Informational BIP describing low-R grinding: re-deriving the ECDSA nonce under a counter until r has its high bit unset, so the DER encoding needs no leading null byte.
This was discussed on the mailing list: https://groups.google.com/g/bitcoindev/c/boEZRlqczvw
Reference implementation and test vectors are TODO.
Feedback is very welcome.