At startup, _schedule_resume_pending_sessions decided whether an
interrupted session was fresh enough to auto-resume by subtracting the
naive local last_resume_marked_at (or updated_at) from a naive local
datetime.now(). The marker is written by the previous gateway process,
so when a DST spring-forward falls between the two, the wall-clock
difference is one hour larger than the real elapsed time: a marker 20
minutes old measured as 80 minutes and the session was skipped by the
default 60-minute window. An offset-carrying marker would have raised
TypeError.
The check now goes through _is_fresh_gateway_interruption, the epoch
helper the per-turn path already uses on the same field. .timestamp()
reads a naive value as local time with that date's offset, which is how
it was written, and handles an aware value exactly. A non-positive
HERMES_AUTO_CONTINUE_FRESHNESS now disables the startup gate, as its
docstring says, instead of skipping every session.