shake_xof_3
if (!shake_xof_3(md_ctx, priv->shake256_md, priv->K, sizeof(priv->K),
if (!shake_xof_3(md_ctx, pub->shake256_md, mu_ptr, mu_len,