The successor of RFC 9180 as draft-ietf-hpke-hpke-04 specifies it, with the one-stage SHA-3 KDFs of draft-ietf-hpke-pq-05, Section 5.
This is a separate, versioned module, so that Rfc9180 keeps its wire behavior: nothing here changes what an Rfc9180 function does. The draft is not yet an RFC, and this module follows revision 04 of it; a later revision that changes the wire gets a module of its own.
The draft is RFC 9180 without the Auth and AuthPSK modes, and with a second kind of KDF. With an HKDF a suite runs the RFC 9180 Base and PSK modes unchanged, so its keys, encapsulations, ciphertexts and exports are those of Rfc9180. With a one-stage KDF, SHAKE128 or SHAKE256, the key schedule derives the key, base nonce and exporter secret in one call of LabeledDerive, and so does Sender.export. Every KEM works with every KDF, those of the draft included. TurboSHAKE128 and TurboSHAKE256 (0x0012 and 0x0013) are not provided yet.
Keys, KEMs, AEADs, PSKs, errors and contexts are those of the rest of the library. Private_key.to_bytes clamps X25519 and X448 keys, where the draft serializes them unclamped; both describe the same key pair.
With a one-stage KDF, info, a PSK and its identifier may each hold at most 65535 bytes (Section 7.2.1), and a longer one is Error.t.Invalid_length. An export may be up to 65535 bytes long.