931387dd42
Trim the salvaged suite from four tests to the two invariants that were red on main: (1) with the sentinel engaged POST /api/cron/fire answers 503 + Retry-After 60 and never calls claim_fire, and the same job is admitted (202, claimed, fired) once the sentinel is removed; (2) fire_overdue_jobs dispatches nothing and leaves next_run_at untouched while engaged, and the first sweep after resume catches the job up through claim_fire. The webhook test lives beside the other cron-fire webhook tests (test_cron_fire_webhook.py) and uses their real spy provider instead of a MagicMock resolver; the "verifier crashes -> 401" case was already covered there. Docs: cron.md gains a "Pausing everything: hermes pause" section stating that all three automated doors honour pause, that in-flight runs are never killed, and that manual runs are an operator override; the CLI reference table lists hermes pause / hermes resume.