Merge pull request #831 from gilles-peskine-arm/mpi_fill_random-constant_time_comparison-development_2.x-restricted

Backport 2.x: Fix small timing side channel in ECDSA ephemeral key generation