That seems reasonable enough; especially if a patch already
exists.

Sent with Proton Mail secure email.

On Friday, July 24th, 2026 at 05:56, Ondrej Kozina via devel 
<[email protected]> wrote:

> On 23/07/2026 20:13, Justin Forbes wrote:
> > On Thu, Jul 23, 2026 at 3:59 AM Ondrej Kozina via devel
> >>
> >> Ok, public awareness aside (which I agree with), are there any Fedora
> >> specific steps planned above what the upstream kernel plans to do?
> >
> > Somewhat. I do plan to disable it completely for F46. If upstream
> > doesn't do so first, it can still be enabled in F45, but that will be
> > the last release.
> 
> The upstream has a plan for restricted mode with allow list for AF_ALG
> and there's a clear justification for it (links below). I currently do
> not follow why this is not enough for Fedora going forward, so I'd like
> to hear more if we want to go further then that.
> 
> My arguments against turning the AF_ALG _completely_, without
> replacement are as follows:
> 
> - there's no xts mode implemented for camellia, serpent and twofish
> ciphers in openssl (I mention only the most used AES alternatives). So
> the cryptsetup (in Fedora) will loose userspace access to those ciphers
> without CAP_SYS_ADMIN. Affects LUKS2.
> 
> - No Adiantum in userspace crypto libraries currently supported by
> libcryptsetup. The fallback via dm-crypt will again need CAP_SYS_ADMIN.
> Affects LUKS2.
> 
> - Limited support for truecrypt/veracrypt containers. Only ciphers
> available in userspace crypto libraries remains usable. No dm-cryt
> fallback possible. Again, look at missing support for xts mode above.
> 
> The AES is default and will be, but there are use cases where AES is not
> a good fit (low end embedded devices with no HW support) and if you turn
> the AF_ALG off completely, it will cause headache.
> 
> - no cryptsetup benchmark for block ciphers (no replacement even with
> CAP_SYS_ADMIN). Though, I'd not personally deem it critical.
> 
> O.
> 
> [1]
> - allow list:
> https://lore.kernel.org/linux-crypto/[email protected]/
> 
> - extended allow_list for other use cases:
> https://lore.kernel.org/linux-crypto/[email protected]/
> 
> --
-- 
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to