hi again, was trying to use learning mode to capture everything done by applications under a certain directory. To be specific I was trying to watch all executables under /etc/rc.d/init.d during a shutdown. It appears that you can only enable learning mode one application at a time and not for a directory acl entry. An error or warning message telling me i was using learning mode incorrectly would have helped. Having said that, perhaps it's an expensive error to test for.
Anyway, i'm still having fun locking my machine down and really just wanted to say thanks for the effort you've put into Grsecurity.
Now, anyone know where i can find a decent hacker to check my work so far