affaan-m/ECC · error
harness health evidence exceeds integrity verification bound
Error message
harness health evidence exceeds integrity verification bound
What it means
The verifier enforces a hard size bound of 8192 bytes on the health evidence JSON before parsing it. If the serialized HealthEvidenceSnapshot exceeds this limit, the store rejects it outright to keep audit evidence compact and parsing bounded.
Solutions
- Trim the snapshot before attaching it: keep only the fields required for integrity verification (candidate_id, asserted_healthy, digest inputs)
- Move bulky diagnostics to a separate store (log file or blob table) and reference them by ID from the snapshot
- Raise the 8192 bound deliberately if your deployment legitimately needs larger evidence, understanding it weakens the audit compactness guarantee
Example fix
// before
let snapshot = HealthEvidenceSnapshot { metrics: full_diagnostics, .. };
// after
let snapshot = HealthEvidenceSnapshot { metrics: full_diagnostics.summarize(1024), .. }; Defensive patterns
Strategy: validation
Validate before calling
// Rust: bound-check the serialized snapshot before attaching it
let json = snapshot.canonical_json()?;
if json.len() > 8192 {
return Err(anyhow::anyhow!("snapshot too large; summarize before attaching"));
} Prevention
- Keep HealthEvidenceSnapshot small: reference bulky diagnostics by ID instead of embedding them
- Summarize or truncate diagnostic payloads at snapshot construction time
- Add a unit test asserting serialized snapshots stay under the 8192 bound
When it happens
Trigger: Storing a HealthEvidenceSnapshot whose canonical JSON serialization is longer than 8192 characters — e.g. a snapshot with very long candidate metadata, verbose diagnostics, or embedded log excerpts.
Common situations: Health checks that include large diagnostic payloads or environment dumps in the snapshot; aggregated evidence accumulated across many checks before being attached to one audit event.
Understand the failure class
Background: payload too large / request exceeds maximum size: why libraries cap bytes and how to fix oversize payloads — this error's family across 50 libraries.
Related errors
- harness health evidence is inconsistent with audit outcome
- audit health evidence does not match its evaluation
- candidate configuration exceeds 1 MiB
- exactly one candidate-keyed health assertion is required
- harness health evidence integrity verification failed
AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16).
Data as JSON: /api/errors/24786abceb69304a.
Report an issue: GitHub.
Appendix: source
Thrown at ecc2/src/session/store.rs:5599
entry.asserted_health,
&entry.health_check_status,
);
if matches!(fields, (None, None, None, None)) {
if entry.legacy_unverifiable
|| matches!(
entry.event_type.as_str(),
"initial_activation" | "promotion_rejected"
)
{
return Ok(());
}
anyhow::bail!("missing harness health evidence integrity metadata");
}
let (Some(json), Some(digest), Some(asserted), Some(status)) = fields else {
anyhow::bail!("incomplete harness health evidence integrity metadata");
};
if json.len() > 8192 {
anyhow::bail!("harness health evidence exceeds integrity verification bound");
}
let snapshot: HealthEvidenceSnapshot = serde_json::from_str(json)?;
let snapshot_candidate_id =
Self::resolve_harness_candidate_id(&self.conn, &snapshot.candidate_id)?;
if snapshot.canonical_json()? != *json
|| snapshot.digest()? != *digest
|| snapshot.asserted_healthy != asserted
|| snapshot_candidate_id != entry.candidate_id
{
anyhow::bail!("harness health evidence integrity verification failed");
}
let event_consistent = match entry.event_type.as_str() {
"promoted" => status == "healthy" && asserted,
"promotion_rolled_back" => status == "unhealthy" && !asserted,
"health_check_error_rolled_back" => status == "error",
_ => false,
};
if !event_consistent {View on GitHub (pinned to 8321021c54)