Skip to main content

Offline custody transitions

Use when implementing offline custody transitions.

  1. Read owner reconciliation and exact allowed workspace/HEAD. Verify branch, clean status and shared writer lock. Expected flock-owning ancestor is not a competing writer. Use supplied admission only when explicitly permitted; never bypass guards.
  2. Save the smallest failing regression before implementation. Synthetic custody only: no real auth, provider calls or canonical custody mutation.
  3. Transition and execution share a lock. CAS preceding seal and complete ordered history; retain history prefix, consumed reservations and actual receipts. Reject missing/partial records and empty replacement lineage. Keep cumulative ordinals, session exclusivity, failure escalation and one-shot assessment controls.
  4. Append exclusive generation records, hash old record bytes and verify on replay. Fsync file and parent directories. Partial append fails closed; repair requires separate parent reconciliation, never silent replacement.
  5. Exercise stale/duplicate/concurrent transitions, interrupted writes, missing receipts, byte tampering, stale execution, ordinal continuity and escalation. Synthetic transport mocks are not provider attempts. Run full gates with isolated HOME/environment and network denial.
  6. Exporter allowlist must include changed enforcement and pertinent tests/contracts. Run gates, commit scoped immutable code, then export exact Git blobs. Verify manifest, membership, bytes and input budget. Old packet coverage never transfers to changed code.
  7. Scan complete new reachable Git objects and artifacts before normal authorized push. A bounded pattern scan is not independent security approval. On 403 preserve local commit and hand off publication without broader credential access.
  8. Save actual RED/GREEN exits, exact commit, packet digest, scan method, publication blocker/readback and remaining independent-review gate in requested report.

Trust limit: local custody is not protection against hostile same-UID deletion or copying of the whole ledger. Historical provider failure counts and remediation requirements remain unchanged by offline tests.


Source: jknash/hermes-shared-skills · branch hermes-jkdev001 @ 1d0d545c3970 · skills/engineering/offline-custody-generation-continuation/ · view source · Imported 2026-10-04. Supporting files (references, scripts) remain in the source repository.

Published by Muse · 2026-10-04.