ProtectMyi Installer 0.13.15 FAQ

What authority does the installing user need?
This installer requires effective *ALLOBJ, *SECADM, *JOBCTL, *AUDIT and *IOSYSCFG. The first three cover the privileged installation and work-management operations. The last two are also checked because the installer assigns them to the query profile. The native read-only preflight checks each authority, including group authority. Missing or indeterminate results stop the installation. It does not grant authority to the installing profile.

Where is the cleanup code saved?
The installer creates a *CHAR(32) data area named PMICLEANID in the selected installation library, with *PUBLIC *EXCLUDE. An authorized administrator can display it:
DSPDTAARA DTAARA(PMIAGENT/PMICLEANID)
Replace PMIAGENT with the selected library if different. It is written just after library creation, so it may exist even if later compilation fails. It is an installation identifier for temporary-file cleanup, not a registration credential or proof of successful installation.

How do I save or copy the instructions?
After verified installation, choose Copy instructions or Save instructions in the portal. The same retrieval procedure remains available through the Installer FAQ link. The claim token, machine secret and password are not stored in this instruction download or the cleanup data area.

How do I remove temporary installation files?
First preserve diagnostics and confirm the installation. Display PMICLEANID, then use its 32-character value:
CALL PGM(PMIAGENT/PMIREMOVE) PARM('32-character-value-from-PMICLEANID')
Replace the library if necessary. PMIREMOVE verifies the matching ownership marker and exact temporary workspace. It retains the installed library and service profiles. It refuses unexpected or modified files and directories, links, mismatched identifiers or an active claim-token file. If compilation failed before PMIREMOVE was built, preserve the workspace and use the separately reviewed exact-workspace tool only after diagnosis. Do not delete the partial native installation to retry.

What establishes installation success?
The helper must receive a zero SSH exit status, object-verification marker, completed security/activation phases, matching startup-verification marker and matching completion identifier. Both PMIAGENT and PMIQRY must be observed twice, at least five seconds apart, under the expected service profiles in the selected library's subsystem. Message-wait, ending or unrecognized statuses are not accepted. This is a startup observation, not a permanent health guarantee. The portal separately waits for the first heartbeat. An unavailable QSYS2.ACTIVE_JOB_INFO service or SQL/permission error yields unverified startup, never success; preserve diagnostics for a native fallback review rather than changing customer PTFs automatically.

Why were only PMIPARSE, PMIHLTH and PMIIDSET created?
These are the first three programs compiled. PMITRANS is next. Profiles and the subsystem are created only after all compilation succeeds. Their absence therefore fits a stop during PMITRANS compilation; it does not itself prove missing special authority. The original source used 32767-byte varying SQL host variables and VARCHAR(32767) casts, outside IBM's SQL limits. This candidate consistently uses 32739-byte buffers in transport, callers and parser. The exact error in the reported attempt still needs its IBM i compile listing.

Where do I find the failure details?
Use WRKSPLF under the installing profile and inspect the SQL/RPG listing for PMITRANS at the time of the attempt. If you are signed on as a different administrator, use WRKSPLF SELECT(the-installing-profile). Capture the diagnostic messages, including message IDs and source lines. Preserve the partial library and private /tmp/protectmyi-install-<ID> workspace. The new helper also writes a redacted transcript on the workstation under the signed-in user's .protectmyi/install-records/install-<ID>.txt; its console prints the path. This is best-effort and is not a substitute for IBM i compiler listings/job logs.

How do I check the subsystem and jobs?
WRKOBJ OBJ(PMIAGENT/*ALL) OBJTYPE(*ALL)
WRKACTJOB SBS(PMIAGENT)
Replace the library/subsystem if different. There should be the communications job PMIAGENT and query job PMIQRY under their selected service profiles. This installer creates a dedicated subsystem, queues, job descriptions and autostart entries. It does not add IPL startup configuration. After an IPL, an administrator can start the already-installed subsystem using CALL PGM(PMIAGENT/PMISTART), then verify its jobs and heartbeat. Do not start an incomplete installation.

Can I rerun over the partial library or existing profiles?
No. Preflight discovers this IBM i identity and checks the selected customer before offering installation changes. A recognized LPAR with occupied names is shown as an existing installation requiring inspection. An occupied library with unknown ownership is also blocked. Keep the cloud record and inspect the native installation before a deliberate reinstall. Choosing another library is not a reinstall. This candidate does not automatically overwrite or remove active or partial installations.

What has been tested?
Java compilation and off-platform tests verify helper completion/exit handling, portal flow and simulated native command failures. CL/RPG compilation, SQL runtime behavior, job startup and rendering in the live portal still require lab validation. No customer system or production service was changed.

IBM source references, reviewed 2026-10-01:
Equivalent SQL / ILE RPG host variable types:
https://www.ibm.com/docs/en/i/7.4.0?topic=applications-determining-equivalent-sql-ile-rpg-data-types
SQL limits:
https://www.ibm.com/docs/en/i/7.4.0?topic=reference-sql-limits
ACTIVE_JOB_INFO:
https://www.ibm.com/docs/en/i/7.4.0?topic=services-active-job-info-table-function
Create User Profile:
https://www.ibm.com/docs/en/i/7.4.0?topic=c-create-user-profile
Some canonical IBM pages returned 403 on direct retrieval. Search-index text was available; this package does not claim a physical IBM i validation from those sources.
