[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83856-en":3,"doc-seo-83856-105":30,"detail-sidebar-cat-0-en-105":84},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83856,8796095462418,"Noah","https://ap-avatar.wpscdn.com/avatar/80000253c1241d02b47?x-image-process=image/resize,m_fixed,w_180,h_180&k=1778826106357471780",8,"Research & Report","Orcaella Hybrid Fault Tolerance with Client-Selectable Finality Latency","Orcaella studies hybrid fault tolerance for state machine replication, focusing on maximizing the safety of a 2-message-delay commit when Byzantine (f) and crash (c) faults are separated. The paper proves a tight requirement n ≥ 5f + 3c + 1 and derives an optimal fast-path quorum q = n − f − c. It proposes two client finality paths: an optimal 2-delay Fast-Path using VoteQC, and a 4-delay Resilient Path using CheckpointQC and FinalityQC to preserve safety through forks while recovering liveness under bounded equivocators.","Orcaella: Hybrid Fault Tolerance with Client-Selectable Finality Latency  \nLefteris Kokoris Kogias, Alberto Sonnino  \nMysten Labs  \n{lefteris, [alberto}@mystenlabs.com](alberto}@mystenlabs.com)  \narXiv :2607 .04789v 1 [ cs .DC] 6 Jul 2026  \nAbstract—Classical partially synchronous state machine replication, as in PBFT [1], tolerates f Byzantine replicas among n ≥ 3f + 1 using three communication steps per request. Recent protocols such as Minimmit [2] achieve two-message-delay decisions under stronger size assumptions, notably n ≥ 5f + 1 when any silent replica must be counted as a potential equivocator. Hydrangea [3] and Kudzu [4] treat mixed Byzantine and crash faults, focusing on providing a fast-path under optimistic conditions while maintaining a fallback commitment path similar to PBFT. In this paper, we also consider a mixed model, but focus on studying the fault tolerance of the 2-message-delay commit. For this, we prove a tight bound of n ≥ 5f + 3c + 1 . Extending this result, we also show that there exists a more resilient commit path that allows an extra fabc \u003C n − 3f − 2c alivebut-corrupt [5] faults at 4-message-delays. Core liveness is claimed in executions with at most f equivocators; if this regime is violated (e.g., AbC-induced forks), the protocol enters synchronous recovery, where only the resilient-path safety guarantee is preserved. As a result, for f = 16 , c = 6, and n = 99, we obtain a commit path that tolerates 22% of replicas failing for liveness, 16% equivocating for 1-RTT safety, and 54% equivocating for 2-RTT safety.  \nI. Introduction  \nState machine replication (SMR) protocols are the foundational building blocks of modern decentralized systems [6] . Under partial synchrony [7], classical solutions like PBFT [1] tolerate up to f Byzantine replicas among n ≥ 3f + 1, but require three all-to-all communication delays to reach consensus. As decentralized applications demand ever-lower latency, recent research has introduced two-message-delay protocols (e.g., Minimmit [2]) . However, achieving this optimal fast-path latency traditionally requires a much larger committee size of n ≥ 5f + 1, as every silent replica must be conservatively treated as a potential Byzantine equivocator.  \nThe challenge. To mitigate the severe 5f +1 requirement, a natural approach is to distinguish between fully Byzantine faults (who may equivocate) and crash faults (who merely go silent) . Recent work like Hydrangea [3] and Kudzu [4] adopt this mixed fault model. However, existing hybrid systems focus on providing a fast-path under optimistic conditions, while eagerly falling back to a slower, PBFTstyle 3-round path when faults increase.  \nThis leaves an open challenge: How can we maximize the fault tolerance of the optimal 2-message-delay commit itself when relaxing the fault model? Furthermore, if a client does not care about this lower latency, can we enhance the mixed fault model to provide even stronger, FlexibleBFT-style [5] safety guarantees?  \nOur solution. In this paper, we answer these questions by formally defining the tight quorum intersections required to maximize 2-message-delay commits under separate Byzantine (f ) and crash-faulty (c) caps. We show that such a system necessitates:  \nn ≥ 5f + 3c + 1  \nwith an optimal fast-path quorum of q = n − f − c, i.e. , 4f + 2c + 1 at the minimal committee size. At c = 0, this recovers the familiar 5f + 1 regime, but when crashes are separated, it allows for configurations with better liveness guarantees.  \nBuilding on this foundational result, we introduce Orcaella, a hybrid protocol that exposes two explicit finality paths for clients. These paths are built using Quorum Certificates (QCs)—cryptographic proofs consisting of q matching signed messages from distinct replicas:  \n• Optimal Fast-Path (2-delay): Clients can finalize quickly after collecting a single quorum of votes (VoteQC), providing safety against f Byzantine faults.  \n• Resilient Path (4-delay): Clients will","cbCait6UVmBjQsdr","https://ap.wps.com/l/cbCait6UVmBjQsdr","pdf",1162675,5,1,14,"English","en",105,"# Introduction\n# The Challenge\n# Our Solution\n# Orcaella Protocol and Finality Paths\n# Concrete Trade-offs","[{\"question\":\"How do the two client finality paths differ in latency and safety?\",\"answer\":\"Clients can use the 2-delay Optimal Fast-Path after a VoteQC for faster finality with safety against f Byzantine faults. Clients willing to wait for the 4-delay Resilient Path chain CheckpointQC and FinalityQC to gain resilience and additional safety against extra alive-but-corrupt replicas during fork scenarios.\"}]",1784191001,35,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":79,"head_meta":81,"extra_data":83,"updated_unix":28},"orcaella-hybrid-fault-tolerance-with-client-selectable-finality-latency","",{"@graph":36,"@context":78},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/orcaella-hybrid-fault-tolerance-with-client-selectable-finality-latency/83856/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72],{"name":73,"@type":74,"acceptedAnswer":75},"How do the two client finality paths differ in latency and safety?","Question",{"text":76,"@type":77},"Clients can use the 2-delay Optimal Fast-Path after a VoteQC for faster finality with safety against f Byzantine faults. Clients willing to wait for the 4-delay Resilient Path chain CheckpointQC and FinalityQC to gain resilience and additional safety against extra alive-but-corrupt replicas during fork scenarios.","Answer","https://schema.org",{"og:url":52,"og:type":80,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":82,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":85},[86,90,94,98,102,107,112,115,120,123,127],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":87,"show_sort_weight":88,"slug":89},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":91,"show_sort_weight":92,"slug":93},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Comic",60,"comic",{"id":103,"doc_module":4,"doc_module_name":46,"category_name":104,"show_sort_weight":105,"slug":106},6,"Technology",50,"technology",{"id":108,"doc_module":4,"doc_module_name":46,"category_name":109,"show_sort_weight":110,"slug":111},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":113,"slug":114},30,"research-report",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},9,"Religion & Spirituality",20,"religion-spirituality",{"id":118,"doc_module":4,"doc_module_name":46,"category_name":121,"show_sort_weight":118,"slug":122},"World Cup","world-cup",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":124,"slug":126},10,"Lifestyle","lifestyle",{"id":128,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":20,"slug":130},19,"General","general"]