90
Chapter 6. Tools for Manipulating and Analyzing SELinux
cat /selinux/avc/cache_threshold
512
echo 768 > /selinux/avc/cache_threshold
# Check to be sure the change took hold.
Be sure you are
# root when using the targeted policy.
cat /selinux/avc/cache_threshold
768
Caution
The default value of 512 for the cache threshold in Red Hat Enterprise Linux is set from extensive
optimization benchmarking. Changing this value could have negative effects on system performance.
To be sure adjusting the cache limit is having positive effects on your performance, watch the num
ber of reclaimed cache entries. Stale cache entries can build up following boot or long after daemon
startup, which requires reclaiming entries when more are required for new processes. If you have a
system where there are a high number of entries changing across a broad enough policy, this reclama
tion may occur more often and effect system performance. You can watch the
reclaims
column in
the output of
avcstat
using the
c
option, which displays the cumulative values:
avcstat c 1
... reclaims ...
...
800 ...
...
830 ...
...
876 ...
...
912 ...
...
955 ...
...
992 ...
Occasional reclaim activity is within the bounds of normal, and it may increase when changing work
loads. Excessive reclaims over a sustained period of time should be looked into.
footer
Our partners:
PHP: Hypertext Preprocessor Best Web Hosting
Java Web Hosting
Inexpensive Web Hosting
Jsp Web Hosting
Cheapest Web Hosting
Jsp Hosting
Cheap Hosting
Visionwebhosting.net Business web hosting division of Web
Design Plus. All rights reserved