Skip to content
Dossier · Engineering discipline

The replay domain

Independent reconstruction as a sealed family - a boundary that reconstructs nothing, then an oracle, an engine, a tribunal and a read-only door

Updated 2026-09-0715 min readEdition preview-01Internal records, not an external audit

01Update log

Update log

  • 7 September 2026 - First edition. Drawn from the acceptance records of the reconstruction family on the sealed development line, the era and power map, the architecture programme's chapter on the independent reconstruction service, and the Foundations edition published on this portal. Structural facts are reported; the family's internal identifiers appear only as a reference line.

Short answer

In most systems, replaying history is a utility: read the log, rebuild the state, trust the result. FxChain treats it as a domain - a power that had to be earned in bounded steps, with the same discipline as any other. The persistence era explicitly denies "reconstruction from the medium", so before the line could reconstruct anything it had to say who may speak about reconstruction at all.

The family that answered took twelve crossings and closed on the sealed line on 2 August 2026. It began with a boundary type that cannot be constructed in safe Rust - a crossing that "named a boundary that possessed no power" - and a taxonomy that names semantic failures but "detects none". It then defined the grammar of a history unit, the continuity of segments, a checkpoint accelerator, the canonical history material and a reference state transition. On that base it earned two independent implementations: a single-unit oracle and a bounded sequence engine, each rebuilt from written byte layouts and forbidden from linking the reference or each other. A tribunal places them side by side and reports agreement, disagreement and asymmetric refusal without deciding which side is right. Finally a read-only door makes them answerable to a node-side caller without granting the node anything it did not already have.

What the family does not claim is stated in its own records: not certification, not final authority, not consensus, not a canonicality decision, not formal verification, not an external validation. It installs no state, persists nothing, selects no head and reaches no network. What it establishes is narrower and more useful: that a bounded preserved history can be rebuilt through separate paths whose disagreement is measured rather than assumed away.

What is established, what is in development, what is not claimed

Claim Status Basis Limit
A reconstruction authority boundary that reconstructs nothing and cannot be instantiated in safe Rust Proven today Family opening record Representation only; the operational successor type is deliberately unnamed
A named taxonomy of semantic reconstruction failures that detects none of them Proven today Taxonomy record Names, not observation: a taxonomy that observed would own the evidence it classifies
A history-unit grammar, segment continuity, a checkpoint accelerator, canonical history material and a reference state transition Proven today Family records Bounded, local, test-reachable
A second implementation of the reference derivations, built from written layouts, whose independence is a dependency-closure fact Proven today Oracle record Agreement removes single-implementation defects, not a shared mistaken premise
A bounded sequence engine that threads state unit to unit, a sibling of the oracle that does not link it, with every dimension bounded at compile time Proven today Engine record Bounded by construction; not a production engine
A differential tribunal that exposes agreement, disagreement and asymmetric refusal and decides nothing Proven today Tribunal record No third implementation; observations, not verdicts
Reachability of every comparison surface measured from an executed hostile corpus, in two disjoint and total tables Proven today Tribunal record Exactly one surface is reachable end to end
A read-only node integration in which mutation is unrepresentable rather than refused Proven today Node-integration record Loopback-only local control; no socket, address, listener or frame
Closure of the family on an honest witness, with what it does not establish written down Proven today Closure record See the sealed-history dossier
The same result reproduced publicly by an outsider Later gate Foundations ledger Not offered today
An offline verifier for capsules, receipts and portable denials delivered first Planned Architecture programme Design; nothing downloadable
A competitive verifier or oracle market Research Architecture programme "Not an active protocol dependency"
Certification, finality, consensus, a canonicality decision, formal verification, external validation Not claimed Tribunal and closure records None

Why replay is a domain, not a feature

The persistence era admitted exactly one power - one preserved artifact, verified against its frozen anchor - and listed among the powers it still denies "reconstruction from the medium" and "canonical truth from storage". Reconstruction therefore could not be a helper function added to the preserved artifact. It had to be a family of its own, opened by a crossing that granted no power at all.

That opening crossing introduced a single public type, the family's authority reference, as an uninhabited type: no constructor, no default, no clone, no decoder, no constant instance and no test escape hatch can produce a value of it, "now or by any future act that does not introduce a fresh successor type". The record is explicit that this is the point: the crossing "names who may speak about reconstruction and reconstructs nothing", and "historical truth is preserved permanently: it named a boundary that possessed no power."

The second crossing named ten classes of semantic failure - malformed units, unsupported versions, missing parents, discontinuous segments, duplicated ordinals, commitment and root mismatches, incomplete checkpoints, ambiguous heads - and detected none of them. "The distinction is the whole crossing: a taxonomy that could observe a failure would own the evidence it classifies, and this crate owns nothing."

   powers denied by the persistence era
   +-----------------------------------------------------------+
   | reconstruction from the medium . canonical truth from      |
   | storage . ambient disk authority . startup bootstrap       |
   +-----------------------------------------------------------+
                 |
                 v   so the family starts with NO power:
   [1] a boundary nobody can instantiate
   [2] a taxonomy that names failures and detects none
                 |
                 v   then earns the grammar, then the implementations

Figure 1 - Why the family opens powerless. The denied column of the era map is the reason the first two crossings do nothing.

