feat(dowel): give engineer the build surface and name it the owner of its own puts #966

Closed
coilysiren wants to merge 1 commit from aos/claude/dowel-site-work into main
Owner

Two changes the demo lane cannot run without.

roles.kdl gains an engineer entry. The role had none, so the bundle composed the
roster identity alone: six skills, zero catalogue sources, no coding, delivery,
diagnosis, or verification doctrine. A lane staged to do work on camera with that
bundle defers every task it was staged to perform.

The ops-* entries are deliberate rather than borrowed. There is no operator seat
behind this lane during the session, so change risk, diagnosis, and remediation
are its own doctrine here. Entries are globs because DeniedComposedSkills errors
on a denied skill named exactly and silently drops one reached by a pattern, and
kai-engineering-voice and tooling-cross-repo-infra both sit under surfaces this
set reaches.

Measured before landing: about 113 KB of skill bodies against creator's 48 KB, so
the flip adds roughly 64 KB to a prefix measured at 116 KB. Recorded rather than
hidden. deploy#932 decided that prefix problem is a caching failure rather than a
roster size, so the set is not trimmed on count alone.

site-work.md then names the winner instead of leaving it to section order, which
is the pattern composedVoicePolicy already sets for voice. The composed bundle
carries boundary-modify-live-system, which hands running-system changes to
DevOps. There is no DevOps seat here, and the site verbs are this lane's own
granted surface, so the boundary does not reach them and this file wins where
they disagree. It also closes the size-based escape: fixing a word or a heading
is the job, and too-small-to-put and too-live-to-touch are the same refusal.

The honest limit stays the tool list rather than the org chart. Rollback,
serving, and nginx have no verb here, so they are declined as absent tools and
never as another role's work.

Refs coilyco-bridge/deploy#658, coilyco-bridge/deploy#932

Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com
Co-authored-by: Angie coilyco-ops@coilysiren.me
Co-authored-by: Claude noreply@anthropic.com

Two changes the demo lane cannot run without. roles.kdl gains an engineer entry. The role had none, so the bundle composed the roster identity alone: six skills, zero catalogue sources, no coding, delivery, diagnosis, or verification doctrine. A lane staged to do work on camera with that bundle defers every task it was staged to perform. The ops-* entries are deliberate rather than borrowed. There is no operator seat behind this lane during the session, so change risk, diagnosis, and remediation are its own doctrine here. Entries are globs because DeniedComposedSkills errors on a denied skill named exactly and silently drops one reached by a pattern, and kai-engineering-voice and tooling-cross-repo-infra both sit under surfaces this set reaches. Measured before landing: about 113 KB of skill bodies against creator's 48 KB, so the flip adds roughly 64 KB to a prefix measured at 116 KB. Recorded rather than hidden. deploy#932 decided that prefix problem is a caching failure rather than a roster size, so the set is not trimmed on count alone. site-work.md then names the winner instead of leaving it to section order, which is the pattern composedVoicePolicy already sets for voice. The composed bundle carries boundary-modify-live-system, which hands running-system changes to DevOps. There is no DevOps seat here, and the site verbs are this lane's own granted surface, so the boundary does not reach them and this file wins where they disagree. It also closes the size-based escape: fixing a word or a heading is the job, and too-small-to-put and too-live-to-touch are the same refusal. The honest limit stays the tool list rather than the org chart. Rollback, serving, and nginx have no verb here, so they are declined as absent tools and never as another role's work. Refs coilyco-bridge/deploy#658, coilyco-bridge/deploy#932 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: Angie <coilyco-ops@coilysiren.me> Co-authored-by: Claude <noreply@anthropic.com>
feat(dowel): give engineer the build surface and name it the owner of its own puts
Some checks failed
ci / image-build (pull_request) Failing after 5s
ci / test (pull_request) Failing after 1m6s
ci / publish-echo-image (pull_request) Has been skipped
ci / publish-observed (pull_request) Has been skipped
83707e57cd
Two changes the demo lane cannot run without.

roles.kdl gains an engineer entry. The role had none, so the bundle composed the
roster identity alone: six skills, zero catalogue sources, no coding, delivery,
diagnosis, or verification doctrine. A lane staged to do work on camera with that
bundle defers every task it was staged to perform.

