CHACHA_BLOCKLEN
chacha_encrypt_bytes(ctx, in, out, CHACHA_BLOCKLEN);
KASSERT(len % CHACHA_BLOCKLEN == 0, ("%s: invalid length", __func__));
.native_blocksize = CHACHA_BLOCKLEN,
blockcount = howmany(nbytes, CHACHA_BLOCKLEN);
rounddown((size_t)UINT32_MAX, CHACHA_BLOCKLEN));
blockcount = howmany(bytecount, CHACHA_BLOCKLEN);
rounddown((size_t)UINT32_MAX, CHACHA_BLOCKLEN));
uint8_t inputle[16], expectedle[16], trash[CHACHA_BLOCKLEN];