Squashed 'strobe/' changes from 66b501fd..0aa9e2ab
0aa9e2ab change signature on x25519 mul because b[] length isnt always NLIMBS; thanks JMG for pointing out that this now causes a warning
7d7f6053 Change sub() so that it should work with non-propagate'd inputs. This has no effect on Strobe's usage of sub(), but it may reduce the risk of problems if the code is imported into other projects.
git-subtree-dir: strobe
git-subtree-split: 0aa9e2abcaa4e6364c97a914d397517668475209