Eric W. Biederman wrote:
My hypothesis.  No one cares now.

My observation. The way we have been maintaining the binary sysctl
side of things using it is asking for your application to be broken in
subtle and nasty ways.

I suspect the right thing to do is simply to make a list of the
supported binary sysctls, and automatically verify those numbers. Doing
that would alleviate these concerns, wouldn't break anything, and isn't
really that hard to do.
