If at the time of FAILOVER the designated backup node is not the most advanced node, it can lead to an endless restart loop. I have a fix for this that I will attach later.
Created attachment 185 [details] Patch to fix bug 318
http://git.postgresql.org/gitweb/?p=slony1-engine.git;a=commit;h=9155148fbc8fc93172639eb172d692ffc5cb9517 Fix was included in 2.2.1