The ops-* entries are deliberate rather than borrowed. There is no operator seat
behind this lane during the session, so change risk, diagnosis, and remediation
are its own doctrine here. Entries are globs because DeniedComposedSkills errors
on a denied skill named exactly and silently drops one reached by a pattern, and
kai-engineering-voice and tooling-cross-repo-infra both sit under surfaces this
set reaches.

Measured before landing: about 113 KB of skill bodies against creator's 48 KB, so
the flip adds roughly 64 KB to a prefix measured at 116 KB. Recorded rather than
hidden. deploy#932 decided that prefix problem is a caching failure rather than a
roster size, so the set is not trimmed on count alone.

site-work.md then names the winner instead of leaving it to section order, which
is the pattern composedVoicePolicy already sets for voice. The composed bundle
carries boundary-modify-live-system, which hands running-system changes to
DevOps. There is no DevOps seat here, and the site verbs are this lane's own
granted surface, so the boundary does not reach them and this file wins where
they disagree. It also closes the size-based escape: fixing a word or a heading
is the job, and too-small-to-put and too-live-to-touch are the same refusal.

The honest limit stays the tool list rather than the org chart. Rollback,
serving, and nginx have no verb here, so they are declined as absent tools and
never as another role's work.

Refs coilyco-bridge/deploy#658, coilyco-bridge/deploy#932

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Angie <coilyco-ops@coilysiren.me>
Co-authored-by: Claude <noreply@anthropic.com>
Member

Flagging three things on this branch's agent/compose/roles.kdl, because main already carries a different engineer grant and this reverts it.

1. It drops the room-craft half that #956 merged. main today grants tooling-sirens-dowel-contract, tooling-discord-community-host, personal-preference-*, and writing-* alongside the engineering set. This branch's graph has none of them. That is the register change Kai asked to avoid on the livestream lane, arriving by a different route than response_style did.

2. The four private-catalogue names are back, and they fail the expander rather than being dropped by the deny list:

role "engineer": pattern "tooling-repo-baseline" matches nothing in <catalogue>
exit status 1

tooling-repo-baseline, tooling-browser-routing, tooling-forgejo-issue-counts, and tooling-triage-cascade live in agentic-os-kai, and request.kdl declares one source, aos-public. The comment above the block says globs let the deny list drop a match, which is true, but these four are exact names and an exact name errors. #964 tracks it. The run stops at the first, so the other three are untested.

3. agent/rendered/roles/engineer.bundle.txt still says Skills: 6 on this branch, against a graph that would admit roughly 33. role-drift-check compares the tracked snapshot to a fresh compile, so it fails on that too, after the expander error clears.

Worth a just role-drift-check before merge. Note also that #963 landed the catalogue-clone cache fix, so image-build now clones a live catalogue rather than a frozen one, which means a graph error here surfaces where it did not before.

Separately, and useful for whatever grant lands: #969 makes the deferred references actually reachable. Until it merges, the 96,080 bytes of coding-* references are advertised in the prompt and refused by read_skill, so a bundle carrying coding-* spends tool rounds discovering that. With #969 in, that surface works as designed.

