fn provenance_content(archive_sha256: &str, binary_sha256: &str) -> String
Returns the provenance marker content for a verified extraction: the manifest-pinned archive digest and the digest of the extracted binary.