From d4c00f75679f4b2d38fadac97f4285cb336feb0d Mon Sep 17 00:00:00 2001 From: Timothy Date: Sat, 5 Sep 2026 12:21:54 +0200 Subject: [PATCH] docs(885): the handover clause states its own unprobed reachability, where the rule is read MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The code banner and the test docstring say that whether act_runner on this instance resolves `workflow_call` + `secrets: inherit` was not probed, and why that is acceptable — it governs reachability today, not the guard's silence. The record stated the clause without that bound, so a reader who meets the rule through the catalog rather than through the file met a confidence claim the source deliberately does not make. Refs #885 Decisions-Edit: yes Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_015QqCpYFsKgnAnx6jVwrKiV --- .../records/ci/pr-route-carries-no-stored-credential.md | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/docs/decisions/records/ci/pr-route-carries-no-stored-credential.md b/docs/decisions/records/ci/pr-route-carries-no-stored-credential.md index 1c964cbce..6c87123e8 100644 --- a/docs/decisions/records/ci/pr-route-carries-no-stored-credential.md +++ b/docs/decisions/records/ci/pr-route-carries-no-stored-credential.md @@ -97,7 +97,10 @@ faulted by name. So a `secrets:` key whose value is not a mapping now faults und sentinel, judged on the VALUE SHAPE rather than on the word `inherit`, for the reason the residue counter does not match `toJSON` by name. Unlike the spelling gaps this one is invisible to the text cross-check for a reason no widening of `secret_refs` fixes — there is no text for its half to match -— so the clause reads the document only, and says so where it is defined. +— so the clause reads the document only, and says so where it is defined. Whether act_runner on this +instance resolves `workflow_call` + `secrets: inherit` at all was NOT probed (2026-09-05); that +governs reachability today, not the guard's silence, and the direction is the one every spelling row +already takes — an unsupported shape costs a spurious demand on a job nobody has written. **The `if:` classifier is a PIN, not a parser.** Exactly one string — `github.event_name != 'pull_request'` — takes a job off the route. Anything else, including