@mirabilos sure, if that's your choice then that's your choice.
I have written code for AF_ALG and I run IPsec. (without ESNs, because that's the default in StrongSwan, and I haven't had reason to worry about rekeying.)
I know who @dalias is and I greatly respect them for their work on musl. But I'll stick with my opinion until someone claims at least the same experience level as I have. Maybe that's dalias, maybe not, idk their skills on this.