Remote Code Analysis in ATC – Technical Setup step...
Application Development and Automation Blog Posts
Learn and share on deeper, cross technology development topics such as integration and connectivity, automation, cloud extensibility, developing at scale, and security.
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for
Search instead for
Did you mean:
Success! Subscription added.
We have launched new Developer forums/groups in the SAP Community. If you are here to publish developer- or SAP-technology related blog posts, please check out our new groups instead. You can find more information about the developer forums in this What's New post.
This will create a one time run. However what if you want this to run every 30 days? How would you automate this so that you would not have to manually schedule this to run each time?
Thank you presenting a series of detailed step by step ATC set up.
We have Evaluation system set up done and SAP Notes implemented on source ECC system. But when we run remote ATC check from evaluation system, we observe considerable number of tool failures. Along with priority 1,2 & 3, the number in tool failure is in hundreds. The error listed is primarily “Prerequisites not met”.
Could you please let us know what action needs to be taken to address this issue.
Did you also process the manual post-implementation steps mentioned in the SAP Notes you applied? E.g., did you execute program RS_ABAP_INIT_ANALYSIS as menitoned in SAP Note 2270689?
Yes I ran program RS_ABAP_INIT_ANALYSIS in check system. If I were to run the program again, the message says "Tables have already been created".
Our check system is SAP_BASIS 701. So I don't know if there needs to be any additional notes applied. Could you please suggest..
FYI, I can confirm below SAP notes are applied in check system:
2270689, 2011106.
Below manual activity is also done:
Create the function group SABP_COMP_PROCS_E in the package SABP_COMPILER (the master language is German - DE).
Activate the whole function group immediately after the creation.
Yes, the report was executed. At least I could see, that the tables were created and also filled.
When I start the report again, I get the message, that the report did already run.
Could the report RS_ABAP_INIT_ANALYSIS be really the reson why I did not receive remote data?
Other reports was checked correctly (at least over 2000). So this is not a general issue but I want to understand the issue and how to fix it so that I can check the rest of the reports.
I have 2 questions re the setup of such a ATC system and performing the custom code check for S/4 adaptation.
Am I correct in assuming that no HANA database is required for the ATC system?
If the ATC system is running using a cloud hosted platform (Azure, AWS, etc), are any parts of the analysed custom code transferred from the target system to the cloud-based ATC system? This is particularly relevant in terms of security and Intellectual Property (IP).
We have configured the central ATC system – SAP_BASIS 7.52 and able to get S4H ATC violations from checked system (SAP_BASIS 7.40, SP17). Applied notes as stated in #2364916. Any how we are getting few “Check Failures” message along with ATC result. Can you plz suggest how it can be remediated.
In addition – if we need to run ATC on code base in system configured as central system how can it can be performed. Do we need to define current system in object provider?
did you also process all manual post-implementaton steps as stated in the applied SAP notes?
You cannot check the ATC central check system itself with the remote ATC infrastructure. You need to check it locally (switch the system role to "Local ATC Checks only").
We are getting tool failure for only 8 objects. Yes we had implemented manual corrections as stated in notes. Only 2270689 is pending as we are not able to download this note. Is this can be reason for tool failure?
We are getting tool failure for only 8 objects. Yes we had implemented manual corrections as stated in 2364916. Only 2270689 is pending in checked system as we are not able to download this note. But report RS_ABAP_INIT_ANALYSIS is available and we executed it.
If the ATC check is done remotely without the (even temporary) transfer of custom code, doesn't this mean that the check might as well be done in the target system itself?
Sorry to be specific here, but from the viewpoint of where the Intellectual Property (IP) even temporarily resides -esp when the ATC central system is cloud-based- is important to us.
the ATC check is RFC-based, it is executed in the ATC central system for remote systems, the underlying Code Inspector check variant must consist of RFC-based checks only. See also Remote ATC checks in the SAP Help.
As you suggested, Now we have enabled remote ATC check. The remote ATC output received was not consistent with results earlier extracted using custom code migration worklist (Using - SYCM*) . Result from remote ATC are fewer in violation count & SAP notes #.
Can you suggest what can be the possible reason. Right now remote ATC is not giving all results as compare to Custom code migration worklist.
Otherwise if you could provide a concrete example of the findings detected with SYCM and not found with remote ATC, please open the OSS ticket. It must be looked at in detail.
Yes, we have custom namespace. I can only see 2 namespace in this report which are not registered but anyhow Remote ATC is still showing the violation from these unregistered packages.
Remote ATC result-set is showing more violations count coming from couple packages
SYCM* result-set - showing less violation count coming from many packages.
One question - customer name space role is 'C' in current source system.It can be the possible issue? and need to be changed to 'P'. But these settings are same for both approach. Please suggest.
