/// <div class="eli5"><b>ELI5.</b> An ideal functionality is the specification the protocol is measured against: who holds what, what goes in, what comes out, and which values become public.</div>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1. Each holds one share.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> An additive share, a subtractive share, or an XOR share.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Both parties receive the opened value:<BR/>additive is share0 + share1, subtractive is share0 - share1,<BR/>XOR is share0 XOR share1.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> That opened value, and nothing else.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> Evaluators 1, 2, and 3 over fp61.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> A secret s. The dealer samples a uniform slope a.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Party i receives s_i = s + a*i.<BR/>Any two parties reconstruct s by Lagrange.<BR/>A share embeds into a 61-bit XOR string for the (2,3) point key.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> One share hides s. Two shares reveal it.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> An honest dealer, then evaluators P0 and P1.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> A secret point alpha and one or more payloads beta.<BR/>A payload may be a wildcard, filled later by F_Assign.<BR/>The interior PRG is BGI or Half-Tree. The outputs do not change.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Key k_i to party i.<BR/>Eval(x) returns subtractive shares of beta when x = alpha, else 0.<BR/>An XOR payload is an XOR share. Several outputs are independent.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> The keys hide alpha and beta.<BR/>Eval of an unassigned wildcard aborts.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> Same dealer and two evaluators as F_DPF.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> Secret point alpha.<BR/>Each output is placed at a public prefix length.<BR/>An optional comparison spec adds an F_DCF channel on the same alpha.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> One key per party.<BR/>Eval of a prefix slot returns that slot's shares on its programmed domain.<BR/>The comparison channel returns F_DCF shares.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> None beyond those shares. A wildcard slot aborts until F_Assign.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> An honest dealer holding both F_IDPF keys, then evaluators P0 and P1.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> An existing key pair for secret alpha.<BR/>
/// extend: the next path bit of alpha and specs whose prefixes equal the new depth.<BR/>
/// add_output: specs whose prefixes are already levels of the key.<BR/>
/// Optional warm path memoizers supply the on-path seeds (must already be filled).</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> A new key pair whose type is the old key plus the new material.<BR/>
/// Earlier correction words, advice bits, leaves, and comparison words are unchanged share for share.<BR/>
/// Eval of an old slot on the new keys matches the old keys. New slots match F_IDPF for those specs.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> None beyond the new keys. Specs that need a deeper tree, share a packing group with an old slot, or sit on the wrong level abort.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1, holding keys from F_DPF or F_IDPF.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> A payload beta, or shares of beta, for a wildcard slot.<BR/>A public delta is applied as given.<BR/>A subtractive share is converted with that party's coefficient.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> The same keys, now evaluating to shares of beta at alpha.<BR/>Alpha does not move.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> None. Eval before Assign aborts.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> An honest dealer, then evaluators P0 and P1.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> Secret point alpha, payloads if_true and if_false,<BR/>and a predicate lt, leq, gt, or geq.<BR/>A path-paint kind plants one public constant on each sibling subtree.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> One key per party.<BR/>Eval(x) returns additive shares of if_true when the predicate holds,<BR/>and of if_false otherwise.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> None. The same outputs are realized by F_BDCF.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> Same dealer and evaluators as F_DCF.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> The F_DCF inputs, plus a public checkpoint schedule.<BR/>Ring words are stored only at those checkpoints.<BR/>A residual tail, when the key sets it, is a table on the node at that height.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Additive shares of the same predicate or path-paint as F_DCF.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> The schedule is public. It does not reveal alpha.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> An honest dealer, then evaluators P0 and P1.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> Secret mask r, public bounds p and q,<BR/>and payloads if_true and if_false.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> One key per party.<BR/>Eval(x) returns additive shares of if_true when<BR/>p <= (x - r) mod 2^n <= q, and of if_false otherwise.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> The bounds are public. r and the payloads stay hidden.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> An honest dealer, then evaluators P0 and P1.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> t distinct points and their payloads.<BR/>The verifiable tag selects VDPF buckets.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> m = O(t) bucket keys on a cuckoo packing with 3 probes.<BR/>Eval(x) sums the three probed buckets and matches the sum of the t point functions.<BR/>A batched proof is one 2-lambda token.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> None beyond the output shares and, when requested, the proof.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1. Semi-honest. Base OT is Chou-Orlandi.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> sample: both parties pass the same lengths<BR/>(bit x block, bit x bit, B2A, correction-word pads).<BR/>transfer_labels: the sender holds two 128-bit strings per row;<BR/>the receiver holds a choice bit per row.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> sample gives each party its share of the pads:<BR/>bit x block, bit AND, a daBit, and a correction-word gamma<BR/>that hides the peer pad bit.<BR/>transfer_labels gives the receiver exactly the chosen string.<BR/>The sender's output buffer is cleared. An empty transfer sends nothing.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> Lengths are public. Choice bits, the unchosen string,<BR/>and the peer pad bit stay hidden.<BR/>One role_state is one direction; the first call runs the base OT.