kcode-k1-chat-thread-durable-state 0.4.10

Authorized durable state transitions for one K1 chat thread
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
# K1 chat-thread durable state

`DurableThread` is the synchronous, one-session state owner used by the session actor. It owns durable conversation transitions, bound Ktool authorization, and forwarding to Durable Turn; it owns no provider protocol, pricing, migration, boxes beyond Durable Turn, or asynchronous channel effects.

## Public contract

- `BoxId`, `BoxValue`, `ChatBox`, `PreparedCall`, `PreparedMailboxFlush`, `Status`, and `ToolCallId` retain their Durable Turn or chat-state contracts. `AccessContext`, `AccessPolicy`, and `ProfileId` retain their Chat Thread Ktools contracts. `EventRecord`, `ModelUsage`, and `TokenBreakdown` retain Durable Turn's provider-independent durable-event contracts; `events` clones records in order and `record_model_usage` forwards unchanged.
- `TransitionError` is `Unauthorized`, `NotStalled`, `NotRestartable`, or `Internal(String)`. `recover(session, kmap)` reconstructs with no authorization or Social facade; additive `recover_with_social(session, kmap, social)` configures Social Ktools. Both preserve the existing Durable Turn transition APIs and results.
- `accept_external_box` rejects `USER_MESSAGE_TYPE` with `Unauthorized` and otherwise delegates once to `accept_box`. `complete_with_terminal_response` completes once and returns the canonical terminal Agent Response box ID even when queued active-turn boxes follow it.
- `accept_user` and `restart` bind one exact context/profile/policy triple through `ChatThreadKtools`; the same triple is idempotent and a different triple is unauthorized before partial effects. A failed newly installed acceptance or restart clears authorization. `fail` and explicit `clear_authorization` clear dispatcher authorization while preserving session state.
- `launch_action` first rejects names absent from the KtoolDocs registry with `unknown Ktool`. It performs KtoolDocs stateless lookup and SendMessage durable append locally, and delegates CurrentTime, five Kmap names, and three Social names to `ChatThreadKtools`. Without Social composition, Social names return `social Ktools are unavailable`. Registered asynchronous or unwired names have a stable no-execution error; WebSearch remains session-actor owned and SetLaunchNode remains intentionally unwired.
- `SendMessage` accepts exactly `{"message":"<nonempty string>"}`, durably appends one visible Agent Message, and returns `success`; malformed arguments return `invalid SendMessage arguments` without appending. Provider stages, prepared input, recovery, mailbox flush, event ordering, and all other existing Durable Turn behavior remain unchanged.

For a worst-practical session history, forwarding `events` is linear in the durable record count and clones the returned records; recording model usage performs Durable Turn's synchronous persistence transaction. `accept_external_box` performs one type comparison plus `accept_box`'s synchronous work. `complete_with_terminal_response` performs `complete`'s synchronous work plus one indexed box lookup.