050cf39a54
The sign_xonly function incorrectly assumed even y-parity for all keys. BIP-340 requires checking the actual y-parity of the derived pubkey and negating the secret key when y is odd. Without this, signatures for keys with odd-y pubkeys (roughly half of all keys) were invalid. All operations now pass correctness tests: - sign + verify for keys 1, 2, 3, 0xff, and 0xd217c1... (random) - verify_fast (skip y-parity check) - batch_verify (5 signatures from same pubkey) C standalone benchmark (x86_64): verifySchnorrFast: 52 µs (19,143 ops/s) verifySchnorr: 60 µs (16,616 ops/s) signSchnorr: 109 µs (9,177 ops/s) pubkeyCreate: 54 µs (18,381 ops/s) ecdhXOnly: 59 µs (16,958 ops/s) https://claude.ai/code/session_011KVZhDcV2G7idNWEBz12GY