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1 hold the point. P2 deals pads and learns nothing.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> XOR shares of alpha, or additive shares.<BR/>Additive shares are converted by a ripple-carry. The sum is not opened.<BR/>Beta is public, or additively shared as leaf-key material without opening the payload.<BR/>An optional Reveal flag asks for the encoded point (and, for a packed wildcard, the lane).</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Each of P0 and P1 receives the F_DPF or F_DCF key make_dpf would emit<BR/>for that alpha, the same roots, and the same beaver coins.<BR/>When Reveal is set, the encoded point is an explicit output,<BR/>and a packed wildcard also returns its lane. Paint comparisons require Reveal.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> Default leakage is none beyond the keys.<BR/>P2 receives neither the point, the prefix, nor the payload.<BR/>The tree prefix, the lane, and a shared payload stay hidden unless Reveal is set.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1. No reusable key is returned.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> XOR or additive shares of alpha, a public or shared payload,<BR/>and a public query: one point, an interval, a sequence, or the full domain.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Shares of F_DPF on that query.<BR/>Leaves are subtractive. Comparison prefixes are additive.<BR/>geneval_cmp returns a prefix share at each public endpoint.<BR/>The point is not opened. Additive inputs are converted without opening the sum.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> Evaluators receive the query-trie correction words.<BR/>Off-path words are uniform. On-path words match a dealer key and hide the point.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1 evaluate. P2 is an honest dealer.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> Additive shares of wires, and a public formula:<BR/>a polynomial, an inner product, a scale, or a bit-mux.<BR/>A later round may reuse a wire. Repeated factors share one blind.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Additive shares of the formula. P2 learns nothing.<BR/>Classic triples are the same functionality on fresh wires.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> None. Opened masks delta = x + lambda are uniform.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> Same as F_Beaver. A MAC key Delta is fixed before sampling.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> The F_Beaver inputs. Every blind, monomial, and value is tagged under Delta.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> The same additive shares, together with tag shares.<BR/>verify_delta and verify_auth_opening accept only consistent tags.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> None when the check accepts. A bad tag aborts.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> Positive integers with absolute difference 1.<BR/>Each party forms two bits from the low bits of its input.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Both parties receive the bit 1{x0 < x1}.<BR/>The bit is one AND of those derived bits.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> That bit. If the inputs do not differ by one, the protocol aborts.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1, on keys generated under the verifiable tag.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> The F_DPF inputs, plus a public evaluation point.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> The F_DPF share, and a 2-lambda proof token from each party.<BR/>Verify accepts exactly when the path and the output share match:<BR/>correction seeds, the leaf correction word, and comparison value words fold into the token.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> The accept or reject bit. Nothing else.<BR/>A tampered seed, leaf, value word, or proof rejects. A zero token rejects.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1, on an extractable key. Default eval does not fold.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> Payload shares written during evaluation,<BR/>and caller-chosen fp61 challenges, one per payload.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Subtractive shares of three moments (z1, z2, z3).<BR/>sketch_verify accepts when z2^2 = z1*z3 after the shares are opened,<BR/>that is, when the opened payloads have at most one nonzero point.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> The accept or reject bit. A second hot point rejects.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1. Correlated AND triples come from the dealer tape.<BR/>The two-party realization is party/oblivious_hash.hpp.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> Each party holds the seed it owns,<BR/>and a XOR share of the path prefix. The level is public.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Both parties receive H(s0) XOR H(s1),<BR/>the same block as hash_node on the joined prefix and the two seeds.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> That opened block. The prefix is not opened.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> An honest dealer and evaluators 1, 2, and 3.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> Secret point alpha and payload beta in fp61.<BR/>The updatable tag keeps the leaf writable.<BR/>The verifiable and extractable tags select those checks.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> One key per evaluator.<BR/>Eval(x) is a degree-1 Shamir share of beta when x = alpha, else 0.<BR/>Any two parties reconstruct. Update(beta') rewrites the payload and does not move alpha.<BR/>Update on a non-updatable key aborts. verify_dpf3 accepts only a consistent triple of proofs.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> One key hides alpha and beta. A bad proof rejects.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> Two shareholders of alpha, producing keys for three evaluators.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> XOR shares of alpha, after the signed-MSB flip on share 0.<BR/>Payload beta in fp61 is a shared input of keygen, not an opened point.<BR/>Verifiable, updatable, and extractable select the same options as F_DPF3.<BR/>Reveal on a spine is the same optional flag as F_DS.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Three F_DPF3 keys for alpha = x0 XOR x1 and that beta.<BR/>Two independent Doerner-Shelat spines carry the Fig. 3 payloads.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> Neither share alone reveals alpha or beta.<BR/>The point and the payload stay shared unless Reveal is set on a spine.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> Evaluators 1, 2, and 3.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> A secret comparison or interval point, and a payload.<BR/>Each evaluator holds one DCF half. A Shamir tip of the payload is bookkeeping for updates.<BR/>Interval containment also takes the public scale c_x in {-1, 0, 1}.