Fix DeriveKey in Hkdf implementation - #2559
Merged
Merged
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
This PR fixes a critical byte overflow bug in the HKDF (HMAC-based Key Derivation Function) implementation that would cause an infinite loop when deriving keys with exactly 255 blocks. The bug occurred because the loop counter was using a byte type, which wraps to 0 after reaching 255, causing an infinite loop condition.
Changes:
- Fixed the loop variable type from
bytetointin the HKDF Expand function - Added comprehensive test coverage for the bug fix, including edge cases with 255 blocks for multiple hash algorithms
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| src/Confluent.SchemaRegistry.Encryption/Vendored/HkdfStandard/Hkdf.cs | Fixed byte overflow bug by changing loop variable from byte to int and casting when assigning to byte array |
| test/Confluent.SchemaRegistry.UnitTests/HkdfTests.cs | Added comprehensive test suite covering the bug fix, including tests for maximum output length (255 blocks), deterministic behavior, various block sizes, and error conditions |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
Toluwa Jibodu (djibodu)
approved these changes
Jan 12, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.




What
Fixes #2558
Also add some unit tests
Checklist
References
JIRA:
Test & Review
Open questions / Follow-ups