This seems to be possible issue. When we are running ATC remotely it is only getting violations for package marked with role (P) in sub-system. All these packages are for custom development (Non Y* / Z*). However with SYCM extract based approach it is giving simplification violation.
I have changed role for few packages and now its giving results thou ATC run. Still output is not exact same as compared to SYCM.
I checked few programs which were giving issues in SYCM but if run ATC on same program in Central system locally (without remote ATC) it is not giving any violations.
As ATC variants is recommended approach, so believe better is trust on ATC results.
We have many SAP systems in the company on different SAP_BASIS levels: 7.11, 7.31, 7.40.
Currently we could establish remote ATC connections to systems with SAP_BASIS 7.31 and 7.40, and also we could run remote ATC tests successfully.
Unfortunately in the technical requirements is written SAP_BASIS 7.11 is no supported.
These systems with SAP_BASIS 7.11 are our main system with target to do remote ATC, because we will upgrade for SAP S4/HANA in near future. Remote ATC would be a great help to do this Job.
Questions:
Will this SAP_BASIS 7.11 level be supported in the near future?
What is the reason for not being supported for remote ATC? But SAP_BASIS 7.02 is being supported!
unfortunately, the SAP_BASIS 7.11 is not supported due to the technical feasibility in this particular release. Please consider, 7.11 is not the underlying release for SAP ERP and therefore the SAP S/4HANA conversion path doesn't exists for 7.11 and consequently S/4HANA related custom code checks with remote ATC don't make any sense.
we have set up an ATC Central System (SAP_BASIS 7.52). With this central ATC we want to check a remote system for S/4 HANA readiness.
Which Variant do i need for the Checkrun? I found the following variants:
S4HANA_READINESS_REMOTE and S4HANA_READINESS_1709 , which is the right one?
the S/4HANA release specific variants check for the simplification items of the corresponding S/4HANA releases. For example the S4HANA_READINESS_1610 checks all relevant simplification items for S/4HANA 1610 and so on.
If you need to check for S/4HANA 1709 readiness, you can use either S4HANA_READINESS_REMOTE or S4HANA_READINESS_1709. Both would be correct.
if you used SCI based on the SAP NetWeaver 7.5 approach (Code Inspector in the context of an S/4HANA migration), then you would get other results, because in 7.52 with remote ATC we delivered more S/4HANA readiness checks).
You need to use remote ATC, this is the recommended approach.
During the system conversion from ERP to S/4HANA (we call it system conversion, not an upgrade, because S/4HANA is a different product family) the SUM executes different tasks: database migraton, software update to S/4HANA, tables content conversion to the S/4HANA data model, but doesn't check custom code.
If you mean SAP Readiness Check, which runs in the preparation phase before SUM, then it uses Code Inspector and Custom Code Analyzer (SYCM), but delivers only high- level overview over the affected custom code by the S/4HANA simplifications, for a deep-dive analysis still the remote ATC must be used.
Just wanted to say thanks for this informative blog.
I would like to ask if could we use a SAP CAL system as the central ATC check system or do we have to have to install a standalone SAP NetWeaver system (SAP_BASIS >=7.51) as we only require to do the S4 HANA checks as a one-off exercise.
if we can use a SAP CAL system do you have any links which I can reference.
I'm facing an issue with viewing code in the remote system.
For the Object Provider I have configured an RFC Destination with a Service User and in the Correction Systems I have configured an RFC Destination with a normal dialog user (me).
I am assuming that when I try to view the source code of a finding then the Correction System RFC destination would be used?
However it appears that the Object Provider is used.
As a follow on question, how have you defined the user for the RFC Destination for correction system? Do you use the current user, a specified dialog type user or a system user?
We have 3 HANA systems with NW 740 SP13, NW 750 SP003. In all these systems I want to run ATC check on MV45AFZZ to analyse the custom code written in its subroutines.Could you please elaborate on how to run the ATC check on Include MV45AFZZ in all these systems?
after switching to “block on errors” end of last week in our ATC-setup, one of our developers in Brazil ran into a rather nondescript “tool failure” error. As this caused a priority 1 finding, it prevented the transport’s release.
When I had checked the same transport manually, no tool failure occured. After some more trial and error, plus the information from the developer that he could release his transport when logged in with language “EN” but not with “PT”, I checked if I could even login to the central system with “PT”. I couldn’t as it wasn’t one of the installed languages.
After discussing options with my colleague from the basis team, we decided to simply set the trusted RFC-connection to default language “EN” (instead of installing multiple and not really needed additional languages in the system). That got rid of the tool failure immediately.
How about updating what you have in the blog post, with the tip to take language(s) into account for the system- or RFC-setting?
2. Define RFC destinations for checked systems
Use transaction SM59 to create RFC destinations for each ABAP system, which will be checked in the current central ATC system.