When a file system is protected by an FSEXEC profile with UACC(NONE), only users and groups with UPDATE access authority or higher are eligible for execute file access. Eligible users are then subject to the usual authorization checking, which includes checking for superuser authority, ownership, permission bits, access control lists (ACLs), and UNIXPRIV authorities.
CA added support to ACF2 with ptf RO91933. The added CLASMAP from the PTF set the record with a length of 44, mixed case, and a default type code of FSE. The call that is made is a FASTAUTH call, so you need to add the type code to a resident directory.
CHANGE INFODIR TYPES(R-RFSE) ADD
As an example, the zFS is called OMVS.ZFS.files.ADMIN. A sample rule would look like this:
ZFS.files.ADMIN UID(uid string that needs access) SERVICE(UPDATE) ALLOW
After any rules are added or changed, a REBUILD will be required: