I doubt this will ever end up as a high-quality mode implementation in
Catacomb, because it doesn't actually provide authenticity. See
`Cryptanalysis of OCB2' by Akiko Inoue and Kazuhiko Minamatsu,
https://eprint.iacr.org/2018/1040.
This is enough to confirm their result.
* First, choose an arbitrary key and nonce, and encrypt a two-block
message whose first block contains len(0^{128}) = 128; the second
block is arbitrary.