Skip to content

Isolation replay and provenance

Codex edited this page Aug 22, 2026 · 2 revisions

Isolation, replay & provenance

GenOS combines three related ideas: keep alternative futures from contaminating each other, preserve the events that produced each future, and reconstruct supported state from those events.

Two dimensions of isolation

Causal isolation: where actions can write

For directory-backed and Git-oriented worlds, each branch receives a distinct mutable root. Path resolution rejects escapes from the assigned world, and branch snapshots/diffs operate within that root.

common snapshot W0
      │
      ├─ world WA ─ files changed by branch A
      ├─ world WB ─ files changed by branch B
      └─ world WC ─ files changed by branch C

A write in WA should not appear in WB merely because both share ancestry.

Contextual isolation: what a branch can know

Each child branch has a distinct identity, event partition, working state, and scoped context. Shared ancestry is explicit; mutable event streams are not implicitly shared.

This reduces accidental cross-branch memory bleeding and makes comparisons meaningful. It does not automatically defend against every prompt injection or data-exfiltration path in external tools.

The actual security boundary

Implemented local protections include scoped world roots, safe relative-path resolution, branch-specific state/event records, tool permissions, budgets, taint metadata, and failure/circuit-breaker behavior.

They do not by themselves provide:

  • kernel or hypervisor isolation;
  • a network namespace or deterministic network proxy;
  • secret redaction from arbitrary child processes;
  • protection from a malicious binary with host access;
  • transactional rollback of external SaaS or API side effects;
  • a production multi-tenant security boundary.

Use containers, microVMs, OS sandboxing, credential brokers, and network policy when the threat model requires them. GenOS tracks the execution and state boundary; it does not replace the host security layer.

Event-sourced state

For supported domain state, the current state is modeled as a fold over an initial state and ordered events:

S0 ── E1 ──> S1 ── E2 ──> S2 ── E3 ──> S3

replay(S0, [E1, E2, E3]) = S3

Events are append-only. A replay reducer applies known event variants in sequence and can verify that the reconstructed state matches the recorded result.

Replay versus rerun

These terms are deliberately different:

Operation What happens
Replay Recorded supported events are folded over a known state without re-invoking the model
Rerun The original model, tool, process, network, and clock interactions are executed again
Restore A stored checkpoint is reconstituted into an active capsule/world
Counterfactual replay A checkpoint is restored, an intervention changes, and the resulting trajectory is compared

Replay can be deterministic even when a new provider inference would not be. That is why GenOS records results and receipts instead of assuming a seed makes a remote model reproducible.

Determinism boundary

GenOS can control or record:

  • canonical serialization and hashing;
  • event order and reducer behavior;
  • seeded local experiments;
  • declared inputs and output receipts;
  • snapshot ancestry and world-tree content;
  • fixed deterministic fixtures.

Sources of nondeterminism outside that boundary include provider implementation changes, GPU kernels, sampling details, concurrency, clocks, network responses, external databases, and tools with hidden state.

For those systems, GenOS favors compensation:

  • record provider/model identifiers and fingerprints;
  • store the original output and usage metadata;
  • validate downstream structure and invariants;
  • compare semantic outcomes against golden data;
  • classify a replay as exact, equivalent, diverged, or unsupported;
  • refuse to claim determinism when required evidence is absent.

Provenance graph

Snapshots and genomes form an acyclic lineage graph:

S0
├─ S1A ─ mutation GA' ─ result RA
├─ S1B ─ result RB ─ replay S1B'
└─ S1C ─ result RC
              │
S2 <── promoted winner / reviewed merge

Useful provenance questions include:

  • What snapshot is the nearest common ancestor?
  • Which mutation introduced this trait?
  • Which event first changed this belief?
  • Which branch produced the promoted artifact?
  • Was the promoted result replayed from the original baseline?
  • Which evidence and reviewer decision authorized the merge?

Integrity is not truth

A digest can show that a record has not changed; it cannot prove that the record is factually correct. An append-only event can faithfully preserve a hallucination. GenOS therefore combines integrity with evaluation, receipts, contradiction checks, and explicit promotion policy.

See Examples & evidence for the tests that exercise reducer replay and world isolation.

Clone this wiki locally