affaan-m/ECC · error

harness health evidence exceeds integrity verification bound

Error message

harness health evidence exceeds integrity verification bound

What it means

The verifier enforces a hard size bound of 8192 bytes on the health evidence JSON before parsing it. If the serialized HealthEvidenceSnapshot exceeds this limit, the store rejects it outright to keep audit evidence compact and parsing bounded.

Solutions

  1. Trim the snapshot before attaching it: keep only the fields required for integrity verification (candidate_id, asserted_healthy, digest inputs)
  2. Move bulky diagnostics to a separate store (log file or blob table) and reference them by ID from the snapshot
  3. Raise the 8192 bound deliberately if your deployment legitimately needs larger evidence, understanding it weakens the audit compactness guarantee

Example fix

// before
let snapshot = HealthEvidenceSnapshot { metrics: full_diagnostics, .. };
// after
let snapshot = HealthEvidenceSnapshot { metrics: full_diagnostics.summarize(1024), .. };
Defensive patterns

Strategy: validation

Validate before calling

// Rust: bound-check the serialized snapshot before attaching it
let json = snapshot.canonical_json()?;
if json.len() > 8192 {
    return Err(anyhow::anyhow!("snapshot too large; summarize before attaching"));
}

Prevention

When it happens

Trigger: Storing a HealthEvidenceSnapshot whose canonical JSON serialization is longer than 8192 characters — e.g. a snapshot with very long candidate metadata, verbose diagnostics, or embedded log excerpts.

Common situations: Health checks that include large diagnostic payloads or environment dumps in the snapshot; aggregated evidence accumulated across many checks before being attached to one audit event.

Understand the failure class

Background: payload too large / request exceeds maximum size: why libraries cap bytes and how to fix oversize payloads — this error's family across 50 libraries.

Related errors


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/24786abceb69304a. Report an issue: GitHub.

Appendix: source

Thrown at ecc2/src/session/store.rs:5599

            entry.asserted_health,
            &entry.health_check_status,
        );
        if matches!(fields, (None, None, None, None)) {
            if entry.legacy_unverifiable
                || matches!(
                    entry.event_type.as_str(),
                    "initial_activation" | "promotion_rejected"
                )
            {
                return Ok(());
            }
            anyhow::bail!("missing harness health evidence integrity metadata");
        }
        let (Some(json), Some(digest), Some(asserted), Some(status)) = fields else {
            anyhow::bail!("incomplete harness health evidence integrity metadata");
        };
        if json.len() > 8192 {
            anyhow::bail!("harness health evidence exceeds integrity verification bound");
        }
        let snapshot: HealthEvidenceSnapshot = serde_json::from_str(json)?;
        let snapshot_candidate_id =
            Self::resolve_harness_candidate_id(&self.conn, &snapshot.candidate_id)?;
        if snapshot.canonical_json()? != *json
            || snapshot.digest()? != *digest
            || snapshot.asserted_healthy != asserted
            || snapshot_candidate_id != entry.candidate_id
        {
            anyhow::bail!("harness health evidence integrity verification failed");
        }
        let event_consistent = match entry.event_type.as_str() {
            "promoted" => status == "healthy" && asserted,
            "promotion_rolled_back" => status == "unhealthy" && !asserted,
            "health_check_error_rolled_back" => status == "error",
            _ => false,
        };
        if !event_consistent {

View on GitHub (pinned to 8321021c54)