Hkdf
lib/hkdf.march — HKDF-SHA256 (RFC 5869) key derivation.
Built on the hmac_sha256_bytes builtin (Bytes -> Bytes -> Bytes) so the pseudorandom key stays raw bytes end-to-end: round-tripping key material through a String would UTF-8-encode bytes >= 0x80 and silently change it.
Used by Crypto.derive_key; call Crypto.hkdf_sha256 / Crypto.derive_key from application code rather than this module directly.
Functions
RFC 5869 §2.3 expand step: stretch a pseudorandom key prk to len bytes of output keying material, bound to the context string info.
RFC 5869 §2.2 extract step: PRK = HMAC-SHA256(salt, ikm).
HKDF-SHA256 (RFC 5869): derive len bytes of output keying material from input keying material ikm, a salt, and a context info string.
PRK = HMAC-SHA256(salt, ikm) -- extract
T(i) = HMAC-SHA256(PRK, T(i-1) ++ info ++ byte(i))
OKM = first `len` bytes of T(1) ++ T(2) ++ … -- expand
`len` must be at most 8160 (255 blocks x 32 bytes, the RFC limit).