It is impossible to synchronize with RACF from a non-APF run. Typically if a RACF update happens to the very profile we are processing, you get a severity 20 message (for instance CKR0027 or CKR0029) which has as "User action" that you should just try again. and only take other action if it persists. However for an APF run we could in principle do something about it.
Ideas have been formulated by various of our customers to make sure the unload is serialized to prevent this from happening (ZALERT-I-18. ZALERT-I-53, ZSECURE-I-136). It definitely is on our to-do list, but always seems to get prioritized below other urgent compliance stuff.
That being said, the frequency of it happening has been greatly reduced due to customers no longer maintaining tape VTOCs, which were the prime contributor to RACF db update frequency. Do you see any reason / upcoming scenario for it to be on the increase again?
For today, you could at least equip your own nightly JCL with an extra IRRUT200 step.
------------------------------
Hans Schoone
Chief Architect zSecure
IBM - zSecure architect
Delft
------------------------------