Skip to content

Fix DeriveKey in Hkdf implementation - #2559

Merged
Robert Yokota (rayokota) merged 1 commit into
masterfrom
fix-hkdf
Jan 12, 2026
Merged

Robert Yokota (rayokota) merged 1 commit into
masterfrom
fix-hkdf

Conversation

@rayokota

@rayokota Robert Yokota (rayokota) commented Jan 12, 2026

Copy link
Copy Markdown
Member

What

Fixes #2558

Also add some unit tests

Checklist

  • [Y] Contains customer facing changes? Including API/behavior changes
  • [Y] Did you add sufficient unit test and/or integration test coverage for this PR?
    • If not, please explain why it is not required

References

JIRA:

Test & Review

Open questions / Follow-ups

@rayokota
Robert Yokota (rayokota) requested a review from a team as a code owner January 12, 2026 18:57
Copilot AI review requested due to automatic review settings January 12, 2026 18:57
@rayokota
Robert Yokota (rayokota) requested a review from a team as a code owner January 12, 2026 18:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a critical byte overflow bug in the HKDF (HMAC-based Key Derivation Function) implementation that would cause an infinite loop when deriving keys with exactly 255 blocks. The bug occurred because the loop counter was using a byte type, which wraps to 0 after reaching 255, causing an infinite loop condition.

Changes:

  • Fixed the loop variable type from byte to int in the HKDF Expand function
  • Added comprehensive test coverage for the bug fix, including edge cases with 255 blocks for multiple hash algorithms

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
src/Confluent.SchemaRegistry.Encryption/Vendored/HkdfStandard/Hkdf.cs Fixed byte overflow bug by changing loop variable from byte to int and casting when assigning to byte array
test/Confluent.SchemaRegistry.UnitTests/HkdfTests.cs Added comprehensive test suite covering the bug fix, including tests for maximum output length (255 blocks), deterministic behavior, various block sizes, and error conditions

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@sonarqube-confluent

Copy link
Copy Markdown

@rayokota
Robert Yokota (rayokota) merged commit 2152ec9 into master Jan 12, 2026
9 checks passed
@rayokota
Robert Yokota (rayokota) deleted the fix-hkdf branch January 12, 2026 20:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Infinite loop in Hkdf.Expand and DeriveKey caused by integer overflow

3 participants