noble rejects multiply(0n) exactly as libsodium rejects a zero scalar, and
the TypeScript SDK read the refusal as an invalid opening the same way
Python did. Both now multiply a zero scalar to the identity by hand.
gtank/ristretto255 accepts it, so the Go module was correct all along. Three
implementations: two agreed with each other and both were wrong, and the one
that matched the Rust core stood alone. That is the argument for a shared
corpus rather than per-language tests -- two implementations agreeing is not
evidence.
The zero vector is now consumed by all three, so the coverage contract holds
every client to it: 27 of 27 in Python, Go and TypeScript.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>