REVIEW 2 major objections 5 minor 56 references
Cassandra lets Byzantine fault-tolerant replicas keep ordering transactions inside network partitions with weak certificates, then safely reconcile those provisional chains once connectivity returns.
Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →
T0 review · grok-4.5
2026-07-12 06:33 UTC pith:BIPBINNM
load-bearing objection Solid systems paper that actually delivers non-zero recoverable BFT progress under partitions where every baseline goes to zero, with standard proofs and thorough eval. the 2 major comments →
Cassandra: Consensus with Partial Progress via Robust Partitionable View Synchronization
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
Core claim
Cassandra establishes that BFT consensus can satisfy Partial Liveness: while the network is partitioned, any synchronous connected component containing at least f+1 correct replicas continues ordering new client transactions via Proof-of-Availability certificates, and that accumulated progress remains recoverable and can be incorporated into final Proof-of-Reliability commits once connectivity is restored, without ever violating safety.
What carries the argument
The two-tier certification framework: a Proof of Availability (PoA) formed by a weak quorum of f+1 votes, which certifies recoverable partial progress inside a partition, and a Proof of Reliability (PoR) formed by a strong quorum of n-f votes, which alone justifies commitment. Paired with a deterministic proposal-priority rule and a decoupled pacemaker that advances rounds on either a PoR or a weak Round Certificate, this lets each partition extend its own chain and later reconcile implicitly.
Load-bearing premise
The system assumes that after every disruption there will eventually be a long enough stable period among the reachable replicas for their local timeouts to catch up to the true message delay, and that the cryptographic keys for certificates were set up before any permanent split.
What would settle it
Partition more than f replicas for longer than any timeout-calibration window, then restore connectivity: if the previously isolated components either commit conflicting transactions or fail to incorporate any of their PoA-certified proposals into the final log, the partial-liveness claim is false.
If this is right
- Any connected component of only f+1 correct replicas can keep ordering and speculatively executing transactions during a partition.
- Divergent PoA-backed histories reconcile automatically once a strong quorum is reachable again, without an explicit merge protocol.
- Under stable networks Cassandra remains competitive (900K TPS at 16 replicas, 480K TPS at 104).
- Speculative PoA work is preserved and can produce a recovery burst after reconnection.
- Round advancement no longer requires a strong quorum of new-view messages.
Where Pith is reading between the lines
- Intra-shard consensus in sharded blockchains could adopt the same weak-quorum progress so a shard does not stall when only f+1 honest replicas remain connected.
- Geo-distributed deployments that experience recurring regional partitions would accumulate less wasted work and recover faster than pure strong-quorum designs.
- The background multiplicative timeout calibration could be reused by other partially-synchronous protocols that currently leave timeouts permanently inflated after transient spikes.
- Speculative execution of PoA-backed proposals offers a measurable intermediate progress metric for systems that previously reported only zero or full throughput under CAP stress.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. Cassandra is a BFT consensus protocol that preserves classical safety while enabling partial progress under network partitions. It replaces strong-quorum-only commitment with a two-tier certification scheme (weak-quorum PoA for recoverable local ordering, strong-quorum PoR for final commit), eliminates designated-leader dependence via all-to-all proposal exchange and a deterministic certificate-priority rule (with threshold-coin tie-break), and uses a decoupled pacemaker that advances rounds on PoR or weak-quorum Round Certificates while calibrating local timeouts off the critical path. Safety, liveness under partial synchrony with recurring GSTs, and Partial Liveness (any connected component of ≥f+1 correct, timeout-sufficient replicas continues to produce recoverable PoA progress) are claimed via Theorems 1–3 and proved in Appendix A. A dual-path optimization (linear fast path with base-path fallback), optional dissemination layer, and speculative PoA execution are evaluated against Tusk, AutoBahn, PBFT, HotStuff, SpotLess and RCC, showing competitive stable-state throughput/latency and non-zero speculative throughput under f+1 and n/2 partitions.
