INFRA Signal 90
Linux 7.3 adds new AF_ALG restrictions after 7.2 deprecation, citing security and maintenance burden
Illustration only Photo by Tyler on Unsplash
Linux 7.3 will impose further restrictions on AF_ALG, the interface that exposes the kernel's internal cryptography API to user-space programs, continuing a multi-cycle trend of removing features such as zero-copy support and offloading.
AF_ALG gave user-space programs direct access to kernel crypto primitives, but maintainers have deemed the interface a security and maintenance liability. Engineers relying on AF_ALG should expect diminishing functionality and plan for migration to alternatives. Only one feed carries this story and no article body was available, so details on the specific new restrictions are limited.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
AF_ALG was deprecated in Linux 7.2 and faces additional restrictions in 7.3.
Previously dropped AF_ALG features include zero-copy support and offloading.
The restrictions stem from security and maintenance concerns around exposing kernel crypto internals to user-space.
THE READ
What the cluster adds up to.
The material comes from a single feed with no article body, so the picture is incomplete. What is clear is that AF_ALG, the kernel interface letting user-space programs access the kernel's internal cryptography API, has been under sustained pressure across recent kernel cycles. Linux 7.2 deprecated it, and 7.3 will add further restrictions, though the specific new restrictions are not enumerated in the available material.
The stated motivation is a combination of security exposure and maintenance burden. Exposing kernel crypto internals to user-space creates an attack surface that maintainers find difficult to sustain. Prior cycles already removed zero-copy support and offloading, indicating a pattern of incremental removal rather than a single breaking change.
For engineers building systems that depend on AF_ALG for cryptographic operations, the practical consequence is a shrinking feature set across kernel upgrades. Systems pinned to older kernels will retain functionality temporarily, but forward compatibility is uncertain. The material does not specify what replacement interfaces or libraries are recommended, so migration planning cannot be grounded from this source alone.
The framing as a 'security and maintenance nightmare' suggests the trajectory is toward further restriction or eventual removal rather than stabilization. Engineers should treat AF_ALG as a deprecated dependency and audit where it appears in their stack. Without the article body, the scope of the 7.3 restrictions and any migration guidance remain unknown.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER