Shit, you're right. (PBKDF2 generates arbitrary-length output, which is what you want from a key derivation function, but maybe not something you care about for a password hash).
Here's a version that's much easier to read than the spec:
https://github.com/emerose/pbkdf2-ruby/blob/master/lib/pbkdf...
I should stop saying PBKDF2 and just go back to saying PBKDF.