{"record":{"id":"8d84a3067a3c20eb","repo":"affaan-m/ECC","slug":"harness-health-evidence-integrity-verification-fai","errorCode":null,"errorMessage":"harness health evidence integrity verification failed","messagePattern":"harness health evidence integrity verification failed","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"ecc2/src/session/store.rs","lineNumber":5609,"sourceCode":"                return Ok(());\n            }\n            anyhow::bail!(\"missing harness health evidence integrity metadata\");\n        }\n        let (Some(json), Some(digest), Some(asserted), Some(status)) = fields else {\n            anyhow::bail!(\"incomplete harness health evidence integrity metadata\");\n        };\n        if json.len() > 8192 {\n            anyhow::bail!(\"harness health evidence exceeds integrity verification bound\");\n        }\n        let snapshot: HealthEvidenceSnapshot = serde_json::from_str(json)?;\n        let snapshot_candidate_id =\n            Self::resolve_harness_candidate_id(&self.conn, &snapshot.candidate_id)?;\n        if snapshot.canonical_json()? != *json\n            || snapshot.digest()? != *digest\n            || snapshot.asserted_healthy != asserted\n            || snapshot_candidate_id != entry.candidate_id\n        {\n            anyhow::bail!(\"harness health evidence integrity verification failed\");\n        }\n        let event_consistent = match entry.event_type.as_str() {\n            \"promoted\" => status == \"healthy\" && asserted,\n            \"promotion_rolled_back\" => status == \"unhealthy\" && !asserted,\n            \"health_check_error_rolled_back\" => status == \"error\",\n            _ => false,\n        };\n        if !event_consistent {\n            anyhow::bail!(\"harness health evidence is inconsistent with audit outcome\");\n        }\n        if let Some(evaluation_id) = entry.evaluation_id {\n            let evaluation: (Option<String>, Option<String>, Option<bool>, Option<String>, bool) = self.conn.query_row(\n                \"SELECT health_evidence_json, health_evidence_sha256, asserted_health, health_check_status, legacy_unverifiable FROM harness_evaluations WHERE id = ?1\",\n                [evaluation_id],\n                |row| Ok((row.get(0)?, row.get(1)?, row.get(2)?, row.get(3)?, row.get(4)?)),\n            )?;\n            if evaluation\n                != (","sourceCodeStart":5591,"sourceCodeEnd":5627,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/ecc2/src/session/store.rs#L5591-L5627","documentation":"After parsing the snapshot, the verifier recomputes the canonical JSON and SHA-256 digest and cross-checks them against the stored values, the asserted-health flag, and the resolved candidate ID. Any mismatch means the evidence was tampered with, corrupted, or generated by a non-canonical serializer, so it bails here.","triggerScenarios":"The stored evidence JSON does not equal snapshot.canonical_json(), or snapshot.digest() != stored sha256, or asserted_healthy disagrees with the stored flag, or the snapshot's candidate_id resolves to a different candidate than the audit entry's candidate_id.","commonSituations":"Manually editing evidence JSON in the database without recomputing its digest; a serializer version change that produces different canonical JSON for the same logical snapshot; attaching evidence captured for one candidate to another candidate's audit event.","solutions":["Recompute the digest from the canonical JSON and update both together, never one alone","Verify the snapshot's candidate_id matches the audit entry's candidate_id before attaching","Check for serializer version drift — regenerate the snapshot with the current HealthEvidenceSnapshot canonical form if formats changed","Treat the row as legacy_unverifiable if it predates integrity enforcement"],"exampleFix":"// before\nrow.health_evidence_json = edited_json; // digest not updated\n// after\nlet snapshot = parse(edited_json);\nrow.health_evidence_json = snapshot.canonical_json()?;\nrow.health_evidence_sha256 = snapshot.digest()?;","handlingStrategy":"validation","validationCode":"// Verify digest/candidate pairing before persisting either record\nlet digest = snapshot.digest()?;\nassert_eq!(snapshot.canonical_json()?, stored_json);\nassert_eq!(snapshot.candidate_id, audit_entry.candidate_id, \"evidence must belong to the audited candidate\");","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Never hand-edit evidence JSON without recomputing its digest","Always regenerate canonical JSON and digest together from the same snapshot","Validate candidate_id match at the call site before attaching evidence to an audit event"],"tags":["audit","integrity","checksum","rust"],"backgroundTag":"checksum-mismatch","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}