Skip to content

fix(composition): read catalogs from the session's tenant graph - #28

Merged
Knucklessg1 merged 1 commit into
mainfrom
fix/tenant-graph-composition
Oct 6, 2026
Merged

Knucklessg1 merged 1 commit into
mainfrom
fix/tenant-graph-composition

Conversation

@Knucklessg1

Copy link
Copy Markdown
Member

Summary

graph-os main crashed at startup against agent-utilities main with PermissionError: A graph-scoped view cannot retarget the verified GraphSession:

  • Catalog composition built views for the bare tenant id (homelab).
  • The verified process session targets AU's tenant graph (tenant__homelab____commons__).
  • AU graph views refuse a session aimed at any other graph.

Changes:

  • Composition and the graph_rlm client now use the session's own graph.
  • GeneratedFleetCatalogPort takes tenant_graph and an injected bind_graph. Each generated read runs under the verified session narrowed to its graph: the tenant graph, or __commons__ for the server registry. This is the narrowing gateway/graph_api.py already uses. The adapter stays free of AU imports.

Evidence

  • Reproduced in a debug pod running the production image with main-branch sources. With this change, startup gets past composition to the next fresh-store prerequisite (the tenant graph and semantic packs are not provisioned yet, which is tracked separately).
  • Tests updated: tests/fleet/test_epistemic_catalog_adapter.py asserts every read is narrowed to the graph it targets, and tests/mcp_server/test_catalog_composition.py asserts the tenant graph is used. ruff and mypy are clean on the changed files. The pre-push gates passed.

🤖 Generated with Claude Code

graph-os main could not start against agent-utilities main: catalog
composition built graph views for the bare tenant id ("homelab") while
the verified process session targets AU's tenant graph
("tenant__homelab____commons__"), and AU graph views refuse any session
aimed at another graph ("A graph-scoped view cannot retarget the verified
GraphSession").

- Composition and the graph_rlm client use the session's own graph.
- The fleet catalog port receives the tenant graph and a graph binder,
  and runs each generated read under the verified session narrowed to
  the read's graph (tenant graph, or __commons__ for the server
  registry), the same narrowing the REST gateway already uses.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@Knucklessg1
Knucklessg1 merged commit 3a8b638 into main Oct 6, 2026
4 checks passed
@Knucklessg1
Knucklessg1 deleted the fix/tenant-graph-composition branch October 6, 2026 14:33
@Knucklessg1
Knucklessg1 restored the fix/tenant-graph-composition branch October 6, 2026 15:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant