On Tue, 2023-02-14 at 14:54 +0100, Ard Biesheuvel wrote: [...] > and the requirement to use > scatterlists for skciphers is especially horrid. Just by way of irony, we do have one place that does use a two element scatterlist. It's how I found this bug: 95ec01ba1ef0 ("crypto: ecdh - fix to allow multi segment scatterlists"). And that does mean I could do with a library version of ecdh with the nist P-256 curve ... pretty please ... Regards, James