# Open-format Codex conversation state 0.7.8
`ConversationState` is the deterministic owner of one open-format Codex conversation. It preserves delta-only same-thread input, full recovery/restart replay, provider stages, malformed native-call preservation, active-turn mailbox flushes, terminal responses, and restartable pre-launch failures.
`prepare_preflight` is a fresh-session-only operation. It allocates stable ToolCallIds, atomically appends ordered System Message and Tool Call boxes through Chat State without scheduling inference, makes those boxes part of the eventual first provider input, and returns each call's canonical BoxID, exact name, arguments and blocking mode. A session can be prepared only once and no provider round is opened.
`PreflightMode` is `Blocking` or `NonBlocking`. `PreflightItem` is either `SystemMessage { contents }` or `KtoolCall { name, arguments, mode }`. `PreparedPreflightCall` exposes `tool_call_id`, `call_box_id`, `name`, `arguments`, and `mode`.
`complete_recoverable_failure` converts one active failed provider operation into an ordinary terminal Agent Response and returns the conversation to `Quiet`, including when a mailbox flush was prepared but not committed. `reset_provider_context` is idle-only and rebuilds the next provider input from the complete canonical conversation so a replacement provider process can continue the same Chat without losing visible history. `halt_critical` installs a first-write-wins, non-restartable `Stalled` status for an integrity failure. These methods consume caller-selected typed policy; this crate does not classify or parse diagnostic strings.
External input, correlated Tool Messages and Results, stages, mailbox flushes, ordinary completion, recovery, status and restart retain their existing behavior. This crate owns no persistence, Ktool validation or execution, blocking gate, HTTP, provider process, migration, deployment, diagnostic storage, or retry policy.