Files
go-sip/internal/configread/binding.go
T

30 lines
1000 B
Go

package configread
import (
"crypto/sha256"
"encoding/binary"
"encoding/hex"
"encoding/json"
"errors"
)
// ExecutionBindingSHA256 binds the exact immutable task and provider bytes
// to the SIP revision delivered to an Agent. Length prefixes prevent
// concatenation collisions; no credential content is returned or logged.
func ExecutionBindingSHA256(taskJSON, providersJSON []byte, sipRevision int64) (string, error) {
if !json.Valid(taskJSON) || !json.Valid(providersJSON) || sipRevision <= 0 {
return "", errors.New("execution snapshot has invalid JSON or SIP revision")
}
h := sha256.New()
var number [8]byte
binary.BigEndian.PutUint64(number[:], uint64(len(taskJSON)))
_, _ = h.Write(number[:])
_, _ = h.Write(taskJSON)
binary.BigEndian.PutUint64(number[:], uint64(len(providersJSON)))
_, _ = h.Write(number[:])
_, _ = h.Write(providersJSON)
binary.BigEndian.PutUint64(number[:], uint64(sipRevision))
_, _ = h.Write(number[:])
return hex.EncodeToString(h.Sum(nil)), nil
}