package hkdf import ( stdhkdf "crypto/hkdf" "crypto/sha256" ) // Extract computes HKDF-Extract(salt, ikm) using SHA-256. // Note: parameter order is (salt, ikm) matching musiquay convention; // stdlib expects (h, secret, salt) - mapping is applied internally. func Extract(salt, ikm []byte) (v [32]byte) { if len(salt) == 0 { salt = []byte{:32} } prk, _ := stdhkdf.Extract(sha256.New, ikm, salt) var out [32]byte copy(out[:], prk) return out } // Expand derives length bytes of keying material from prk using SHA-256 HKDF-Expand. func Expand(prk, info []byte, length int32) (buf []byte) { out, _ := stdhkdf.Expand(sha256.New, prk, info, length) return out }