aboutsummaryrefslogtreecommitdiff
path: root/claude-rules/knowledge-base.md
diff options
context:
space:
mode:
authorCraig Jennings <c@cjennings.net>2026-07-19 05:01:51 -0500
committerCraig Jennings <c@cjennings.net>2026-07-19 05:01:51 -0500
commitc6383e97f7dc1113959a000f6273d30c2f20415e (patch)
tree72732c52a66c25694c4062594ec841d158844422 /claude-rules/knowledge-base.md
parentccc9c268a187daebfeab9c18418e9a9629f9acc8 (diff)
downloadrulesets-c6383e97f7dc1113959a000f6273d30c2f20415e.tar.gz
rulesets-c6383e97f7dc1113959a000f6273d30c2f20415e.zip
feat(sentry): wire the roam writers and wrap-up guard for sentry
Phase 3 of the sentry supervisor: reconcile the existing roam writers and wrap-up so sentry's locks actually guard something, and its shutdown has one enforced entry point. The roam-write lock only helps if every roam writer takes it, so both writers now do. knowledge-base.md's write recipe and inbox.org core §5 acquire the roam-write lock around their edit and trigger roam-sync instead of committing themselves. That closes a gap the one-git-owner rule already implied but the KB recipe still violated: the recipe told agents to run git add -A && commit && push against a tree that's chronically dirty from live captures, which could sweep an in-flight capture into a stray commit. roam-sync stays the roam repo's only committer. Agents edit-plus-trigger under the lock, and roam-sync.sh's header now states that contract instead of the old "agents commit inline" note. Both writers degrade as the spec settled: an absent agent-lock proceeds unlocked (today's behavior), and only a present helper reporting the lock busy after its bounded wait defers or surfaces. wrap-it-up.org gains a Step 0 that refuses while sentry is live. It checks the single-runner lock and points at "stop sentry" rather than archiving the anchor and tearing down the buffer under a still-firing loop. Both files derive the lock name the same way (sentry-<repo-basename>), so the guard and the engine agree. triage-intake.org notes that it also runs as sentry's triage pass under the no-approvals contract, with its trigger phrases unchanged.
Diffstat (limited to 'claude-rules/knowledge-base.md')
-rw-r--r--claude-rules/knowledge-base.md21
1 files changed, 20 insertions, 1 deletions
diff --git a/claude-rules/knowledge-base.md b/claude-rules/knowledge-base.md
index d61ef03..478d5b8 100644
--- a/claude-rules/knowledge-base.md
+++ b/claude-rules/knowledge-base.md
@@ -43,7 +43,26 @@ A write is one node per fact, under `agents/`, roam-valid so Craig's org-roam in
<the fact, with [[id:...]] links to related nodes>
```
-Pull before writing, commit and push after (`git -C ~/org/roam add -A && git commit && git push`) — same session discipline as any repo. Never edit Craig's hand-authored nodes; link to them. This write autonomy is scoped to the KB alone — it is not permission to send email, comment on tickets, or post to any public or external channel.
+Pull before writing (`git -C ~/org/roam pull --ff-only`, read-only). Then acquire the roam-write lock, write the node, and trigger roam-sync to commit and push — roam-sync stays the roam repo's only committer (the 2026-06-24 one-git-owner rule). The tree is chronically dirty from live captures, so an agent's own `git add -A && commit` could sweep an in-flight capture into a stray commit; edit-plus-trigger avoids that. Never edit Craig's hand-authored nodes; link to them. This write autonomy is scoped to the KB alone — it is not permission to send email, comment on tickets, or post to any public or external channel.
+
+The write block, with the lock and the trigger:
+
+```sh
+# Acquire the roam-write lock so a concurrent sentry pass or inbox writer can't
+# race this write. Callers pass a name; agent-lock owns the path (tmpfs).
+if [ -x .ai/scripts/agent-lock ]; then
+ if ! .ai/scripts/agent-lock acquire roam-write --wait; then
+ # Busy after the bounded wait — surface and stop, don't write unlocked.
+ echo "roam-write lock held by another writer; try again shortly" >&2
+ exit 1
+ fi
+fi
+# ... write ~/org/roam/agents/<ts>-<slug>.org ...
+systemctl --user start roam-sync.service # roam-sync commits + pushes
+[ -x .ai/scripts/agent-lock ] && .ai/scripts/agent-lock release roam-write
+```
+
+Degrade gracefully when `agent-lock` isn't installed (an older checkout mid-sync): the guard above is skipped and the write proceeds unlocked — today's behavior. Only a *present* helper reporting the lock busy after its bounded wait stops the write; an *absent* helper never blocks it.
## What goes in, what stays out