afcdd5cb3e
- Fix GLV_MINUS_LAMBDA constant (d[1] and d[2] were incorrectly computed from Kotlin signed-to-unsigned conversion) - Fix scalar_mul reduction: the carry from folding high limbs was silently dropped when the target position exceeded 4 limbs. Use proper row-based fold with carry propagation into higher positions - Fix in-place gej_double aliasing: when r == p, the output overwrites the input during computation. Added explicit copy-on-alias Verified working: pubkeyCreate, 2*G, (n-1)*G, ecmult for all scalar sizes. Verify path still needs debugging (ecmult_double_g gives correct result for simple cases but the full sign→verify round-trip has a hash/nonce mismatch). https://claude.ai/code/session_011KVZhDcV2G7idNWEBz12GY