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> One additive share of the F_DCF or F_IC predicate value per evaluator,<BR/>unreduced in uint64. A complementary pair (1 with 2, or 3 with 2) opens by summation into fp61.<BR/>One party holds one DCF share, not both.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> One evaluator does not learn the point or the clear payload.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> Same three evaluators as F_DPF3.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> t distinct points and fp61 payloads.<BR/>Packing matches F_MPDPF. Each bucket is an F_DPF3 key.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Eval(x) sums Shamir shares across the three probes<BR/>and reconstructs to the sum of the t point functions.<BR/>Update replays the existing cuckoo placement and rewrites each occupied bucket.<BR/>It does not draw a new packing.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> Same as F_DPF3 on each bucket.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1. The dealer keyed powers 1, c, c^2, c^3 at a hidden center.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> Additive shares of x. Public coefficients of a cubic.<BR/>The parties open eta = x - r. The center is 2r when wired that way.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Additive shares of the polynomial at the wrapped group element.<BR/>The binomial shift by the public carry kappa is local. No further round.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> eta. Not x, and not the center.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1, after the same public opening of eta as F_Horner.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> A polynomial of runtime degree, at most 16.<BR/>Coefficients are public, or additively shared.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Additive shares of f at the wrapped x.<BR/>Public coefficients are a local binomial shift and a dot.<BR/>Shared coefficients use that local shift and one F_Beaver inner product.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> eta, and nothing further from F_Beaver.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1. The dealer keyed binom(center, k) for k = 0..d.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> Additive shares of x. The parties open eta = x - r.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Additive shares, in Z/2^64, of binom(x, 0), ..., binom(x, d)<BR/>after the public Chu-Vandermonde shift by the carry kappa.<BR/>A public dot, forward difference, or hockey-stick prefix is local.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> eta. Not x, and not the center.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1. The dealer keyed the wrap comparison and a split of r.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> An n-bit limb x, n at most 64, and a public destination modulus.<BR/>The parties open eta = x - r.<BR/>Destinations are zn64, zn128, field128, and the P-256 scalar field.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Additive shares of x in that residue group.<BR/>The wrap indicator stays inside the share. A factor of the modulus reduces locally.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> eta. Not x, and not the wrap bit in the clear.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1. The dealer keyed a state vector S_c at the hidden center.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> A public invertible matrix M over Z/2^64, or XOR shares for a GF(2) checkpoint.<BR/>The parties open eta = x - r. The hot piece has a public carry kappa.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Shares of M^kappa * S_c.<BR/>Negative kappa multiplies by M inverse. The determinant must be odd.<BR/>Fibonacci, geometric powers, and a CRC jump are this functionality.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> eta and the public matrix power. Not the state, and not the center.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1. The dealer keyed c^m * lambda^c in Z/2^64.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> Public coefficients a_m and a public unit lambda, or the dyadic tag lambda = 1/2.<BR/>The parties open eta = x - r. The hot piece has public carry kappa.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> For odd lambda, additive shares of sum a_m (c+kappa)^m lambda^(c+kappa).<BR/>For lambda = 1/2, additive shares of sum a_m x^m / 2^x.<BR/>The untwisted sum is shifted by a masked low-limb carry. The opened mask is uniform.<BR/>The untwisted sum stays shared.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> eta. Not the untwisted sum, and not the center.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1, with optional verifiable comparison keys and a MAC key.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> Additive shares of an n-bit limb, a public shift, and,<BR/>for the carry-out form, public knowledge that the secret is negative, nonnegative, or unknown.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> Additive shares of the matching cleartext oracle:<BR/>exact truncate-and-reduce, arithmetic right shift plus the unit correction,<BR/>exact fused arithmetic right shift, signed extension,<BR/>unknown-sign carry-out, window overflow, or fused same-ring.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> A fresh masked opening is uniform and hides the secret limb.<BR/>A bad path proof or a bad MAC aborts. The secret limb is not learned.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> A public straight-line bit netlist.<BR/>Each shared input is an XOR share of that bit.<BR/>A private input is known to one party.<BR/>The usual source of those bits is a DPF leaf, via F_YaoShare.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> XOR shares of each output bit.<BR/>P0's share is the permute bit of the zero label.<BR/>P1's share is the color of the label it holds.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> None beyond the output shares.<BR/>Tables are one-time. P1 does not learn Delta.<BR/>P0 does not learn P1's private bits or P1's shares.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1. For a replicated leaf, P2 is idle.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> One share each of an integer the DPF already produced:<BR/>subtractive (point leaf), additive (comparison leaf),<BR/>an fss_share, or the party-0 and party-1 replicated views.<BR/>The reverse calls take XOR shares of the low width bits.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> XOR shares of those bits, least-significant bit first,<BR/>or ring shares of the integer the bits encode, in the leaf's scheme.<BR/>y2rss deals a fresh replicated triple of that integer.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> A2B opens a masked x - r. B2A opens a masked bit.<BR/>Both masks are uniform. The integer stays shared.<BR/>This is not the local (3,3) cast dpf::rss2y / dpf::y2rss.</TD></TR>
/// </TABLE>
/// >];
/// }
/// \enddot
/// \htmlonly
/// <div class="tldr"><b>TL;DR.</b> Each figure states the parties, the inputs, the outputs, and what is revealed. A masked value or a public offset appears only when the parties learn it.</div>