e116e9d9f5
RFC 9180 Section 5.1 defines default_psk = "" (empty byte string), not zeros of hash length. Fixed the HPKE key schedule to use ByteArray(0) instead of ByteArray(N_H) for the PSK parameter in Base mode. The EncryptWithLabel interop test remains failing (1/41) due to an unresolved HPKE key derivation discrepancy. The DH computation is correct (verified across Python nacl, cryptography, and Java XDH) but the derived AEAD key doesn't decrypt the test vector ciphertext. Investigation shows our LabeledExtract produces correct psk_id_hash but different info_hash compared to the RFC 9180 reference, suggesting a subtle version or encoding difference in the HPKE test vector generation. Final test results: 40/41 passing (98%). https://claude.ai/code/session_01NocQDWj2Y92FugjfgazzL3