affaan-m/ECC · error
audit health evidence does not match its evaluation
Error message
audit health evidence does not match its evaluation
What it means
When the audit entry references an evaluation (entry.evaluation_id), the verifier loads that evaluation's own health evidence metadata and re-runs the same integrity verification on it. If the evaluation's evidence fails verification, the audit entry's evidence is deemed inconsistent with its source evaluation.
Solutions
- Ensure audit events attach the exact snapshot stored on their evaluation (same JSON, digest, asserted flag, status)
- Re-run the promotion/audit flow so both records are written together from one health check result
- Inspect the harness_evaluations row for the evaluation_id and reconcile or regenerate its evidence to match
Defensive patterns
Strategy: validation
Validate before calling
// Reuse the evaluation's stored evidence when writing the audit entry let (json, digest, asserted, status) = load_evaluation_evidence(evaluation_id)?; attach_audit_evidence(entry, json, digest, asserted, status);
Prevention
- Write the audit event and its evaluation's evidence in the same transaction from one snapshot
- Never copy audit rows between evaluations
- If evaluation evidence is regenerated, rewrite the linked audit evidence in the same change
When it happens
Trigger: An audit event whose evidence snapshot was generated independently of (or differs from) the evidence stored on the linked harness_evaluation row; the evaluation's evidence failing any of the prior checks (missing, oversized, digest mismatch).
Common situations: Copying audit rows between evaluations; regenerating an evaluation's evidence after the audit event was written; partial updates where evaluation evidence changed but audit evidence did not.
Understand the failure class
Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.
Related errors
- harness health evidence integrity verification failed
- incomplete harness health evidence integrity metadata
- missing harness health evidence integrity metadata
- candidate content address or canonical configuration is…
- harness health evidence exceeds integrity verification bound
AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16).
Data as JSON: /api/errors/ad62133ba536a657.
Report an issue: GitHub.
Appendix: source
Thrown at ecc2/src/session/store.rs:5635
if !event_consistent {
anyhow::bail!("harness health evidence is inconsistent with audit outcome");
}
if let Some(evaluation_id) = entry.evaluation_id {
let evaluation: (Option<String>, Option<String>, Option<bool>, Option<String>, bool) = self.conn.query_row(
"SELECT health_evidence_json, health_evidence_sha256, asserted_health, health_check_status, legacy_unverifiable FROM harness_evaluations WHERE id = ?1",
[evaluation_id],
|row| Ok((row.get(0)?, row.get(1)?, row.get(2)?, row.get(3)?, row.get(4)?)),
)?;
if evaluation
!= (
Some(json.clone()),
Some(digest.clone()),
Some(asserted),
Some(status.clone()),
false,
)
{
anyhow::bail!("audit health evidence does not match its evaluation");
}
}
Ok(())
}
#[cfg(test)]
fn connection_for_test(&self) -> &Connection {
&self.conn
}
}
#[cfg(test)]
mod tests {
use super::*;
use chrono::{Duration as ChronoDuration, Utc};
use std::fs;
struct TestDir {View on GitHub (pinned to 8321021c54)