We consider an architecture for ultra-dependable operation based on synchronizedstate machine replication, extended to provide transient recovery andreconfiguration in the presence of Byzantine faults.The architecture allows processors suspected of being faulty to be placedon "probation." Processors in this status cannot disrupt other processors, butthose that are nonfaulty or recovering from transient faults are able to remainsynchronized with the other processors and with each...