e730deedd1
Every participant gateway can now keep a durable copy of a hosted room's ordered log and continue the room when its authority host is gone: - gateway/hosted_room_replicas.py: replica store in root state.db. ingest_page() persists authority-stamped groups.log pages idempotently, refusing sequence gaps and authority-epoch regressions. promote_replica() continues the room locally at epoch+1 with a lineage-proving authority.claimed event; the stale owner is fenced everywhere the claim replicates. demote_room() lets a returning stale authority fence itself (authority.lost) upon observing a newer epoch, killing split-brain writes. - tui_gateway/methods_groups.py: groups.replicate / groups.replica_state / groups.promote / groups.demote RPC surface. Promotion requires confirm=true — storage decides HOW takeover is atomic and provable, the caller (user action now, lease/quorum driver later) decides WHEN it is safe, matching the boundary blessed on #97681. Validation: 20 new tests incl. a full failover round-trip (A hosts, B replicates incrementally, A dies, B promotes with complete history, A returns demoted and fenced); 69 total across the hosted-rooms area; E2E with two real gateway stores and real install identities.