The chain of twelve crossings

   boundary --> taxonomy --> history-unit grammar --> segment continuity
      |                                                     |
      v                                                     v
   checkpoint accelerator --> canonical history material --> reference
                                                           transition
                                                                |
                    +-------------------------------------------+
                    v
             independent oracle (one unit)      bounded engine (a sequence)
                    \                                  /
                     \   siblings: neither links       /
                      \  the other or the reference   /
                       v                             v
                     differential tribunal (decides nothing)
                                   |
                                   v
                     read-only node door (mutation unrepresentable)
                                   |
                                   v
                     closure on an honest witness

Figure 2 - The family from boundary to closure. Two implementations, one comparison, one door, one seal.

The middle of the chain is the grammar: what a history unit is, how segments continue one another, how a checkpoint may accelerate a rebuild without becoming history, what the canonical material is, and - as an executable reference - what applying one unit does to a reconstruction state. Everything after it is about reaching that answer again without trusting the reference.

Independence as a dependency-closure fact

The oracle crossing asks a precise question: can the reference's answer "be reached again, from the same values, by an implementation that does not link the reference, does not link the accepted material owner and does not even link the accepted hash boundary?" The values an adjudication needs are carried by a neutral case crate that "computes nothing at all"; the oracle re-implements the accepted derivations from written layouts, with its own re-declared domain tags and the hash primitive taken directly.

The record insists that independence is "a DEPENDENCY-CLOSURE fact, not a source scan". An idiomatic accessor can return the accepted derivation without any text a scanner would find; so the proof is over the dependency graph across every edge kind and every feature mode, and additionally by building in a scratch workspace from which the reference crate has been physically removed. A text scan is retained "as a secondary readability check and is explicitly not the rule".

Re-declaring the domain tags is both the only available construction and the risk: a silent edit on either side would leave the oracle compiling and self-consistent while every value diverged. Three guards discharge it - a live differential guard over computed values, frozen digest vectors bound to the accepted tree, and a definition-site pin naming the exact accepted lines a future editor must not touch, singling out the tag with exactly one occurrence in the accepted tree as "the least guarded of the five and the one this crossing depends on most".

   reference transition          independent oracle
   (accepted)                    (rebuilt from written layouts)
        |                               |
        |  no link, at any depth,       |
        |  in any feature mode          |
        v                               v
   values ---- differential guard ---- values      must agree, case by case
             + frozen digest vectors
             + definition-site pin

Figure 3 - Two paths to the same value. "What agreement removes is the class of defect that lives in one implementation alone."

The limit is written into the record: "This crossing does not establish that the accepted derivations are CORRECT. It establishes that a second implementation, built from written layouts and forbidden from linking the first, reaches the same values on every case exercised here. Two implementations that agree may still share a mistaken premise."

The sibling law

The engine crossing answers the next question: can a bounded sequence of units be reconstructed deterministically, the state of one unit opening the next, without any of those links "and without acquiring an unbounded door on the way"? Its load-bearing decision is that the engine does not link the oracle either. The two are siblings under the neutral case grammar, "joined only by the later differential tribunal. A tribunal that compared an implementation against something calling it would compare nothing." An earlier sentence in the programme had permitted the dependency; the record notes the supersession openly rather than applying it silently.

Every limit a caller may declare is clamped by a compile-time ceiling, "because a limit a caller may raise without bound is not a bound but a number the attacker chose." Nine dimensions are bounded - units, opening and final entries, canonical state bytes, case bytes, identities, effects, report bytes and total iterations - and the iteration bound is checked against a count projected from the request shape before any unit is processed, so an oversized request is refused rather than partially executed and abandoned.

A tribunal that decides nothing

The tribunal "exposes agreement, disagreement and asymmetric refusal. It does not decide which side is right, does not repair either side, and installs nothing. Nothing in its position entitles it to select canonical truth, so no such entry point exists to call." It contains no third implementation, declares no domain tag, links no hash primitive and writes no preimage - the absence of the hashing dependency in its manifest is "a dependency fact rather than a promise a reader has to trust".

Its subtle part is making a sequence and a single unit comparable. The engine consumes a bounded sequence; the oracle adjudicates one unit against the opening state that unit carries. The tribunal runs the engine once, runs the oracle unit by unit, and threads the oracle-produced state into the next oracle unit. "Each side threads ITS OWN produced state: sharing one thread would let the tribunal decide for a side what that side's next opening state is, which is exactly the authority it does not have." That threading is proved positively, with a negative control that must fail when the real threaded state is substituted, and with a regression lock so that the earlier shared-thread behaviour fails rather than passing unnoticed.

   engine:  unit1 -> unit2 -> unit3   (threads its own state)
   oracle:  unit1 -> unit2 -> unit3   (threads its own state)
                 |        |        |
                 v        v        v
              compare  compare  compare   -> agree . disagree . refuse asymmetrically
                                            (reported, never adjudicated)

Figure 4 - Side by side, each on its own thread. The tribunal reports; it never selects a side.

