Recovery, threadsafe and modern interfaces
CICS protects data by backing out a failed task's changes and recovering in-flight work after a crash. It runs programs on more than one kind of TCB, which is why threadsafe matters, and it moves large data with channels and containers and exposes programs as web services and JSON APIs.
Units of work and backout
Every CICS task runs inside a unit of work (UOW). Changes to recoverable resources are tentative until a syncpoint, which happens at the end of the task or when the program issues EXEC CICS SYNCPOINT. If the task abends first, dynamic transaction backout reverses its changes so the data is left as it was at the last syncpoint.
| Resource | How it becomes recoverable |
|---|---|
| VSAM file | RECOVERY attribute on the file definition (NONE, BACKOUTONLY or ALL), or for RLS files the LOG attribute in the ICF catalog (NONE, UNDO or ALL) |
| Temporary storage queue | Defined as recoverable through a TSMODEL |
| Intrapartition transient data queue | Logical recovery on the TDQUEUE definition |
| DB2, IMS, MQ | Coordinated with CICS through two-phase commit |
Non-recoverable resources are not backed out. A common surprise is a work file defined with RECOVERY(NONE): the abend backs out the DB2 update but leaves the file record written.
When the region itself fails
CICS writes before-images and UOW status to its system log (DFHLOG, with DFHSHUNT for long-running or shunted work), held in the z/OS system logger. After a failure, an emergency restart reads the log and backs out every UOW that was in flight. If CICS loses contact with a coordinator during two-phase commit, the UOW is indoubt and may be shunted: its locks are kept until the outcome is known. Forward recovery (rebuilding a damaged file from a backup plus logged changes) uses a separate forward recovery log and a product such as CICS VSAM Recovery.
The open transaction environment and threadsafe
Historically all application code ran on one QR TCB (quasi-reentrant), so only one task executed application code at a time in a region and programs could share storage safely. The open transaction environment adds pools of open TCBs (for example L8 and L9) where code can run in parallel.
CONCURRENCY(QUASIRENT)CONCURRENCY(THREADSAFE)CONCURRENCY(REQUIRED)API(OPENAPI)Threadsafe is a property of the code, not a switch. A program that updates a shared area such as the CWA without serialising (for example with EXEC CICS ENQ) can corrupt data once marked threadsafe. Teams review code before changing the attribute.
Channels and containers
The COMMAREA is limited to 32 KB. A channel is a named set of containers, each holding any amount of data subject to storage. Programs use PUT CONTAINER, GET CONTAINER and LINK ... CHANNEL(...). CHAR containers can be converted between code pages by CICS; BIT containers are passed unchanged. Channels are the normal interface for web services and APIs.
Web services, JSON and APIs
- Provider: CICS receives HTTP through a TCPIPSERVICE, matches the URL with a URIMAP, and a PIPELINE passes the request to the program, often as containers.
- Assistants: batch utilities generate mappings between COBOL copybooks and SOAP/XML (DFHLS2WS, DFHWS2LS) or JSON (DFHLS2JS, DFHJS2LS).
- REST APIs: many sites expose CICS programs with z/OS Connect, which maps JSON to the program interface; a Liberty JVM server inside CICS is another option.
- Requester: CICS programs can call out with
WEB OPEN,WEB CONVERSEandWEB CLOSE.
The details are covered in the APIs course; here the point is that the same COBOL program can serve 3270, MQ and web clients if its interface is clean.
Common mistakes
Only recoverable resources are backed out. Check the RECOVERY setting of files and queues the program updates.
Shared storage updated without serialisation can be corrupted when tasks run in parallel. Review the code and test under load first.
A cold start throws away the information needed to back out in-flight work. Use an emergency or auto start unless the systems programmer decides otherwise.
What you will see at work
- Design reviews ask which resources are recoverable and where syncpoints fall in long tasks.
- Performance projects often convert heavy DB2 programs to threadsafe to cut CPU.
- New interfaces use channels and containers so the same program can be called from 3270, MQ or a REST API.
Key terms
Check your understanding.
Take this lesson's quiz and save your progress. Free.