package configread import ( "crypto/sha256" "encoding/binary" "encoding/hex" "encoding/json" "errors" ) // ExecutionBindingSHA256 binds the exact immutable task and provider bytes // to the SIP revision delivered to an Agent. Length prefixes prevent // concatenation collisions; no credential content is returned or logged. func ExecutionBindingSHA256(taskJSON, providersJSON []byte, sipRevision int64) (string, error) { if !json.Valid(taskJSON) || !json.Valid(providersJSON) || sipRevision <= 0 { return "", errors.New("execution snapshot has invalid JSON or SIP revision") } h := sha256.New() var number [8]byte binary.BigEndian.PutUint64(number[:], uint64(len(taskJSON))) _, _ = h.Write(number[:]) _, _ = h.Write(taskJSON) binary.BigEndian.PutUint64(number[:], uint64(len(providersJSON))) _, _ = h.Write(number[:]) _, _ = h.Write(providersJSON) binary.BigEndian.PutUint64(number[:], uint64(sipRevision)) _, _ = h.Write(number[:]) return hex.EncodeToString(h.Sum(nil)), nil }