ProtectMyi Installer 0.13.8

Extract this ZIP into a NEW directory.
On Linux open a terminal in THAT directory, then run:
chmod +x run-linux.sh
./run-linux.sh

On Windows run ProtectMyiInstaller.exe. Java 8 or newer is required.

Stop any older helper before starting this version.
Return to https://app.protectmyi.org and choose Connect IBM i.

# ProtectMyi isolated IBM i agent 0.7.0 / helper 0.13.8

Fresh installations only. Existing library/profile/subsystem names cause refusal, not upgrades. The portal provides editable installation names, Check prerequisites, and an explicit Continue with installation button. Changing inputs invalidates approval. Registration occurs after Continue and a fresh prerequisite check.

All persistent agent objects, including PMICLSRC and PMIRPGSRC source files, reside in the selected library. The dedicated subsystem has the same name as that library. It has its own job queue, output queue, two message queues, two job descriptions and two autostart entries. QUSRWRK, system queues, startup programs and system values are not altered. IBM commands/APIs are invoked normally.

The portal requests registration and immediate startup after object/security commands succeed and registration credentials are verified. IPL startup is intentionally left to the administrator. Use STRSBS SBSD(selected-library/selected-library) after IPL, once the prior configuration has enabled RUN_ENABLED.

All source programs are compiled with USRPRF(*USER). Failed fresh installations preserve partial objects for review; no native-object deletion or profile modification is attempted. Existing profiles are never changed.

Each install has an ID and a PMIMARK data area recording the ID and selected profiles. The random private workspace is /tmp/protectmyi-install-<ID>. A file inventory is recorded before installation, extended for generated source, and checked by the explicit cleanup tool.

After successful installation, the portal displays:
CALL PGM(selected-library/PMIREMOVE) PARM('32-character-installation-ID')

PMIREMOVE checks the library marker before invoking exact-workspace IFS cleanup. Cleanup refuses symbolic links, changed/missing files, extra files, an active token or a mismatched ID. It deletes only inventoried files and empty directories. It does not delete native objects, service profiles, logs, queues or installation state. Preserve failed-install files for diagnosis before choosing to remove them.

Automatic native-object purge and in-place upgrades are intentionally disabled in this release. They require a separate verified ownership/inventory and stopped-job implementation. Do not use older uninstall scripts for this installation.

Off-platform tests simulate IBM i commands and execute actual shell cleanup. Compilation and execution of CL/RPG still require validation on IBM i; Linux tests do not establish those results.

Prerequisites: reachable SSH; an existing accessible home directory; IBM i Java 8 or newer at /usr/bin/java; readable IBM Toolbox /QIBM/ProdData/OS400/jt400/lib/jt400Native.jar; Qshell/PASE/tar and required CL/RPG/SQL RPG commands. The preflight calls read-only QSYCUSRS natively under the Java job's existing profile, checking *ALLOBJ *SECADM *AUDIT *IOSYSCFG *JOBCTL individually, including group authorities. It never supplies a user ID/password to Java or changes IBM's JAR. If native optimizations are unavailable it stops before the program call.

The helper uploads a small compiled probe to its newly created private /tmp/protectmyi-authority-<random ID>/native-authority-check.jar. After the check it removes that exact JAR and uses rmdir for the exact directory. No temporary native CL program, source file or QTEMP objects are needed. Installation payload also includes the same probe for the final authority check immediately before persistent writes.

The source is under ibmi/native-authority/src. It compiles with Java 8 and the public IBM Toolbox API. IBM's Toolbox JAR is used for compilation only on the build workstation and is not redistributed in this release.

Physical IBM i Java/native Toolbox/API execution still requires validation.
