affaan-m/ECC · error

harness health evidence integrity verification failed

Error message

harness health evidence integrity verification failed

What it means

After parsing the snapshot, the verifier recomputes the canonical JSON and SHA-256 digest and cross-checks them against the stored values, the asserted-health flag, and the resolved candidate ID. Any mismatch means the evidence was tampered with, corrupted, or generated by a non-canonical serializer, so it bails here.

Solutions

  1. Recompute the digest from the canonical JSON and update both together, never one alone
  2. Verify the snapshot's candidate_id matches the audit entry's candidate_id before attaching
  3. Check for serializer version drift — regenerate the snapshot with the current HealthEvidenceSnapshot canonical form if formats changed
  4. Treat the row as legacy_unverifiable if it predates integrity enforcement

Example fix

// before
row.health_evidence_json = edited_json; // digest not updated
// after
let snapshot = parse(edited_json);
row.health_evidence_json = snapshot.canonical_json()?;
row.health_evidence_sha256 = snapshot.digest()?;
Defensive patterns

Strategy: validation

Validate before calling

// Verify digest/candidate pairing before persisting either record
let digest = snapshot.digest()?;
assert_eq!(snapshot.canonical_json()?, stored_json);
assert_eq!(snapshot.candidate_id, audit_entry.candidate_id, "evidence must belong to the audited candidate");

Prevention

When it happens

Trigger: The stored evidence JSON does not equal snapshot.canonical_json(), or snapshot.digest() != stored sha256, or asserted_healthy disagrees with the stored flag, or the snapshot's candidate_id resolves to a different candidate than the audit entry's candidate_id.

Common situations: Manually editing evidence JSON in the database without recomputing its digest; a serializer version change that produces different canonical JSON for the same logical snapshot; attaching evidence captured for one candidate to another candidate's audit event.

Understand the failure class

Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.

Related errors


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/8d84a3067a3c20eb. Report an issue: GitHub.

Appendix: source

Thrown at ecc2/src/session/store.rs:5609

                return Ok(());
            }
            anyhow::bail!("missing harness health evidence integrity metadata");
        }
        let (Some(json), Some(digest), Some(asserted), Some(status)) = fields else {
            anyhow::bail!("incomplete harness health evidence integrity metadata");
        };
        if json.len() > 8192 {
            anyhow::bail!("harness health evidence exceeds integrity verification bound");
        }
        let snapshot: HealthEvidenceSnapshot = serde_json::from_str(json)?;
        let snapshot_candidate_id =
            Self::resolve_harness_candidate_id(&self.conn, &snapshot.candidate_id)?;
        if snapshot.canonical_json()? != *json
            || snapshot.digest()? != *digest
            || snapshot.asserted_healthy != asserted
            || snapshot_candidate_id != entry.candidate_id
        {
            anyhow::bail!("harness health evidence integrity verification failed");
        }
        let event_consistent = match entry.event_type.as_str() {
            "promoted" => status == "healthy" && asserted,
            "promotion_rolled_back" => status == "unhealthy" && !asserted,
            "health_check_error_rolled_back" => status == "error",
            _ => false,
        };
        if !event_consistent {
            anyhow::bail!("harness health evidence is inconsistent with audit outcome");
        }
        if let Some(evaluation_id) = entry.evaluation_id {
            let evaluation: (Option<String>, Option<String>, Option<bool>, Option<String>, bool) = self.conn.query_row(
                "SELECT health_evidence_json, health_evidence_sha256, asserted_health, health_check_status, legacy_unverifiable FROM harness_evaluations WHERE id = ?1",
                [evaluation_id],
                |row| Ok((row.get(0)?, row.get(1)?, row.get(2)?, row.get(3)?, row.get(4)?)),
            )?;
            if evaluation
                != (

View on GitHub (pinned to 8321021c54)