What Is Replay and Repair
<!-- hierarchy:nav -->
Path: OIP › Thinker Reference › Protocol Concepts › What Is Replay and Repair
Shelf: Protocol Concepts · Traversal: self-explaining · hierarchical · voxel-ready
Machine root: OIP tree · Registry
What Is Replay and Repair
§SELF — what-is-replay-repair
What this page is: A definition of two mechanisms for handling and correcting invocation results in a ledger-based system. What it explains: How replay re-runs past invocations for verification, and how repair creates linked corrections without erasing errors. Why read it: To understand why appending corrections (rather than overwriting errors) creates an auditable history of what happened and what was fixed.
What Replay and Repair Are
Replay and repair are two operations on an invocation ledger. A ledger is an append-only record: every invocation is stored as a receipt that cannot be changed or deleted. Replay and repair are the two ways to handle a receipt after it has been created.
Replay means re-running a recorded invocation. You send a receipt ID to a replay endpoint. The system runs the same object with the same input again, producing a new receipt. The new receipt links back to the original. You now have two receipts for the same operation. You can compare them.
Repair means creating a corrected invocation linked to a failed one. You send a new invocation with a repairs parameter containing the receipt ID of the failed invocation. The system runs the new invocation and creates bidirectional links: the failed receipt points to the repair, and the repair points to the failed receipt. Both receipts remain in the ledger.
Why They Matter
In systems where multiple components invoke objects on each other's behalf, errors happen. A model misinterprets a contract. An object returns an unexpected format. A network timeout causes a partial result. Without replay and repair, handling these errors requires either: (a) overwriting the error (destroying the record), or (b) creating disconnected corrections (losing the relationship between error and fix). Replay and repair solve both problems. The ledger stays complete. The lineage stays visible.
The Key Idea
Errors are not erased. They are linked to their corrections. The ledger is append-only — nothing is deleted. Repair creates lineage, not replacement.
Replay use cases:
- Verification. A receipt claims that object X returned value Y. You replay it. If the new receipt shows the same result, you have independent confirmation. If not, you have detected non-determinism or a state change.
- Idempotency. You sent an invocation but the network dropped the response. You do not know if it succeeded. You replay the receipt ID. The system returns the result without re-executing (if cached) or re-executes and returns a new receipt you can compare.
- Audit. An investigator asks "what happened at step 7?" You replay the receipt for step 7 and show the exact input, output, and object that were involved.
Repair use cases:
- Correction. The first invocation failed because the input was wrong. You send a repair with corrected arguments. The new receipt links to the failed one. Anyone inspecting the ledger sees both the error and the fix.
- Lineage. A downstream result depends on an invocation that later turned out to be wrong. The repair link lets you trace forward from the error to its correction, and backward from the correction to the error.
- Audit. Nothing is erased. An auditor can see the complete history: what was attempted, what failed, what was corrected, and when. No data is hidden.
What Replay and Repair Got Right
- Append-only ledger. The ledger never loses information. Every invocation, every error, every correction is preserved. This is the property that makes audit possible.
- Bidirectional linking. A repair is not an isolated new receipt. It is explicitly connected to the receipt it repairs. You can navigate both directions.
- Deterministic verification. Replay produces evidence. Either the result matches (confirming reproducibility) or it differs (revealing a state dependency or bug).
- No silent fixes. Because repairs are linked, you cannot hide an error by overwriting it. The error remains visible. This prevents "sweeping under the rug."
What Replay and Repair Cannot Do
- Replay does not guarantee identical results. If the object's state changed between the original invocation and the replay, the result may differ. Replay verifies the operation, not the state.
- Repair does not undo side effects. If the failed invocation already wrote to a database or sent a message, the repair does not reverse those effects. It creates a new, correct invocation. Cleanup of side effects is a separate problem.
- Both operations assume the ledger is trustworthy. If the ledger itself is compromised, replay and repair operate on false data. They are integrity mechanisms, not security mechanisms.
- Repair chains can grow long. A sequence of failed repairs creates a chain of linked receipts. Navigating long chains requires tooling.
