AquaQoSDocs

Benchmarks

Conservative Aqua, raw overcommitment and two AquaQoS policies on equal backing and identical demand.

The question. Can a protected-capacity scheduler let several Aqua strategies share one inventory with fewer settlement failures than raw overcommitment, while keeping the conservative allocation's protected capacity and making the price and gas trade-offs visible?

Recorded Clean retained report with dirty=false, Node 22.16.0, Hardhat 3.8.0, solc 0.8.30, Cancun, viaIR and optimizer 700. Local test tokens only.

72
fresh EVM fixtures
616
offered swaps, all retained
12
replenishment pushes
52
guard rejections replayed

Systems under test

Every system uses the same pinned code, compiler, EVM, token pair, fee-free XYC program, exact-output demand and accounts. Each fixture starts with B = 10,000 raw units of each token.

SystemVirtual per strategyGuaranteeCustody
A · conservative AquaB/NNoneMaker EOA
B · raw overcommitmentBNoneMaker EOA
C · AquaQoSBB/2NAquaQoS vault
C100 · matched AquaQoSBB/NAquaQoS vault

C100's guarantees equal A's initial split, which isolates the guarantee ratio. Quote depth and custody still differ from A and are not controlled away.

Workloads

Group sizes of 2, 4 and 8 strategies, six workloads each, every swap mined as its own transaction:

  • Low contention: one strategy active at a time.
  • Concentrated overload, forward and reverse: one strategy consumes its guarantee and burst before siblings are offered demand.
  • Replenishment: fixed Aqua.push deposits at documented steps.
  • Balanced round-robin and seeded shuffle: every strategy trades once in each direction; both orders share one demand multiset.

Demand is never reduced after a failure, and taker balances are never topped up mid-run.

Outcomes

Every offered swap has exactly one primary outcome. Guard rejections and settlement failures are never counted as successful volume.

OutcomeMeaning
successReceipt succeeds and ERC-20 and Aqua deltas match
quote_rejectionThe program cannot admit the output, for example on shallow virtual depth
guard_rejectionAquaQoS rejects before any token moves
settlement_failureRaw Aqua reaches settlement, the transfer fails, and everything rolls back

Results

Successful over offered output units. q, g and f are quote-rejected, guard-rejected and settlement-failed units.

StrategiesWorkloadABCC100
2Concentrated6,000/18,000 (q 12,000)9,000/18,000 (q 3,000; f 6,000)9,000/18,000 (g 9,000)6,000/18,000 (g 12,000)
4Concentrated6,000/13,500 (q 7,500)9,000/13,500 (f 4,500)9,000/13,500 (g 4,500)6,000/13,500 (g 7,500)
8Concentrated6,000/12,000 (q 6,000)9,750/12,000 (f 2,250)9,750/12,000 (g 2,250)6,000/12,000 (g 6,000)
2Replenishment7,500/10,000 (q 2,500)10,000/10,00010,000/10,00010,000/10,000
8Replenishment1,875/2,500 (q 625)2,500/2,5002,500/2,5002,500/2,500

Low-contention, balanced and shuffled workloads fill all offered demand under every policy. No configured-capacity violation was found in any recorded C or C100 post-action state.

How to read this

At equal protection, C100 fills exactly what conservative Aqua fills: 6,000. C's extra volume comes from its smaller guarantees, not from the guard itself. The guard's contribution is where excess demand fails: before settlement, with sibling guarantees intact, instead of as a raw inventory shortage.

Gas: the losing case

Median transaction gas at eight strategies:

CaseA / BCC100
Low-contention success113,715210,099210,099
Concentrated: raw settlement failure126,779
Concentrated: guard rejection146,465147,137

Guarded success costs 96,384 more gas at eight strategies, about 84.8% overhead, because every admission reads each sibling. Guard rejection is also more expensive than raw settlement failure. Earlier rejection does not mean cheaper rejection. Trade sizes change with group size, so these medians are not a controlled per-sibling slope.

Were the rejections necessary?

Every one of the 52 C and C100 guard rejections was rebuilt from its recorded pre-state and executed through the official unguarded router.

17
would fail in settlement
35
would settle but breach configured capacity
0
safe fills rejected in this sample
12
successful controls reproduced

Scope limit This covers the static, fee-free, maximum-allowance TokenMock cases in this report. It does not measure same-transaction or finite-allowance conservatism, where safe fills can be rejected, and it does not claim every rejection outside this scope was necessary.

What this does not show

Mainnet liquidity, economic value, profitability or universal solvency; a single-strategy group; token diversity; broader shuffled overload; or universal worst-case gas.

Verify

On this page