Reachability is reported in two tables and measured from an executed hostile corpus: surfaces reached end to end by the real entry point with both implementations unmutated, and surfaces exercised only by feeding a pure comparator two synthetic observations. The tables are proved disjoint and their union total. Exactly one surface is reachable end to end - the sequence frontier - "because the sequence engine enforces adjacent-unit continuity and the single-unit oracle has no adjacent pair to enforce it on. That is the one disagreement two correct implementations can genuinely have." Every other surface would require one of the two independent paths to be mutated. And the record closes the scope: "This is not certification, not final authority, not consensus, not a canonicality decision, not formal verification, and not an external independent validation."

Mutation is unrepresentable, not refusable

The node-integration crossing makes the three accepted pieces answerable to a node-side caller "without granting the node anything it did not already have". It measured before designing: the line already carried a bounded, loopback-only, read-only local-control transport with a seam its own header calls the state-authority firewall. "So the port exists and the connection does not." Building a second transport would have given the read-only guarantee two owners, "and one of them would eventually have been wrong". The crossing consumes the existing seam and declares no socket, no address, no listener and no frame.

The design rule is stated in a sentence worth keeping: "A handler that parses a write and then declines it is still a surface that understands writes, and the branch that declines is one edit away from not declining." The operation vocabulary therefore has no mutating variant; requests to apply, write, install, commit, select a canonical side or finalise resolve to nothing and are answered as unknown. The absence is proved by compile-fail cases on the absent variant and the absent entry points, "not by a runtime test that a future refactor could invert". The tribunal's answers, exposed over the query surface, stay observations.

   read-only local control (existing, loopback only)
        |
        v
   recon.* operations: query, compare, report ...      -> answered
   recon.apply / write / install / commit / finalize   -> no representation
                                                         (compile-fail proven)

Figure 5 - The door. Nothing that would mutate has a shape the door can parse.

What the replay domain does not do

  • It does not decide truth. The tribunal reports agreement and disagreement; it selects no canonical side, and no entry point exists that could.
  • It does not install, persist, select a head or reach a network. Each record says so for its own scope.
  • It does not prove the shared primitive or the shared domain tags correct. Independence removes single-implementation defects, not a shared premise.
  • It is not certification, formal verification or external validation.
  • Its offline verifier for outsiders - the first rung of the adoption ladder - is planned, not built; nothing is downloadable today.

Verdict

The replay domain is the clearest example on the line of a power earned in the right order: first the right to speak about it, then the vocabulary of its failures, then the grammar, then two implementations forbidden from leaning on each other, then a judge that only reports, then a door that cannot parse a write - and only then a seal, on a witness the closure had first to repair. Its records refuse the words most projects would reach for - certified, verified, final - and replace them with something an outsider can check: a bounded history rebuilt twice, and every disagreement measured.

Frequently asked questions

Does this mean FxChain can restore a node from backup?

No. The family rebuilds a bounded preserved history through two independent paths and compares them; it installs no state and selects no head. Cold resurrection at scale is a reserved plane, and the continuity pipeline is design.

If two implementations agree, is the result correct?

Not necessarily, and the records say so. Agreement removes the class of defect that lives in one implementation alone; it cannot remove a premise both share. That is why the domain tags are guarded separately and why the tribunal reports rather than certifies.

Why does the tribunal not pick a winner?

Because nothing in its position entitles it to. Selecting canonical truth is a power, and the family did not earn it; so no entry point for it exists.

Can I run this myself?

Not yet. Public reproduction is a later gate on the Foundations ledger, and the offline verifier the architecture programme wants delivered first is planned.

Where is the line between this and Foundations?

Foundations presents what independent reconstruction establishes, with its evidence and limits, for an evaluator. This dossier follows how the family was built, crossing by crossing.

Sources and methodology

Drawn from the acceptance records of the reconstruction family on the sealed development line - the boundary, the taxonomy, the grammar, the oracle, the engine, the tribunal, the node integration and the closure - together with the era and power map, the architecture programme's chapter on the independent reconstruction service, and the Foundations edition on this portal. Quotations are from the records. Implementation claims are limited to what the records describe as accepted; design claims are attributed and carry the status planned, research or later gate.

The records are not published on this portal and are not reproduced here; identifiers, module names and limits are reported as the shape of the work. Figures shown anywhere on this portal come from a single dated snapshot; none are introduced by this dossier. Reference line: the family is the persistence era's third movement, crossings 361 to 372, closed on 2 August 2026.

Related reading: FxChain Foundations and its evidence; Sealed history for the closure's witness; FxState for the commitment the rebuilt history must reach.

Discuss a mechanism

Bring a bounded subject, its method and the evidence you want examined. An enquiry does not grant a licence, a production endpoint or a delivery date.