{"record":{"id":"b3ea3b57a6c1f5a9","repo":"affaan-m/ECC","slug":"harness-health-evidence-is-inconsistent-with-audit","errorCode":null,"errorMessage":"harness health evidence is inconsistent with audit outcome","messagePattern":"harness health evidence is inconsistent with audit outcome","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"ecc2/src/session/store.rs","lineNumber":5618,"sourceCode":"        }\n        let snapshot: HealthEvidenceSnapshot = serde_json::from_str(json)?;\n        let snapshot_candidate_id =\n            Self::resolve_harness_candidate_id(&self.conn, &snapshot.candidate_id)?;\n        if snapshot.canonical_json()? != *json\n            || snapshot.digest()? != *digest\n            || snapshot.asserted_healthy != asserted\n            || snapshot_candidate_id != entry.candidate_id\n        {\n            anyhow::bail!(\"harness health evidence integrity verification failed\");\n        }\n        let event_consistent = match entry.event_type.as_str() {\n            \"promoted\" => status == \"healthy\" && asserted,\n            \"promotion_rolled_back\" => status == \"unhealthy\" && !asserted,\n            \"health_check_error_rolled_back\" => status == \"error\",\n            _ => false,\n        };\n        if !event_consistent {\n            anyhow::bail!(\"harness health evidence is inconsistent with audit outcome\");\n        }\n        if let Some(evaluation_id) = entry.evaluation_id {\n            let evaluation: (Option<String>, Option<String>, Option<bool>, Option<String>, bool) = self.conn.query_row(\n                \"SELECT health_evidence_json, health_evidence_sha256, asserted_health, health_check_status, legacy_unverifiable FROM harness_evaluations WHERE id = ?1\",\n                [evaluation_id],\n                |row| Ok((row.get(0)?, row.get(1)?, row.get(2)?, row.get(3)?, row.get(4)?)),\n            )?;\n            if evaluation\n                != (\n                    Some(json.clone()),\n                    Some(digest.clone()),\n                    Some(asserted),\n                    Some(status.clone()),\n                    false,\n                )\n            {\n                anyhow::bail!(\"audit health evidence does not match its evaluation\");\n            }","sourceCodeStart":5600,"sourceCodeEnd":5636,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/ecc2/src/session/store.rs#L5600-L5636","documentation":"Beyond cryptographic integrity, the verifier enforces semantic consistency: the event type must agree with the evidence. 'promoted' requires status 'healthy' with asserted_healthy=true, 'promotion_rolled_back' requires 'unhealthy' with asserted=false, and 'health_check_error_rolled_back' requires status 'error'. Anything else fails this check.","triggerScenarios":"Recording a 'promoted' event while the health evidence shows status 'unhealthy' or asserted=false; a rollback event backed by evidence asserting healthy; an unknown event_type falling into the `_ => false` arm.","commonSituations":"A promotion pipeline that writes the audit event before the health check result is known; code that reuses a healthy snapshot when logging a rollback; a typo'd or new event_type string not covered by the match.","solutions":["Capture a fresh health snapshot at the moment of the event and attach the one matching the outcome","Make the event-writing code derive event_type and evidence from the same health-check result so they cannot diverge","If you added a new event type, extend the match in the verifier to define its required (status, asserted) combination"],"exampleFix":"// before\naudit_event(\"promoted\", evidence_from_last_check); // may carry stale/unhealthy evidence\n// after\nlet check = run_health_check();\naudit_event(if check.healthy { \"promoted\" } else { \"promotion_rolled_back\" }, check.into_snapshot());","handlingStrategy":"validation","validationCode":"// Rust: enforce outcome/status coherence before writing the event\nfn event_matches_outcome(event_type: &str, status: &str, asserted: bool) -> bool {\n    match event_type {\n        \"promoted\" => status == \"healthy\" && asserted,\n        \"promotion_rolled_back\" => status == \"unhealthy\" && !asserted,\n        \"health_check_error_rolled_back\" => status == \"error\",\n        _ => false,\n    }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Derive event_type and evidence from a single health-check result object","Capture evidence at the exact moment of the outcome, not from a prior check","Extend the verifier's match table whenever a new event type is introduced"],"tags":["audit","validation","rust","state-machine"],"backgroundTag":"invalid-state-transition","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}