LOCKDOWN System Option

Enables the ability to limit access to files and to specific SAS features for a SAS session executing in a batch or server processing mode.

Valid in:configuration file, SAS invocation
Category:Environment Control: Initialization and Operation
PROC OPTIONS GROUP=EXECMODES
Restriction:cannot be used when XCMD or RLANG are enabled
See:XCMD System Option
PROTOLIBS System Option
LOCKDOWN Statement
Configuration Guide for SAS Foundation for UNIX Environments

Syntax

LOCKDOWN

Syntax Description

LOCKDOWN
Enables the ability to limit access to files and to specific SAS features for a SAS session executing in a batch or server processing mode.

Details

The LOCKDOWN option is intended for use in a multi-environment deployment. In addition to LOCKDOWN, security administrators also rely on the NOXCMD system option. For more information, see XCMD System Option: UNIX in SAS Companion for UNIX Environments, XCMD System Option: Windows in SAS Companion for Windows, and XCMD System Option: z/OS in SAS Companion for z/OS.
When the LOCKDOWN option is specified for a SAS session, SAS enters a locked-down state at a lockdown point. A SAS session in the locked-down state has following restrictions:
  • limited file system access
    All access to local files and directories are validated through the lockdown path list.
    The lockdown path list specifies which host file resources are available when a SAS session is in the locked-down state. This list includes default system directories and user directories and files. For details about the lockdown path list, see LOCKDOWN Statement.
  • limited SAS language features
    The following SAS language features are disabled:
    • DATA step Java Object "javaobj"
      Note: On z/OS, execute any of the DATA step functions that are part of the SAS Data Location Assist feature. For details, see SAS Data Location Assist for z/OS in SAS Companion for z/OS.
    • PROC JAVAINFO and PROC GROOVY
    • FUNCTIONS: ADDR, ADDRLONG, PEEK, PEEKLONG, PEEKC, PEEKCLONG, POKE, POKELONG, and MODULE
    • Some z/OS host procedures: PDS, PDSCOPY, RELEASE, SOURCE, TAPECOPY, and TAPELABEL
    • z/OS access method: VTOC
LOCKDOWN does not take effect in a SAS session until after the lockdown point.
The lockdown point is the point during SAS execution when the following tasks have completed to establish a user’s SAS environment:
  • SAS session initialization
  • AUTOEXEC execution
  • INITSTMT execution
  • metadata library pre-assignments
During initialization of the user’s SAS environment, all paths and files are available and work as designed (for example, SASUSER, SASHELP, WORK, LOG, and so on). Metadata pre-assigned libraries and AUTOEXEC pre-assigned libraries also work as designed. When initialization is complete, SAS is put in the locked-down state with limited file system access.
When the server is locked down and the PROTOLIBS system option is not set to NONE, the lockdown path list will override the path list that is specified by the PROTOLIBS system option. When PROTOLIBS system option is set to NONE, the modules that are specified by the LINK Statement cannot be loaded. For more information, see PROTOLIBS System Option.

Examples

Example 1: Autoexec Example

In this example, the server invocation points to a SAS autoexec file in which specific paths are added to the lockdown path list:
/usr/local/bin/SAS/SASFoundation/9.4/sas -objectserver
-lockdown -autoexec sample-auto.sas

Example 2: z/OS Example

In this example, a SAS autoexec file is used with LOCKDOWN in a z/OS batch job:
//SASSTEP EXEC SAS,OPTIONS='LOCKDOWN NOXCMD'
//SASEXEC DD   DISP=SHR,DSN=USER01.SAS.PGMLIB(LOCKAUTO)
//SYSIN   DD   DISP=SHR,DSN=USER01.SAS.PGMLIB(PGM01)

See Also

System Options:
XCMD System Option: UNIX in SAS Companion for UNIX Environments
XCMD System Option: Windows in SAS Companion for Windows
XCMD System Option: z/OS in SAS Companion for z/OS
Other SAS Documents:
Locked-Down Servers in SAS Intelligence Platform: Security Administration Guide
Last updated: October 6, 2026