.github-private#936 asks that the rule which merged into adopt-claude-harness.sh (via .github-private#941) also land in this repo's claude/context.md. This issue records the insertion point, the content, and — the part worth not re-deriving — why it cannot be a single PR.
Filed from a session whose token is scoped to this repo only (.github-private → 403), so it could neither comment on #936 nor open the private half. Nothing here is claimed; it is a record, not work in progress.
Insertion point
claude/context.md line 37, immediately after the door-1 line:
1. `claim-ticket.yml` (`bounded-systems/.github`, workflow_dispatch: repo,
issue, claimant, human_authorization) — the real door, lease-backed.
Reachable only if `.github` was attached at session creation
(`add_repo` refuses it). ← new text goes here
What the text must say
Three claims, all of which a session hits as a wall today:
- A session that needs a dot-prefixed repo must be created with it as
source_url — add_repo refuses dot-prefixed names mid-session, so the capability cannot be added later.
create_session takes one source. Work spanning .github and .github-private therefore needs two sessions, not one.
- A session spawned with no source has no API scope at all — not reduced scope, none.
Copy the bytes; do not re-author them
The canonical text is the one already merged into adopt-claude-harness.sh in .github-private (#941). It must be copied verbatim, not paraphrased from this issue — see the next section for why an approximation fails a lint rather than merely reading differently.
Why this is a sequenced pair, not one PR
The public copy here is canonical — .claude/inject-org-context.sh:3, "Canonical source since .github#175: bounded-systems/.github -> claude/context.md" — and it is what gets served to sessions with no checkout (boot.bounded.tools/public-context.md, same script, line 124).
.github-private pins its copy byte-for-byte against this one. This repo names that check itself, in the drift hint at .claude/inject-org-context.sh:88:
To settle it, run .github-private/.claude/context-parity.sh — it compares against bounded-systems/.github rather than against the disk.
Consequences, in order:
- Public-first is the only correct order. A sibling session tried the private half first;
context-parity.sh went red against an unchanged canonical source, and it reverted. That failure confirms the direction rather than contradicting it — the mirror cannot lead.
- Merging the public half alone turns
.github-private's lint red until the private sync lands. The window between the two merges is a red-CI window in another repo, so the private PR should be ready to merge before the public one goes in, not started after.
- Each half needs its own session, created with that repo as its single
source_url — which is the very rule the text is documenting.
Suggested sequencing
- Session A (
source_url = .github): open the PR adding the sentence at line 37. Hold it.
- Session B (
source_url = .github-private): prepare the parity sync PR against the exact bytes from (1).
- Merge (1), then (2) immediately.
Refs .github-private#936, .github-private#941, .github#175.
.github-private#936 asks that the rule which merged intoadopt-claude-harness.sh(via.github-private#941) also land in this repo'sclaude/context.md. This issue records the insertion point, the content, and — the part worth not re-deriving — why it cannot be a single PR.Filed from a session whose token is scoped to this repo only (
.github-private→403), so it could neither comment on #936 nor open the private half. Nothing here is claimed; it is a record, not work in progress.Insertion point
claude/context.mdline 37, immediately after the door-1 line:What the text must say
Three claims, all of which a session hits as a wall today:
source_url—add_reporefuses dot-prefixed names mid-session, so the capability cannot be added later.create_sessiontakes one source. Work spanning.githuband.github-privatetherefore needs two sessions, not one.Copy the bytes; do not re-author them
The canonical text is the one already merged into
adopt-claude-harness.shin.github-private(#941). It must be copied verbatim, not paraphrased from this issue — see the next section for why an approximation fails a lint rather than merely reading differently.Why this is a sequenced pair, not one PR
The public copy here is canonical —
.claude/inject-org-context.sh:3, "Canonical source since .github#175: bounded-systems/.github -> claude/context.md" — and it is what gets served to sessions with no checkout (boot.bounded.tools/public-context.md, same script, line 124)..github-privatepins its copy byte-for-byte against this one. This repo names that check itself, in the drift hint at.claude/inject-org-context.sh:88:Consequences, in order:
context-parity.shwent red against an unchanged canonical source, and it reverted. That failure confirms the direction rather than contradicting it — the mirror cannot lead..github-private's lint red until the private sync lands. The window between the two merges is a red-CI window in another repo, so the private PR should be ready to merge before the public one goes in, not started after.source_url— which is the very rule the text is documenting.Suggested sequencing
source_url=.github): open the PR adding the sentence at line 37. Hold it.source_url=.github-private): prepare the parity sync PR against the exact bytes from (1).Refs
.github-private#936,.github-private#941,.github#175.