Flagging three things on this branch's `agent/compose/roles.kdl`, because `main` already carries a different engineer grant and this reverts it. **1. It drops the room-craft half that #956 merged.** `main` today grants `tooling-sirens-dowel-contract`, `tooling-discord-community-host`, `personal-preference-*`, and `writing-*` alongside the engineering set. This branch's graph has none of them. That is the register change Kai asked to avoid on the livestream lane, arriving by a different route than `response_style` did. **2. The four private-catalogue names are back**, and they fail the expander rather than being dropped by the deny list: ``` role "engineer": pattern "tooling-repo-baseline" matches nothing in <catalogue> exit status 1 ``` `tooling-repo-baseline`, `tooling-browser-routing`, `tooling-forgejo-issue-counts`, and `tooling-triage-cascade` live in `agentic-os-kai`, and `request.kdl` declares one source, `aos-public`. The comment above the block says globs let the deny list drop a match, which is true, but these four are exact names and an exact name errors. #964 tracks it. The run stops at the first, so the other three are untested. **3. `agent/rendered/roles/engineer.bundle.txt` still says `Skills: 6`** on this branch, against a graph that would admit roughly 33. `role-drift-check` compares the tracked snapshot to a fresh compile, so it fails on that too, after the expander error clears. Worth a `just role-drift-check` before merge. Note also that #963 landed the catalogue-clone cache fix, so `image-build` now clones a live catalogue rather than a frozen one, which means a graph error here surfaces where it did not before. Separately, and useful for whatever grant lands: #969 makes the deferred references actually reachable. Until it merges, the 96,080 bytes of `coding-*` references are advertised in the prompt and refused by `read_skill`, so a bundle carrying `coding-*` spends tool rounds discovering that. With #969 in, that surface works as designed.
Member

Closing rather than resolving the conflict. Checked file by file against d887bd8, and this branch carries nothing main does not already have.

  • agent/compose/roles.kdl - this is the pre-union engineering-only half, against base a948fc8. #956 landed the union of it and #961's room-craft. Resolving in favour of this branch would drop the room-craft globs and reinstate tooling-repo-baseline, tooling-browser-routing, tooling-forgejo-issue-counts, and tooling-triage-cascade, which live in agentic-os-kai and fail the bake with pattern "tooling-repo-baseline" matches nothing. See #964.
  • .agents/skills/sirens-dowel/references/site-work.md - older than main's. It describes a generic "list the pages, read a page, put a page" surface. Main describes the quire MCP by its real verbs, list_page / get_page / set_page, after 695ea7b matched the prose to what actually shipped. Merging this regresses the prose to a surface that does not exist.

Against current main the branch is a ~3,500 line revert: it predates internal/coalesce, internal/ingest, cmd/sirens-echo-bridge, #947's config work, and #963's catalogue-clone fix.

Reopenable if I have missed something, but I diffed both files directly and the delta is empty in the direction that matters.

Closing rather than resolving the conflict. Checked file by file against `d887bd8`, and this branch carries nothing main does not already have. * **`agent/compose/roles.kdl`** - this is the pre-union engineering-only half, against base `a948fc8`. #956 landed the union of it and #961's room-craft. Resolving in favour of this branch would drop the room-craft globs and reinstate `tooling-repo-baseline`, `tooling-browser-routing`, `tooling-forgejo-issue-counts`, and `tooling-triage-cascade`, which live in `agentic-os-kai` and fail the bake with `pattern "tooling-repo-baseline" matches nothing`. See #964. * **`.agents/skills/sirens-dowel/references/site-work.md`** - older than main's. It describes a generic "list the pages, read a page, put a page" surface. Main describes the quire MCP by its real verbs, `list_page` / `get_page` / `set_page`, after 695ea7b matched the prose to what actually shipped. Merging this regresses the prose to a surface that does not exist. Against current main the branch is a ~3,500 line revert: it predates `internal/coalesce`, `internal/ingest`, `cmd/sirens-echo-bridge`, #947's config work, and #963's catalogue-clone fix. Reopenable if I have missed something, but I diffed both files directly and the delta is empty in the direction that matters.
coilyco-ops closed this pull request 2026-08-18 19:16:01 +00:00
Some checks failed
ci / image-build (pull_request) Failing after 5s
ci / test (pull_request) Failing after 1m6s
ci / publish-echo-image (pull_request) Has been skipped
ci / publish-observed (pull_request) Has been skipped

Pull request closed

Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
coilyco-gaming/sirens-echo!966
No description provided.