๐ Succession Without Elections
Knock out the leader. Nobody votes. Nobody fights. The rules were signed in advance โ and a slow network can never crown the wrong machine.
Analogy: a lifeguard chair with a posted rota. The lifeguard
renews a sand-timer while on duty. If the timer runs ALL the way out, the #2 on the rota
waits one extra beat (and #3 waits two) before climbing up โ so a #3 who merely
heard late can never jump the queue. When #1 comes back, they wait for the timer's
boundary, then take the chair back. Every change is written in the logbook, in ink.
The control chain โ signed frames, appended only, never rewritten.
What am I looking at? The roster (who's #1, #2, #3) is a signed
frame minted in advance. Every tick the leader writes carries a short lease. Only
when a lease fully expires may the next rank act โ and rank r must wait (rโ1) extra grace
beats, so latency can't cause a coup: the laggy #3 just ends up waiting longer, never
jumping in early. When the old leader returns it defers until the current lease's
boundary, then writes a resumption frame. History is never edited โ you can scroll the
logbook and replay exactly who led when, and why. That's ยง3.5 โ proven in the paper's
five-scenario harness (A1โA5) plus a live two-hour lease.