30 lines
1000 B
Go
30 lines
1000 B
Go
package configread
|
|
|
|
import (
|
|
"crypto/sha256"
|
|
"encoding/binary"
|
|
"encoding/hex"
|
|
"encoding/json"
|
|
"errors"
|
|
)
|
|
|
|
// ExecutionBindingSHA256 binds the exact immutable task and provider bytes
|
|
// to the SIP revision delivered to an Agent. Length prefixes prevent
|
|
// concatenation collisions; no credential content is returned or logged.
|
|
func ExecutionBindingSHA256(taskJSON, providersJSON []byte, sipRevision int64) (string, error) {
|
|
if !json.Valid(taskJSON) || !json.Valid(providersJSON) || sipRevision <= 0 {
|
|
return "", errors.New("execution snapshot has invalid JSON or SIP revision")
|
|
}
|
|
h := sha256.New()
|
|
var number [8]byte
|
|
binary.BigEndian.PutUint64(number[:], uint64(len(taskJSON)))
|
|
_, _ = h.Write(number[:])
|
|
_, _ = h.Write(taskJSON)
|
|
binary.BigEndian.PutUint64(number[:], uint64(len(providersJSON)))
|
|
_, _ = h.Write(number[:])
|
|
_, _ = h.Write(providersJSON)
|
|
binary.BigEndian.PutUint64(number[:], uint64(sipRevision))
|
|
_, _ = h.Write(number[:])
|
|
return hex.EncodeToString(h.Sum(nil)), nil
|
|
}
|