Currently, if HR goes down before the replication master does, or between the last check on the replication master and the time that HR comes back up, HR will be unable to decide whether it is safe to fail over and will not do so with some timings. This is probably the safest route for now, but we should address it in the future in order to cope with "network down" events.