Since the curve is an abelian group, it has a module structure, consisting of these scalars. They are the integers modulo "ell", where "ell" is 2**252 + something something.
NB: The buffer is assumed to be zero from
byte 32 onward - each operation should call
32 octets, interpreted as little-endian 256 bit unsigned integer
64 octets, interpreted as little-endian 512 bit unsigned integer