DJB himself has consistently advocated for Classic McEliece in any application which can accept its performance characteristics (which are excellent except for the ginormous public keys), and spent many bytes trying to convince people that the set of applications that can is wider than they suspect.
In other words, Bernstein proposed a NTRU-based scheme under his theory it was the most conservative. The only major attacks on lattice-based schemes since his proposal have been on the hardness assumption his scheme uses. I would personally suggest this means that Bernstein is not an accurate predictor of the security of lattice-based schemes. So far his track record (with this notable example, but also many others) is remarkably bad.
1. algebraic structure: sure use frodoKEM
2. error rates smaller than those required for worst-case to average-case reductions: idk bump error rates
3. some coding theorist ruins everyone's fun and has linear time decoding for p-ary construction A codes: probably drink a lot idk
fortunately there haven't been any "incremental" attacks in any of these directions, so it is really more an academic discussion.
Also note the primary issue with FrodoKEM isn't performance (though that is definitely worse), but size. My impression from the following
https://blog.cloudflare.com/sizing-up-post-quantum-signature...
https://blog.cloudflare.com/making-protocols-post-quantum/
was that TLS w/ FrodoKEM might have some undesirable performance characteristics, though that isn't directly stated in the articles. Iirc TLS w/ FrodoKEM
This is in fact that what I meant, and should have said: thanks.