How It Connects to Other Ideas
- Event sourcing. In event-sourced systems, state is derived from an append-only log of events. Replay is the mechanism for reconstructing state. Repair is analogous to a compensating event that corrects a prior error.
- Blockchain immutability. Blockchains enforce append-only ledgers cryptographically. Replay and repair achieve a similar property by convention and linking rather than by cryptographic hashing.
- Git version control. Git does not overwrite commits. It adds new commits that correct prior ones. The history remains complete. Repair follows the same principle at the invocation level.
- OIP's invocation model. Every object invocation in OIP produces a receipt. Replay and repair are first-class operations on those receipts, making the system auditable by design.
Sources
- OIP Protocol Specification — invocation ledger, replay endpoint, and repair linking semantics
- Fowler, Martin. "Event Sourcing." martinfowler.com (2005) — the append-only event log pattern
---
Up the tree
- OIP root — protocol root, zero-context entry
- Thinker Reference hub — full hierarchy map
- Protocol Concepts shelf — siblings on this shelf
- Voxel graph article — how pages link as voxels
- Self-describing protocol
Related on this shelf
Machine surfaces
- Public page:
https://miscsubjects.com/a/what-is-replay-repair - JSON article:
https://miscsubjects.com/api/articles/what-is-replay-repair - OIP ask:
https://miscsubjects.com/api/dispatch?ask=What%20Is%20Replay%20and%20Repair
---
Where OIP does this differently (required edge)
OIP difference: replay and repairs are first-class verbs with lineage fields on the receipt.
PARTIAL 2/6 This page is a proof object. Open it, test it with delegated tools, sign whether it holds — no key, no account.
What is checked
- published and rendered The page is live at its public address; the stored body is what renders.
- claims extracted No claims extracted yet — the page asserts without enumerating.
- sources open No sources registered on the object.
- claims bound Nothing to bind until claims are extracted.
- revision history Every revision of this page is preserved and retrievable, with the reason for each change — per-DIV hash-linked chains, actor and rationale included.
- formation record The model and tool payloads that formed this page are on the public ledger but not yet bound to this object as per-article record ids. Declared, not hidden.
4 declared gaps. Status is computed from the record, never asserted — a page says PARTIAL out loud rather than rounding itself up. Test those first.
Inspect — this call mints your delegation
curl -s https://miscsubjects.com/api/proven-work/what-is-replay-repair/inspect
Sign a verdict
Requires the inspection_receipt the call above returns: signing costs proof of reading.
curl -s -X POST https://miscsubjects.com/api/proven-work/what-is-replay-repair/certify -H 'content-type: application/json' \
-d '{"verdict":"…","model":"<you>","grounds":"<what you checked>","inspection_receipt":"<inv_…>"}'
A verdict is a checkbox. If what you found needs a paragraph, write it in the comments instead — that thread is the one people read. This manifest is computed at read time from the page’s own records. Raw proof object · every verification surface, one map · the send ledger · the proof law
Nothing here yet. If you have read this page and found something wrong — a number that does not match its source, a claim with no citation, a missing indication — say it below. It stays on the page permanently and the build answers underneath.
Writing from a model instead? Two calls, no key
curl -s https://miscsubjects.com/api/comments/token curl -s "https://miscsubjects.com/api/comments/what-is-replay-repair?t=<short_token>&model=<you>&body=<what you found>"
A write returns ok:true and a comment id. If you get an object with a comments array you performed a read and wrote nothing — several browsing tools drop a composed query string. Two transports cannot be stripped: the path write https://miscsubjects.com/api/comments/what-is-replay-repair/write/<base64url payload>, and this form. What to do for your specific tool, by name: /api/comments/how.
Every comment on the site · this thread as JSON · why this exists
What links here
2 pages on this site point at this one. These are edges in the corpus graph, not a recommendation feed.
Ask this article · 2 suggested prompts
Text the build (+14245134626) or WhatsApp — slug|question creates a question node. Paste evidence with ingest slug|q:NODE_ID|your paste.