APVIRTUAL statement may be included in the system configuration file. This statement allows the administrator to specify which domains on which APs (crypto resources) should be used for sharing. If this statement is omitted, a limit of two crypto resources will be chosen for shared use by default. Any crypto resources not designated for shared use at IPL time will be available for dedicated use. 7. Support for a VCHID operand on the DEFINE CHPID command for IQD type channel paths. 8. Dynamic I/O support for the new type CS5 (Coupling over PCIe/ICB-P) channel paths, allowing these channels to be defined or modified. In addition, the following items are supported in z/VM 6.3 only: 1. Guest exploitation of PCI address translation enhancements provided on z13. 2. Enhancements to the PCI Function Measurement data: New measurement fields for the various PCI function types will be correctly indicated in guest measurement blocks and Performance Toolkit reports. A memo to users is provided with instructions for the new versions of the DIRECTXA and SALIPL utilities and additional notes about the new cryptographic support. Please see VM65588 for corresponding IBM Directory Maintenance (DirMaint) updates and VM65527 for corresponding IBM Performance Toolkit (PerfKit) updates. Note: It is always recommended to apply the compatibility APAR to z/VM before upgrading your hardware. z/VM 6.3.0 can be installed directly on the z13 and service for VM65577 applied immediately afterward. For z/VM 6.2.0, however, at a minimum, APAR VM65007 must be applied before the z/VM system will IPL successfully on the z13. It is recommended that you install the z13 compatibility PTF for z/VM 6.2.0 before moving your z/VM 6.2.0 system to the z13. To support this APAR, new editions of the following publications are available: * z/VM V6.2 License Information, GC24-6200-06 * z/VM V6.3 CP Commands and Utilities Reference, SC24-6175-06 * z/VM V6.3 CP Messages and Codes, GC24-6177-06 * z/VM V6.3 CP Planning and Administration, SC24-6178-07 * z/VM V6.3 General Information, GC24-6193-07 * z/VM V6.3 I/O Configuration, SC24-6198-04 * z/VM V6.3 License Information, GC24-6200-08 * z/VM V6.3 Migration Guide, GC24-6201-06 * z/VM V6.3 Running Guest Operating Systems, SC24-6228-04 . See http://www.vm.ibm.com/library/ for the online version of the updated publications. . VM65577 also includes a fix for a problem in z/VM dedicated crypto support (CRYPTO APDEDICATED specified in the user directory) which may occur when running a single system image (SSI) cluster. . Problem Description: VM Guest is unable to access Crypto Hardware from a member of an SSI. . Full Error Description: This problem can result in one z/VM system in the relocation domain running Linux guests using the crypto hardware while Linux guests on the other system cannot access the crypto hardware. If there is a facility installed and supported on one system which is not on the other system, the architecture level for the relocation domain will be set to the common level which does not include that facility. This causes interception of the crypto instruction which checks the crypto hardware on the system with the additional architecture facility. This interception is not handled correctly by z/VM, and guests, such as Linux on System z using the zcrypt device driver, are not able to detect the crypto hardware. This problem is resolved by applying VM65577. Keywords: D/T2964 z13 D/T2965 z13s D/T2827 zEC12 D/T2828 zBC12 D/T2817 z196 D/T2818 z114 D/T2097 z10-EC D/T2098 z10-BC z90crypt
APAR Information
APAR number
VM65577
Reported component name
VM CP
Reported component ID
568411202
Reported release
630
Status
CLOSED UR1
PE
NoPE
HIPER
NoHIPER
Special Attention
YesSpecatt / New Function / Xsystem
Submitted date
2014-06-16
Closed date
2015-02-10
Last modified date
2017-12-11
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
UM34520 UM34521 UM34544 UM34545
Modules/Macros
CAPABILI CBITABLE CHPID CPLOAD CPU CRYPTO HCPACOBK HCPACT HCPARD HCPARDBK HCPASI HCPB9S HCPCBI HCPCCF HCPCCFBK HCPCCG HCPCCN HCPCREBK HCPCVU HCPCVV HCPDHDR HCPDIR HCPDVMD HCPEQUAT HCPGIR HCPGRF HCPHCD HCPIOX HCPKAE HCPKAI HCPKAP HCPKAQ HCPKAR HCPKAU HCPKFC HCPKFL HCPKFR HCPLDI HCPLGN HCPLOD HCPMDLAT HCPMES HCPMESA HCPMESB HCPMNP HCPMOM HCPMSS HCPMTS HCPMXD HCPMXF HCPMXI HCPMXRBK HCPOFI HCPOM1 HCPPCCBK HCPPCH HCPPCI HCPPCJ HCPPCK HCPPDF HCPPDR HCPPDRBK HCPPRV HCPQPR HCPQPS HCPQUY HCPQVA HCPRCC HCPRCCBK HCPRLE HCPRLP HCPRLU HCPRPCI HCPRST HCPSAL HCPSCFBK HCPSGQ HCPSI2GB HCPSSI HCPSTFLE HCPSYC HCPSYE HCPSYS HCPSYSCM HCPUDM HCPUDP HCPUDS HCPUSP HCPVPCI HCPWAT HCPWLG HCPWRP HCPWRPBK HCPWRU HCPWSI HCPWVS HCPWZD HCPZSC HCPZSI HCP1167E HCP1717I HCP1718I HCP1719I HCP1720I HCP1721I HCP1722I HCP2768E HCP584I HCP6706E HCP6873E HCP877I HCP879I HCP9009W HCP9061W MRIODPAC MRIODPAD MRIODPDS MRIODPON MRMTRCCC MRMTRPCI MRMTRSYS MRSYTEPM MRSYTSYG PCIFUNCT VIRTCRYP VM65577
Fix information
Fixed component name
VM CP
Fixed component ID
568411202
Applicable component levels
RA62 PSY UM34544
UP15/12/22 P 1501
RA63 PSY UM34545
UP15/09/22 P 1502
R620 PSY UM34521
UP15/02/11 P 1501
R630 PSY UM34520
UP15/02/11 P 1502
Fix is available
Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.
[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG27M","label":"APARs - z\/VM environment"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"630","Edition":"","Line of Business":{"code":"LOB16","label":"Mainframe HW"}}]
Document Information
Modified date:
11 December 2017