SLH-DSA: Don't recompute PK.root when signing
The HT constructor always built the top-layer XMSS tree to derive htPubKey, so every signature repeated the whole of key generation (about 1/d of the signing work) to compute a value the private key already holds in PK.root. Move the root computation into an explicit HT.pkGen() that only key generation calls, and call it once there rather than once per key half.
P
Peter Dettman committed
af3c793b9cc938de81218643ea71420167d2d57f
Parent: b1c75bf