Significance. If the claims hold, Cassandra supplies a clean, CAP-aware middle ground for permissioned BFT systems: partitions no longer force zero useful progress, yet final commits remain classical and safe. The combination of two-tier certificates, partitionable leader election, and a weak-quorum-capable pacemaker is a coherent design contribution that is orthogonal to sharding and DAG mempools and could be reused as an intra-shard component. Strengths that raise confidence include a full Appendix A proof suite built on standard quorum-intersection, single-vote and lock-monotonicity arguments, an open-source C++ implementation inside Apache ResilientDB, and a multi-scenario evaluation (scalability to 104 replicas, three partition patterns, Byzantine delay/tail-forking, geo-regional partition, ablation) that independently supports the 0-to-1 progress claim. The free parameters (K, α, δmin) are confined to timeout calibration and do not appear in the safety or partial-liveness statements.
major comments (2)
- §4.1.1 / Fig. 6 / Lemma 5: The Two-PoR commit rule is stated clearly, but the manuscript never quantifies how much provisional PoA work is discarded when a competing higher-priority branch wins after recovery. Because Partial Liveness is defined as “recoverable” progress that “can be incorporated,” a short bound or experimental measurement of the fraction of PoA-certified proposals that ultimately become ancestors of a committed PoR (under the f→n/2→f and geo-partition scenarios of Fig. 12) is needed to make the usefulness claim precise rather than qualitative.
- §2 / Lemma 6 / Theorem 3: Partial Liveness is conditioned on every correct replica inside the component already being timeout-sufficient (δi ≥ Δ). The background SyncTimeout service itself requires a 2f+1 SYNC-READY collection to form a SYNC-CERT; under a permanent or long-lived partition that never contains a strong quorum, calibration cannot succeed and the δi ≥ Δ premise may never hold. The paper should either (a) state an explicit additional assumption that each component experiences at least one calibration-success window, or (b) show that RC-based round advancement alone still yields PoAs even with mis-calibrated (but finite) timeouts, so that the partial-progress claim does not silently depend on a strong-quorum calibration step.
minor comments (5)
- Fig. 12 caption and §7.3: Distinguish more explicitly in the plots (or legend) between final committed TPS and speculative PoA TPS; the text already does so, but the figures themselves can be misread as ordinary throughput.
- §5.1: The fast-path collector is described as “e.g., the next-round leader”; a one-sentence statement that any fixed deterministic collector works (and that the base-path fallback is independent of that choice) would remove a minor ambiguity.
- §4.2.3: The optional multiplicative decrease of δi (factor α) is mentioned only in prose; adding the precise predicate “elapsed < δi/α” to the pseudocode of Fig. 9 would improve reproducibility.
- Related Work: A short comparison paragraph with Raptr’s prefix-consensus and with AutoBahn’s dissemination-only partial progress would help readers locate Cassandra’s novelty more quickly.
- Typographical: “stabalized” → “stabilized” (several places); “tai-forking” in the reader summary is a transcription error—the manuscript correctly says “tail-forking.”
Circularity Check
No significant circularity: Safety/Liveness/Partial Liveness rest on standard quorum-intersection and protocol definitions, independent of evaluation numbers or self-citations.
full rationale
The derivation chain for Theorems 1–3 (and the supporting Lemmas 1–11 in Appendix A) is self-contained. Safety follows from classical BFT ingredients—strong-quorum intersection of size 2f+1 (Lemma 1), single-vote per round (Lemma 2), PoR uniqueness, lock monotonicity under the Two-PoR rule, and the resulting locked-set argument—none of which is defined in terms of the target claim or fitted to data. Liveness and Partial Liveness likewise follow from the explicit model (partial synchrony with recurring GSTk, pre-established threshold keys, local timeouts calibrated off-path) together with the protocol’s own definitions of PoA (f+1 votes), RC, deterministic priority, and data availability; the probability bound (2f+1)/n for coin-resolved good rounds is a direct counting argument, not a fitted parameter. Evaluation metrics (TPS/latency under partitions) are measured post-hoc and never appear inside the theorems. Self-citations (ResilientDB platform, prior multi-leader or DAG works) are used only for implementation and comparison baselines; they do not supply any uniqueness theorem or ansatz that forces the central claims. Consequently the paper exhibits none of the six circularity patterns.
