kdf
static void kdf(void *bufp, aes_int_key key, UINT8 ndx, int nbytes)
static __owur int kdf(uint8_t out[ML_KEM_SHARED_SECRET_BYTES],