Ticket #12980, comment 4
I only see one place t is used other than in the derivation of s_t, in the derivation of the symmetric key k_t. Using s_t in place of t should be fine here, since the security proof only relies on the reduction knowing s_t.