docs(885): the handover clause states its own unprobed reachability, where the rule is read

The code banner and the test docstring say that whether act_runner on this
instance resolves `workflow_call` + `secrets: inherit` was not probed, and why
that is acceptable — it governs reachability today, not the guard's silence. The
record stated the clause without that bound, so a reader who meets the rule
through the catalog rather than through the file met a confidence claim the
source deliberately does not make.

Refs #885
Decisions-Edit: yes

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015QqCpYFsKgnAnx6jVwrKiV
This commit is contained in:
2026-09-05 15:15:43 +02:00
co-authored by Claude Fable 5.1
parent c325cd6ee4
commit d4c00f7567
@@ -97,7 +97,10 @@ faulted by name. So a `secrets:` key whose value is not a mapping now faults und
sentinel, judged on the VALUE SHAPE rather than on the word `inherit`, for the reason the residue
counter does not match `toJSON` by name. Unlike the spelling gaps this one is invisible to the text
cross-check for a reason no widening of `secret_refs` fixes — there is no text for its half to match
— so the clause reads the document only, and says so where it is defined.
— so the clause reads the document only, and says so where it is defined. Whether act_runner on this
instance resolves `workflow_call` + `secrets: inherit` at all was NOT probed (2026-09-05); that
governs reachability today, not the guard's silence, and the direction is the one every spelling row
already takes — an unsupported shape costs a spurious demand on a job nobody has written.
**The `if:` classifier is a PIN, not a parser.** Exactly one string —
`github.event_name != 'pull_request'` — takes a job off the route. Anything else, including