Axiom & Free-Parameter Ledger
free parameters (3)
- K (timeout-calibration interval in rounds)
- α (timeout-decrease threshold)
- δmin (minimum local timeout)
axioms (4)
- domain assumption n ≥ 3f+1 replicas, at most f Byzantine; strong quorum 2f+1, weak quorum f+1
- domain assumption Partial synchrony with unbounded sequence of stabilized periods GSTk after which messages among mutually reachable correct replicas arrive within unknown finite Δ
- domain assumption Authenticated channels via unforgeable digital signatures and collision-resistant hash; threshold signatures (f+1,n) and (2f+1,n) set up before any runtime partition
- domain assumption Correct replicas cast at most one vote per round and follow the deterministic priority and locking rules
invented entities (3)
-
Proof of Availability (PoA) certificate
no independent evidence
-
Proof of Reliability (PoR) certificate
no independent evidence
-
Decoupled pacemaker with background SyncTimeout calibration
no independent evidence
read the original abstract
Replicated databases and permissioned blockchain systems rely on Byzantine Fault-Tolerant (BFT) consensus to maintain a globally consistent order of transactions across distributed replicas. These protocols preserve safety even under asynchrony, as they commit a transaction only after agreement among a strong quorum of replicas. During network partitions, however, when no strong quorum is reachable, they lose liveness and cannot make useful progress. In this paper, we present Cassandra, a consensus protocol that enables partial progress without sacrificing safety. Cassandra achieves this through a two-tier certification framework that decouples availability from commitment, allowing each partition to extend its own chain and reconcile these chains once the network is restored. To support this, Cassandra introduces a pacemaker that advances views without requiring a strong quorum and calibrates each replica's timeout off the critical path. Our evaluation results show that Cassandra remains competitive with state-of-the-art BFT protocols under stable conditions, sustaining 900K TPS at 16 replicas and 480K TPS at 104 replicas, with latency ranging from 0.31s at 16 replicas to 0.75s at 104 replicas. Under severe partitions, Cassandra maintains non-zero speculative throughput through PoA-backed progress, preserving work that can be reconciled once connectivity is restored.
Figures
Reference graph
Works this paper leans on
-
[1]
[n. d.]. Cassandra: Consensus with Partial Progress via Robust Partitionable View Synchronization (Extended Version). https://github.com/apache/incubator- resilientdb/blob/cassandra/Cassandra_extended.pdf
-
[2]
[n. d.]. Cassandra Source Code. https://github.com/apache/incubator-resilientdb/ tree/cassandra
-
[3]
Mustafa Al-Bassam, Alberto Sonnino, Shehar Bano, Dave Hrycyszyn, Sarah Meiklejohn, and George Danezis. 2018. Chainspace: A Sharded Smart Contracts Platform. InNDSS
2018
-
[4]
Ahmed Alquraan, Hatem Takruri, Mohammed Alfatafta, and Samer Al-Kiswany
-
[5]
InUSENIX OSDI
An Analysis of Network-Partitioning Failures in Cloud Systems. InUSENIX OSDI. 51–68
-
[6]
Amazon Web Services. 2025. Summary of the Amazon DynamoDB Service Disruption in the Northern Virginia (US-EAST-1) Region. https://aws.amazon. com/message/101925/. (Accessed: 07-01-2026)
2025
-
[7]
Apache ResilientDB. [n. d.]. Apache ResilientDB (Incubating). https://resilientdb. apache.org/
-
[8]
Maria Apostolaki, Aviv Zohar, and Laurent Vanbever. 2017. Hijacking Bitcoin: Routing Attacks on Cryptocurrencies. In2017 IEEE Symposium on Security and Privacy (SP). IEEE, 375–392. doi:10.1109/SP.2017.29
-
[9]
Balaji Arun and Binoy Ravindran. 2022. Scalable Byzantine Fault Tolerance via Partial Decentralization. InPVLDB
2022
-
[10]
