UncommittedConfigEntry
RaftEngine.onChangeMembership guard 4: the log's last config entry is still uncommitted (lastConfigIndex > currentCommitIndex).
Log-grounded, so it also covers the inherited paths where pendingConfigChange is null because no local caller exists — the Simple(C_new) that finalizeInheritedCommittedJoint appends on election, and the one onConfigCommitted appends when a leader inherits an in-flight Joint. Adopt-on-append flips membershipState to Simple the instant that entry is appended, so without this guard a change arriving in the window before it commits passes both the settled-Simple and pendingConfigChange checks and can hand its caller a config that was never the committed one.