I made an edit to linebreaking in props.conf, then used the CLI "splunk add oneshot " to index a file, saw that new events were indexed, but still according to the old line-breaking scheme. After a splunk restart and another "add oneshot", the new linebreaking scheme was honored. Is a restart each time the only way to incorporate edits to props.conf?
Not anymore you don't. That used to be the case, but as of 4.x (iirc) each search will be run in its own process so it will read all settings at the time of initialization. So, the latest search-time settings will always be used.