Eric A. Brewer. 2000. Towards Robust Distributed Systems. InACM PODC
2000
-
[11]
Miguel Castro and Barbara Liskov. 1999. Practical Byzantine Fault Tolerance. In USENIX OSDI. 173–186
1999
-
[12]
Miguel Castro and Barbara Liskov. 2002. Practical Byzantine Fault Tolerance and Proactive Recovery. InACM Transactions on Computer Systems. 398–461
2002
-
[13]
Cloudflare. 2025. Cloudflare outage on December 5, 2025. https://blog.cloudflare. com/5-december-2025-outage/. Accessed: 07-01-2026
2025
-
[14]
Cloudflare. 2025. Cloudflare outage on November 18, 2025. https://blog.cloudflare. com/18-november-2025-outage. Accessed: 07-01-2026
2025
-
[15]
Cryptonary. 2021. Solana Network Went Down Again; Mainnet Beta Restarts After 7 Hours of Outage. InOnline resource
2021
-
[16]
George Danezis, Lefteris Kokoris-Kogias, Alberto Sonnino, and Alexander Spiegel- man. 2022. Narwhal and Tusk: A DAG-Based Mempool and Efficient BFT Con- sensus. InACM EuroSys
2022
-
[17]
Reiter, and Haibin Zhang
Sisi Duan, Michael K. Reiter, and Haibin Zhang. 2018. BEAT: Asynchronous BFT Made Practical. InACM CCS
2018
-
[18]
Cynthia Dwork, Nancy Lynch, and Larry Stockmeyer. 1988. Consensus in the Presence of Partial Synchrony. InJournal of the ACM. 288–323
1988
-
[19]
Rosario Gennaro, Stanislaw Jarecki, Hugo Krawczyk, and Tal Rabin. 1999. Secure Distributed Key Generation for Discrete-Log Based Cryptosystems. InEURO- CRYPT. 295–310
1999
-
[20]
Seth Gilbert and Nancy Lynch. 2012. Perspectives on the CAP Theorem. InIEEE Computer
2012
-
[21]
Neil Giridharan, Florian Suri-Payer, Ittai Abraham, Lorenzo Alvisi, and Natacha Crooks. 2024. AutoBahn: Seamless High Speed BFT. InACM SOSP
2024
-
[22]
Reiter, Dragos-Adrian Seredinschi, Orr Tamir, and Alin Tomescu
Guy Golan Gueta, Ittai Abraham, Shelly Grossman, Dahlia Malkhi, Benny Pinkas, Michael K. Reiter, Dragos-Adrian Seredinschi, Orr Tamir, and Alin Tomescu. 2019. SBFT: A Scalable and Decentralized Trust Infrastructure. InIEEE DSN
2019
-
[23]
Suyash Gupta, Jelle Hellings, and Mohammad Sadoghi. 2021. Fault-Tolerant Dis- tributed Transactions on Blockchain. InSynthesis Lectures on Data Management
2021
-
[24]
Suyash Gupta, Jelle Hellings, and Mohammad Sadoghi. 2021. RCC: Resilient Concurrent Consensus for High-Throughput Secure Transaction Processing. In IEEE ICDE
2021
-
[25]
Suyash Gupta, Sajjad Rahnama, Jelle Hellings, and Mohammad Sadoghi. 2020. ResilientDB: Global Scale Resilient Blockchain Fabric. InPVLDB. 868–883
2020
-
[26]
Hughes, Joshua Primero, and Mohammad Sadoghi
Jelle Hellings, Daniel P. Hughes, Joshua Primero, and Mohammad Sadoghi. 2023. Cerberus: Minimalistic Multi-Shard Byzantine-Resilient Transaction Processing. InJournal of Systems Research
2023
-
[27]
Jelle Hellings and Mohammad Sadoghi. 2021. ByShard: Sharding in a Byzantine Environment. InPVLDB
2021
-
[28]
Kendric Hood, Joseph Oglio, Mikhail Nesterenko, and Gokarna Sharma. 2021. Partitionable Asynchronous Cryptocurrency Blockchain. InIEEE ICBC
2021
-
[29]
Van Jacobson. 1988. Congestion Avoidance and Control. InACM SIGCOMM
1988
-
[30]
Dakai Kang, Suyash Gupta, Dahlia Malkhi, and Mohammad Sadoghi. 2025. HotStuff-1: Linear Consensus with One-Phase Speculation. InSIGMOD
2025
-
[31]
Dakai Kang, Sajjad Rahnama, Jelle Hellings, and Mohammad Sadoghi. 2024. SpotLess: Concurrent Rotational Consensus Made Practical Through Rapid View Synchronization. InIEEE ICDE
2024
-
[32]
Jonathan Katz and Yehuda Lindell. 2014. Introduction to Modern Cryptography (2nd Edition). InChapman and Hall/CRC
2014
-
[33]
Idit Keidar, Eleftherios Kokoris-Kogias, Oded Naor, and Alexander Spiegelman
-
[34]
InACM PODC
All You Need is DAG. InACM PODC
-
[35]
S. Keshav, W. Golab, B. Wong, S. Rizvi, and S. Gorbunov. 2018. RCanopus: Making Canopus Resilient to Failures and Byzantine Faults. InarXiv preprint arXiv:1810.09300. Conference’17, July 2017, Washington, DC, USA Shaokang Xie, Dakai Kang, Junchao Chen, Suyash Gupta, Daniel P. Hughes, and Mohammad Sadoghi
