{"record":{"id":"24786abceb69304a","repo":"affaan-m/ECC","slug":"harness-health-evidence-exceeds-integrity-verifica","errorCode":null,"errorMessage":"harness health evidence exceeds integrity verification bound","messagePattern":"harness health evidence exceeds integrity verification bound","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"ecc2/src/session/store.rs","lineNumber":5599,"sourceCode":"            entry.asserted_health,\n            &entry.health_check_status,\n        );\n        if matches!(fields, (None, None, None, None)) {\n            if entry.legacy_unverifiable\n                || matches!(\n                    entry.event_type.as_str(),\n                    \"initial_activation\" | \"promotion_rejected\"\n                )\n            {\n                return Ok(());\n            }\n            anyhow::bail!(\"missing harness health evidence integrity metadata\");\n        }\n        let (Some(json), Some(digest), Some(asserted), Some(status)) = fields else {\n            anyhow::bail!(\"incomplete harness health evidence integrity metadata\");\n        };\n        if json.len() > 8192 {\n            anyhow::bail!(\"harness health evidence exceeds integrity verification bound\");\n        }\n        let snapshot: HealthEvidenceSnapshot = serde_json::from_str(json)?;\n        let snapshot_candidate_id =\n            Self::resolve_harness_candidate_id(&self.conn, &snapshot.candidate_id)?;\n        if snapshot.canonical_json()? != *json\n            || snapshot.digest()? != *digest\n            || snapshot.asserted_healthy != asserted\n            || snapshot_candidate_id != entry.candidate_id\n        {\n            anyhow::bail!(\"harness health evidence integrity verification failed\");\n        }\n        let event_consistent = match entry.event_type.as_str() {\n            \"promoted\" => status == \"healthy\" && asserted,\n            \"promotion_rolled_back\" => status == \"unhealthy\" && !asserted,\n            \"health_check_error_rolled_back\" => status == \"error\",\n            _ => false,\n        };\n        if !event_consistent {","sourceCodeStart":5581,"sourceCodeEnd":5617,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/ecc2/src/session/store.rs#L5581-L5617","documentation":"The verifier enforces a hard size bound of 8192 bytes on the health evidence JSON before parsing it. If the serialized HealthEvidenceSnapshot exceeds this limit, the store rejects it outright to keep audit evidence compact and parsing bounded.","triggerScenarios":"Storing a HealthEvidenceSnapshot whose canonical JSON serialization is longer than 8192 characters — e.g. a snapshot with very long candidate metadata, verbose diagnostics, or embedded log excerpts.","commonSituations":"Health checks that include large diagnostic payloads or environment dumps in the snapshot; aggregated evidence accumulated across many checks before being attached to one audit event.","solutions":["Trim the snapshot before attaching it: keep only the fields required for integrity verification (candidate_id, asserted_healthy, digest inputs)","Move bulky diagnostics to a separate store (log file or blob table) and reference them by ID from the snapshot","Raise the 8192 bound deliberately if your deployment legitimately needs larger evidence, understanding it weakens the audit compactness guarantee"],"exampleFix":"// before\nlet snapshot = HealthEvidenceSnapshot { metrics: full_diagnostics, .. };\n// after\nlet snapshot = HealthEvidenceSnapshot { metrics: full_diagnostics.summarize(1024), .. };","handlingStrategy":"validation","validationCode":"// Rust: bound-check the serialized snapshot before attaching it\nlet json = snapshot.canonical_json()?;\nif json.len() > 8192 {\n    return Err(anyhow::anyhow!(\"snapshot too large; summarize before attaching\"));\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Keep HealthEvidenceSnapshot small: reference bulky diagnostics by ID instead of embedding them","Summarize or truncate diagnostic payloads at snapshot construction time","Add a unit test asserting serialized snapshots stay under the 8192 bound"],"tags":["audit","payload-size","rust","validation"],"backgroundTag":"payload-too-large","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}