# Public API
```rust
pub use kcode_k1_chat_codex_codec::{BoxValue, Call};
pub use kcode_k1_chat_state::{ChatBox, ToolCallId};
pub enum Arrival {
System(String), User(String), Attachment,
Return { tool_call_id: ToolCallId, result: Result<String, String> },
}
pub struct Start { pub job: u64, pub boxes: Vec<BoxValue> }
pub struct PreparedCall {
pub tool_call_id: ToolCallId,
pub name: String,
pub arguments: String,
}
pub enum Status { Running, Quiet, Stalled { message: String, restartable: bool } }
pub enum RestartError { NotStalled, NotRestartable }
pub struct ConversationState { /* private */ }
impl ConversationState {
pub fn new(session: [u8; 12]) -> Self;
pub fn recover(session: [u8; 12], boxes: Vec<ChatBox>, force: bool) -> Result<Self, String>;
pub fn boxes(&self) -> &[ChatBox];
pub fn status(&self) -> Status;
pub fn accept(&mut self, arrival: Arrival) -> Result<(), String>;
pub fn begin(&mut self) -> Result<Option<Start>, String>;
pub fn prepare_stage(&mut self, job: u64, text: String, values: Vec<BoxValue>) -> Result<Vec<PreparedCall>, String>;
pub fn complete(&mut self, job: u64, output: kcode_k1_codex_adapter::ShimOutput<BoxValue>) -> Result<(), String>;
pub fn fail(&mut self, job: u64, message: String, restartable_before_launch: bool);
pub fn restart(&mut self) -> Result<(), RestartError>;
}
```
`begin` opens scheduled inference and projects canonical boxes not yet submitted; it creates no Kennedy box. `prepare_stage` validates a complete ordered wave before changing state, then makes its calls canonical through one provider-free actor transition. It never executes tools. `complete` accepts terminal text only; calls belong exclusively to accepted stages.
Arrivals delegate to `ActorState`, whose active-round FIFO queue is released after completion. Recovery validates the supplied session on every canonical tool-call ID, resumes above the greatest recovered sequence, and reseeds a fresh native thread from the complete canonical history. A pre-call failure may be restarted; after a call wave, failure completes with empty text and halts nonrestartably.