294 | @@ -295,6 +295,20 @@ static void test_send_api(void) {
295 | p2[0] = secp256k1_group_order_bytes;
296 | CHECK(secp256k1_silentpayments_sender_create_outputs(CTX, op, rp, 2, SMALLEST_OUTPOINT, NULL, 0, p2, 2) == 0);
297 | }
298 | + /* Check that an invalid keypair is caught even when it is passed alongside a valid one.
The "first nor last keypair skipped" rationale is already covered by the existing checks. What this block actually adds is the invalid-first ordering: if the early return 0; were dropped, a valid keypair followed by an invalid one still fails via the zero-sum check, but an invalid keypair followed by a valid one leaves a nonzero sum and wrongly succeeds.
Could you reword the comment to say that, e.g. "pass the invalid keypair first, followed by a valid one, so that silently skipping it is not masked by the subsequent zero-sum check"?
Reworded the comment in a044ade to explain the invalid-first case, and updated the PR description to match. Also applied the const placement suggestion in ca6b4a2.