Make MCP retrieval and writes graph aware - #64
blast-hardcheese wants to merge 4 commits into
Conversation
There was a problem hiding this comment.
Confidence Score: 1/5
Summary
Extends MCP retrieval and writes across project and global graphs, but global policy isolation and reference round-tripping have reproducible defects. Secondary-store error handling and grounding warnings also need correction.
Important Files Changed
| File | Overview |
|---|---|
| README.md | Documents cross-graph retrieval and write routing. |
| src/kindex/config.py | Preserves the user-level data directory before project overrides. |
| src/kindex/mcp_server.py | Adds cross-graph discovery and routing with policy-isolation and reference-handling defects. |
| src/kindex/store.py | Adds read-only connections; cleanup masks profile-mismatch errors. |
| src/kindex/tasks.py | Formats graph-qualified task references. |
| src/kindex/vectors.py | Checks existing vector compatibility without schema writes. |
| tests/test_mcp_cross_graph.py | Tests basic routing but misses policy isolation, aliases, dependency round-trips, and secondary-store failures. |
|
Independent review at head Does it fix the two-store defect? No.Reproduced from inside first. Three stores on this machine:
Mechanical cause, And the file that flips the switch is created by a different lane: At this PR's head:
Blocking1. Two harms. Ordering changes for all existing users with no flag and no migration — and the PR's risk note says reordering happens "relative to a single-graph search", which is the opposite of what it does. And the 2. Default writes still land in the store the reader will not read. 3. A git-tracked A cloned repository can destroy the additive-immutability invariant that High4. A stale global graph breaks project-only operations with a protocol error. 5. Profile mismatch raises Medium and below6. A routed global write permanently stamps the user's primary database ( 7. Retrieval containment changes with no opt-out: 8. Grounding verdicts dropped for global hits — 9. 10. Global task All six Adapt findings are real. I disagree with their severity ordering — they rated the Tests
Nothing would fail if a write went to the wrong store. Absent: a default What this gets rightThe diagnosis is correct and the missing concept is named in the right place: the MCP surface had one implicit store and no vocabulary for a second, and It refuses rather than fakes the impossible case. SQLite edges can't span databases, and instead of inventing a shadow edge table or silently dropping the link, the cross-store paths fail with an explicit message. That's the correct answer. The read-only secondary store is defensively right: The hard boundary is preserved — And the comment at Gate item 1 behind Verdict: CHANGES_REQUESTEDRight diagnosis, right primitive — but it doesn't fix the live defect, it silently changes search ranking for every existing user including single-graph ones, and it lets a cloned repo's Upstream fixes worth making regardless of this PR
|
Summary
edit_policyand other local overrides out of the global graph. Secondary reads use SQLite read-only mode and never stamp the global database.Graph identity boundary
Repository identity can group related worktrees for future discovery, but it does not authorize writes to a sibling worktree graph. Broader discovery is outside this PR. A future feature needs persistent database identity plus a live worktree or configured-global binding. Git archive cannot recreate an untracked
.kin/localdatabase.Validation
tests/suite on the final code: 2,914 passed, 4 skipped, 9 subtests passed. Focused runs covered the cross-graph/profile regressions (70 passed) and the existing title-collision contract (22 passed). Tests used Node 24 with the ambient Codex session ID cleared.kin policy check --event pre-commitandgit diff --checkpass.Risk notes