I don't know if they have steps planned out, however, I can chime in on how it *could* be done. Please note that I don't know whether this is the right, or whether this actually works, since I've never patched a kernel before, and I don't have the time to compile a kernel and test it.
Within the Linux source tree (`linux/crypto`), there is a makefile (named "Makefile"). I think if you remove a few lines via the diff below, this feature will be disabled: ``` 172,176d171 < obj-$(CONFIG_CRYPTO_USER_API) += af_alg.o < obj-$(CONFIG_CRYPTO_USER_API_HASH) += algif_hash.o < obj-$(CONFIG_CRYPTO_USER_API_SKCIPHER) += algif_skcipher.o < obj-$(CONFIG_CRYPTO_USER_API_RNG) += algif_rng.o < obj-$(CONFIG_CRYPTO_USER_API_AEAD) += algif_aead.o ``` Sent with Proton Mail secure email. On Thursday, July 23rd, 2026 at 05:59, Ondrej Kozina via devel <[email protected]> wrote: > Hi Peter, > > On 23/07/2026 11:27, Peter Robinson wrote: > >>> The first phase uses the upstream patches due to land shortly, likely > >>> in 7.3, to limit the use of the API to the known apps and restricts > >>> the use. This allows Fedora to identify unknown users and gracefully > >>> deal with them before the active demise of the interface upstream > >>> providing users a more graceful process rather than universally > >>> pulling the rug without any notice. > >> > >> I don't understand what is the purpose of this change request. Do you > >> want to take additional steps beyond what kernel upstream currently > >> plans and switch off AF_ALG in before it's limited by upstream kernel? > >> Do you plan to "backport" those patches in earlier fedora kernels? Or > >> it's simply to announce that there's a upstream kernel change coming and > >> people should get ready for it? > > > > It's primarily communication and awareness and adding the upstream > > pieces at a release boundary, F-45 will ship with the 7.2 kernel, we > > don't want the upstream patches heading to 7.3 to suddenly break users > > mid release when upstream yanks whatever rug they choose whenever they > > choose. It doesn't make for a good user experience does it? > > > > Ok, public awareness aside (which I agree with), are there any Fedora > specific steps planned above what the upstream kernel plans to do? > > O. > > -- -- _______________________________________________ devel mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
