{"record":{"id":"cfd2bd7e383b5c4a","repo":"affaan-m/ECC","slug":"missing-harness-health-evidence-integrity-metadata","errorCode":null,"errorMessage":"missing harness health evidence integrity metadata","messagePattern":"missing harness health evidence integrity metadata","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"ecc2/src/session/store.rs","lineNumber":5593,"sourceCode":"    }\n\n    fn verify_harness_audit_entry(&self, entry: &HarnessAuditEntry) -> Result<()> {\n        let fields = (\n            &entry.health_evidence_json,\n            &entry.health_evidence_sha256,\n            entry.asserted_health,\n            &entry.health_check_status,\n        );\n        if matches!(fields, (None, None, None, None)) {\n            if entry.legacy_unverifiable\n                || matches!(\n                    entry.event_type.as_str(),\n                    \"initial_activation\" | \"promotion_rejected\"\n                )\n            {\n                return Ok(());\n            }\n            anyhow::bail!(\"missing harness health evidence integrity metadata\");\n        }\n        let (Some(json), Some(digest), Some(asserted), Some(status)) = fields else {\n            anyhow::bail!(\"incomplete harness health evidence integrity metadata\");\n        };\n        if json.len() > 8192 {\n            anyhow::bail!(\"harness health evidence exceeds integrity verification bound\");\n        }\n        let snapshot: HealthEvidenceSnapshot = serde_json::from_str(json)?;\n        let snapshot_candidate_id =\n            Self::resolve_harness_candidate_id(&self.conn, &snapshot.candidate_id)?;\n        if snapshot.canonical_json()? != *json\n            || snapshot.digest()? != *digest\n            || snapshot.asserted_healthy != asserted\n            || snapshot_candidate_id != entry.candidate_id\n        {\n            anyhow::bail!(\"harness health evidence integrity verification failed\");\n        }\n        let event_consistent = match entry.event_type.as_str() {","sourceCodeStart":5575,"sourceCodeEnd":5611,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/ecc2/src/session/store.rs#L5575-L5611","documentation":"This error is raised in the harness health evidence verifier in the session store (ecc2/src/session/store.rs). When processing an audit entry whose event type is not an early-return case (e.g. not 'initial_activation' or 'promotion_rejected'), the store requires integrity metadata (JSON payload, digest, asserted flag, status). If the metadata fields are entirely absent, it bails with this message to prevent persisting unverifiable health evidence.","triggerScenarios":"Inserting or validating an audit event (e.g. 'promoted', 'promotion_rolled_back', 'health_check_error_rolled_back') whose health evidence metadata fields (health_evidence_json, health_evidence_sha256, asserted_health, health_check_status) are all None/missing.","commonSituations":"Legacy audit rows written by older versions of the harness that did not attach health evidence; manual DB manipulation; a promotion flow that forgot to capture and attach the health snapshot before writing the audit event.","solutions":["Regenerate the audit event through the harness so the health evidence snapshot and its digest are captured and attached","Migrate legacy rows: recompute or backfill health_evidence_json, health_evidence_sha256, asserted_health and health_check_status, or mark the row legacy_unverifiable","Check the code path that creates the audit entry to ensure the health evidence snapshot is recorded before the event is written"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Rust: verify evidence metadata is present before writing the audit event\nfn has_health_evidence(fields: &AuditFields) -> bool {\n    fields.health_evidence_json.is_some()\n        && fields.health_evidence_sha256.is_some()\n        && fields.asserted_health.is_some()\n        && fields.health_check_status.is_some()\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always attach a complete health evidence snapshot when writing promotion/rollback audit events","Treat legacy rows without evidence as legacy_unverifiable instead of attempting verification","Add an integration test that every audit event type carries complete evidence metadata"],"tags":["audit","integrity","rust","database"],"backgroundTag":"missing-required-argument","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}