to64
to64(&salt[i], arc4random(), 4);
uint64_t *from64, *to64;
to64 = crypto_cursor_segment(toc, &toseglen);
to64);
gcm_ghash_v8(s.Xi.u, Htable, (uint8_t *)to64,
to64 += 2;
uint64_t *block64, *from64, *to64;
to64 = crypto_cursor_segment(toc, &toseglen);
to64);
to64 += 2;