Fencing tokens stop a deposed leader
A primary that has been replaced without knowing it will keep trying to write. Fencing stops it at the storage layer: each grant of leadership carries a number that only increases, and storage refuses any write whose number is lower than one it has already accepted.
The deposed leader cannot simply be told to stop. It may be cut off, as in a partition, or merely paused. Kleppmann's example is a garbage-collection pause that outlasts a lease, after which the process wakes and writes as though it still held the lock. Burns describes the same hazard on an overscheduled machine whose processor stalls for minutes. Checking the lease just before writing narrows the window without closing it, since the lease can expire between the check and the write.
So the check moves to the receiver. Burns has the recipient validate the current owner and a resource version sent with each request; Kleppmann's fencing token is the same idea, with a ZooKeeper zxid as the number. Such numbers come from stores built on consensus, which hand out ownership one holder at a time. Storage must actually enforce the check, or the defence against split brain exists only on paper.