Harness Span-Lineage Graph-Integrity Meta-Lens
“A forged lineage cannot launder a clean AgentSmack grade.”
Every harness content grader that binds a policy gate, an approval, an llm-call, or a prompt assembly to a downstream privileged action.executed does so via the parentId causal lineage — and then trusts it. Nothing grades whether that graph is structurally sound. So a forged DAG launders a clean grade the same way a back-dated gate launders the clock: a cycle in parentId (A→B→A makes causal-ancestry ambiguous and forges a lineage); two spans sharing one id (so a binding resolves to the wrong node — the foundation of every proof is non-unique); a privileged effect that is causally orphaned (no parentId, no causal ancestor — it appears from nowhere, so no gate or assembly can be bound to authorize it); a subtree spliced from a foreign root; or an ambiguous multi-root run. This lab is a pure, deterministic meta-lens over the SAME Phase-4 span list: any forgery-class finding forces the verdict to forged (score clamped into the failing band, non-launderable); a broken or spliced chain is suspect; a single-span list is insufficient_signal, never a fabricated coherent. Grading is by the (id, parentId, name, privilege) structure, not the array index — re-ordering the spans cannot change the verdict, and the ancestor walk is bounded so a cycle terminates rather than hangs. The report carries only span ids + closed enums + span indices + scalar counts (no raw span / attribute / secret bytes). Load a sample to watch the verdict swing with no live infra.
Grading the SAME spans for content failures, wall-clock physics, or telemetry sufficiency? Run the Harness Telemetry Check, the Span-Timeline Temporal-Integrity lab, and the Instrumentation-Coverage auditor. A graph can be clock-coherent and fully instrumented yet structurally forged.