Looks good overall.
I think I have questions on the section "Protocol Upgrade Changes" that is a bit light on details:
* more details are needed on "merges need to be restarted", specifically I think you're implying that the inputs for any merge are always available by simply looking at the latest bucket list (so giving some idea of how things work would help)
* more details are needed on how we can mitigate the "picking the right time" (including quantifying requirements around that "right time")
* nit: I don't think we have a concept of "in-memory merges"
Nicolas