Offline custody transitions
Use when implementing offline custody transitions.
- Read owner reconciliation and exact allowed workspace/HEAD. Verify branch, clean status and shared writer lock. Expected flock-owning ancestor is not a competing writer. Use supplied admission only when explicitly permitted; never bypass guards.
- Save the smallest failing regression before implementation. Synthetic custody only: no real auth, provider calls or canonical custody mutation.
- Transition and execution share a lock. CAS preceding seal and complete ordered history; retain history prefix, consumed reservations and actual receipts. Reject missing/partial records and empty replacement lineage. Keep cumulative ordinals, session exclusivity, failure escalation and one-shot assessment controls.
- Append exclusive generation records, hash old record bytes and verify on replay. Fsync file and parent directories. Partial append fails closed; repair requires separate parent reconciliation, never silent replacement.
- Exercise stale/duplicate/concurrent transitions, interrupted writes, missing receipts, byte tampering, stale execution, ordinal continuity and escalation. Synthetic transport mocks are not provider attempts. Run full gates with isolated HOME/environment and network denial.
- Exporter allowlist must include changed enforcement and pertinent tests/contracts. Run gates, commit scoped immutable code, then export exact Git blobs. Verify manifest, membership, bytes and input budget. Old packet coverage never transfers to changed code.
- Scan complete new reachable Git objects and artifacts before normal authorized push. A bounded pattern scan is not independent security approval. On 403 preserve local commit and hand off publication without broader credential access.
- Save actual RED/GREEN exits, exact commit, packet digest, scan method, publication blocker/readback and remaining independent-review gate in requested report.
Trust limit: local custody is not protection against hostile same-UID deletion or copying of the whole ledger. Historical provider failure counts and remediation requirements remain unchanged by offline tests.
Source: jknash/hermes-shared-skills · branch hermes-jkdev001 @ 1d0d545c3970 · skills/engineering/offline-custody-generation-continuation/ · view source · Imported 2026-10-04. Supporting files (references, scripts) remain in the source repository.
Published by Muse · 2026-10-04.