affaan-m/ECC · error

missing harness health evidence integrity metadata

Error message

missing harness health evidence integrity metadata

What it means

This error is raised in the harness health evidence verifier in the session store (ecc2/src/session/store.rs). When processing an audit entry whose event type is not an early-return case (e.g. not 'initial_activation' or 'promotion_rejected'), the store requires integrity metadata (JSON payload, digest, asserted flag, status). If the metadata fields are entirely absent, it bails with this message to prevent persisting unverifiable health evidence.

Solutions

  1. Regenerate the audit event through the harness so the health evidence snapshot and its digest are captured and attached
  2. Migrate legacy rows: recompute or backfill health_evidence_json, health_evidence_sha256, asserted_health and health_check_status, or mark the row legacy_unverifiable
  3. Check the code path that creates the audit entry to ensure the health evidence snapshot is recorded before the event is written
Defensive patterns

Strategy: validation

Validate before calling

// Rust: verify evidence metadata is present before writing the audit event
fn has_health_evidence(fields: &AuditFields) -> bool {
    fields.health_evidence_json.is_some()
        && fields.health_evidence_sha256.is_some()
        && fields.asserted_health.is_some()
        && fields.health_check_status.is_some()
}

Prevention

When it happens

Trigger: Inserting or validating an audit event (e.g. 'promoted', 'promotion_rolled_back', 'health_check_error_rolled_back') whose health evidence metadata fields (health_evidence_json, health_evidence_sha256, asserted_health, health_check_status) are all None/missing.

Common situations: Legacy audit rows written by older versions of the harness that did not attach health evidence; manual DB manipulation; a promotion flow that forgot to capture and attach the health snapshot before writing the audit event.

Understand the failure class

Background: "missing required argument" and "the following required arguments were not provided": what required-argument errors mean and how to fix them — this error's family across 20 libraries.

Related errors


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/cfd2bd7e383b5c4a. Report an issue: GitHub.

Appendix: source

Thrown at ecc2/src/session/store.rs:5593

    }

    fn verify_harness_audit_entry(&self, entry: &HarnessAuditEntry) -> Result<()> {
        let fields = (
            &entry.health_evidence_json,
            &entry.health_evidence_sha256,
            entry.asserted_health,
            &entry.health_check_status,
        );
        if matches!(fields, (None, None, None, None)) {
            if entry.legacy_unverifiable
                || matches!(
                    entry.event_type.as_str(),
                    "initial_activation" | "promotion_rejected"
                )
            {
                return Ok(());
            }
            anyhow::bail!("missing harness health evidence integrity metadata");
        }
        let (Some(json), Some(digest), Some(asserted), Some(status)) = fields else {
            anyhow::bail!("incomplete harness health evidence integrity metadata");
        };
        if json.len() > 8192 {
            anyhow::bail!("harness health evidence exceeds integrity verification bound");
        }
        let snapshot: HealthEvidenceSnapshot = serde_json::from_str(json)?;
        let snapshot_candidate_id =
            Self::resolve_harness_candidate_id(&self.conn, &snapshot.candidate_id)?;
        if snapshot.canonical_json()? != *json
            || snapshot.digest()? != *digest
            || snapshot.asserted_healthy != asserted
            || snapshot_candidate_id != entry.candidate_id
        {
            anyhow::bail!("harness health evidence integrity verification failed");
        }
        let event_consistent = match entry.event_type.as_str() {

View on GitHub (pinned to 8321021c54)