Pith/arXiv arXiv 2018
-
[36]
Fischer, and Bryan Ford
Eleftherios Kokoris-Kogias, Philipp Jovanovic, Linus Gasser, Nicolas Gailly, Ismail Khoffi, Lars M. Fischer, and Bryan Ford. 2018. OmniLedger: A Secure, Scale-Out, Decentralized Ledger via Sharding. InIEEE S&P
2018
-
[37]
Ramakrishna Kotla, Lorenzo Alvisi, Mike Dahlin, Allen Clement, and Edmund Wong. 2007. Zyzzyva: Speculative Byzantine Fault Tolerance. InACM SOSP
2007
-
[38]
Andrew Lewis-Pye. 2022. Quadratic Worst-Case Message Complexity for State Machine Replication in the Partial Synchrony Model. InarXiv preprint arXiv:2201.01107
Pith/arXiv arXiv 2022
-
[39]
Andrew Lewis-Pye and Ittai Abraham. 2023. Fever: Optimal Responsive View Synchronisation. InarXiv preprint arXiv:2301.09881
Pith/arXiv arXiv 2023
-
[40]
Andrew Lewis-Pye, Dahlia Malkhi, Oded Naor, and Kartik Nayak. 2024. Lumiere: Making Optimal BFT for Partial Synchrony Practical. InACM PODC
2024
-
[41]
Hanzheng Lyu, Shaokang Xie, Jianyu Niu, Ivan Beschastnikh, Yinqian Zhang, Mohammad Sadoghi, and Chen Feng. 2025. Orthrus: Accelerating Multi-BFT Consensus Through Concurrent Partial Ordering of Transactions. InIEEE ICDE
2025
-
[42]
Hanzheng Lyu, Shaokang Xie, Jianyu Niu, Chen Feng, Yinqian Zhang, and Ivan Beschastnikh. 2025. Ladon: High-Performance Multi-BFT Consensus via Dynamic Global Ordering. InACM EuroSys
2025
-
[43]
Hanzheng Lyu, Shaokang Xie, Jianyu Niu, Mohammad Sadoghi, Yinqian Zhang, Cong Wang, Ivan Beschastnikh, and Chen Feng. 2025. HYDRA: Break- ing the Global Ordering Barrier in Multi-BFT Consensus. InarXiv preprint arXiv:2511.05843
arXiv 2025
-
[44]
Jean-Philippe Martin and Lorenzo Alvisi. 2005. Fast Byzantine Consensus. In IEEE DSN
2005
-
[45]
Andrew Miller, Yu Xia, Kyle Croman, Elaine Shi, and Dawn Song. 2016. The Honey Badger of BFT Protocols. InACM CCS
2016
-
[46]
Pedersen
Torben P. Pedersen. 1991. A Threshold Cryptosystem without a Trusted Party. InEUROCRYPT. 522–526
1991
-
[47]
Mohammad Sadoghi. 2025. The Problems of Consensus: An Ethical Inquiry into Democratic and Decentralized Principles. InSpringerBriefs in Philosophy
2025
-
[48]
Alexander Spiegelman, Neil Giridharan, Alberto Sonnino, and Lefteris Kokoris- Kogias. 2022. Bullshark: DAG BFT Protocols Made Practical. InACM CCS
2022
-
[49]
Chrysoula Stathakopoulou, Tudor David, Matej Pavlovic, and Marko Vukolic
-
[50]
InJournal of Systems Research
Mir-BFT: Scalable and Robust BFT for Decentralized Networks. InJournal of Systems Research
-
[51]
Chrysoula Stathakopoulou, Matej Pavlovic, and Marko Vukolic. 2022. State Machine Replication Scalability Made Simple. InACM EuroSys
2022
-
[52]
Andrei Tonkikh, Balaji Arun, Zhuolun Xiang, Zekun Li, and Alexander Spiegel- man. 2025. Raptr: Prefix Consensus for Robust High-Performance BFT. InarXiv preprint arXiv:2504.18649
Pith/arXiv arXiv 2025
-
[53]
Shaokang Xie, Dakai Kang, Hanzheng Lyu, Jianyu Niu, and Mohammad Sadoghi
-
[54]
InarXiv preprint arXiv:2501.01062
Fides: Secure and Scalable Asynchronous DAG Consensus via Trusted Components. InarXiv preprint arXiv:2501.01062
-
[55]
Reiter, Guy Golan Gueta, and Ittai Abra- ham
Maofan Yin, Dahlia Malkhi, Michael K. Reiter, Guy Golan Gueta, and Ittai Abra- ham. 2019. HotStuff: BFT Consensus with Linearity and Responsiveness. InACM PODC
2019
-
[56]
Mahdi Zamani, Mahnush Movahedi, and Mariana Raykova. 2018. RapidChain: Scaling Blockchain via Full Sharding. InACM CCS. Cassandra: Consensus with Partial Progress via Robust Partitionable View Synchronization Conference’17, July 2017, Washington, DC, USA A Correctness Proof This section provides the full proofs of Theorems 1, 2, and 3. A.1 Safety We assum...
2018
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.