const L_LO: u128 = 0x14def9dea2f79cd6_5812631a5cf5d3ed;
const L_HI: u128 = 1 << 124;
#[inline(always)]
fn halves(s: &[u8; 32]) -> (u128, u128) {
let lo = u128::from_le_bytes(s[..16].try_into().unwrap());
let hi = u128::from_le_bytes(s[16..].try_into().unwrap());
(hi, lo)
}
#[inline]
pub fn is_canonical(s: &[u8; 32]) -> bool {
halves(s) < (L_HI, L_LO)
}
#[inline]
pub fn negate_challenge(c: &[u8; 16]) -> [u8; 32] {
let c = u128::from_le_bytes(*c);
if c == 0 {
return [0; 32];
}
let (lo, borrow) = L_LO.overflowing_sub(c);
let hi = L_HI - borrow as u128;
let mut out = [0u8; 32];
out[..16].copy_from_slice(&lo.to_le_bytes());
out[16..].copy_from_slice(&hi.to_le_bytes());
out
}