Skip to content

Rule-Miss and Evidence Diagnosis

Use this playbook when a session observed traffic but the expected mutation, acceptance or oracle result is missing. Every miss reports a stable code -- start there, not at the target.

Triage order

  1. Reach: Did the session start, and is the sender using AIT's listener?
  2. Protocol: Did initialize/session/card negotiation succeed?
  3. Decode eligibility: Was the transport and decoder eligible for the rule?
  4. Predicates: Which path/operator/expected/actual comparison missed?
  5. Mutation: Did intended and actual mutation paths agree?
  6. Encode/delivery: Was the changed message re-encoded and correlated?
  7. Acceptance: Did the target-facing matcher pass?
  8. Oracle: Did the independent effect occur?

Obtain a record cursor from a lightweight page, then load detail:

ait traffic tail --run RUN_ID --limit 50 --json
ait traffic inspect --run RUN_ID --cursor RECORD_CURSOR --related-limit 20 --json

Reading transcript 2.1

Each rule evaluation can include transport and decoder eligibility, rule ID/digest, predicate path/operator/expected value, bounded actual preview and digest, outcome, stable miss code, intended/actual paths and transform/encode failures.

Actual previews are limited to 256 characters and at most 128 predicate evaluations are recorded per traffic record. They are marked as unredacted source evidence. Use the cockpit redaction preview before export.

Common diagnoses

Symptom Meaning
transport_ineligible Rule is not intended for this transport/direction.
decoder_ineligible Message was not decoded into the required structure.
predicate/path miss Payload shape or rule path differs from expectation.
transform failure Predicate matched but the requested mutation could not be applied.
encode failure Mutated structure could not be returned to the wire format.
correlation loss Delivery occurred but response/task linkage was lost.
no oracle observation Transport worked but impact was not demonstrated.

Use the correlated-hop navigator to compare request/response and delegated records. Compare attack and control structures before changing the rule; a control that takes a different route is not a useful negative control.