by voron » Mon Mar 10, 2008 4:04 am
There would be nice to have an ability to change Logging Options thresholds in runtime. I need all(actually all non-duplicate) grsec denies during policy development&testing, but I don't wont to rebuild kernel twice to change these values to bigger and then again to lower while policy development&testing ends. I tried to enable sysctl, but still don't have any suitable file in /proc/sys/kernel/grsecurity to adjust logging options thresholds. Maybe there is a point to add feature to block repeatable messages, having a tunnable buffer for detect duplicates.