# K1 chat-thread durable state
`DurableThread` is the synchronous, one-session state owner used by the session actor. It owns durable conversation transitions, bound action authorization, and forwarding to Durable Turn; it owns no provider protocol, pricing, migration, boxes beyond Durable Turn, or asynchronous channel effects.
## Public contract
- `BoxId`, `BoxValue`, `ChatBox`, `PreparedCall`, `PreparedMailboxFlush`, `Status`, and `ToolCallId` retain their Durable Turn or chat-state contracts. `AccessContext`, `AccessPolicy`, and `ProfileId` retain their chat-thread-actions contracts.
- `EventRecord`, `ModelUsage`, and `TokenBreakdown` are Durable Turn's provider-independent durable-event types. `events(&self) -> Vec<EventRecord>` returns cloned durable records in recorded order.
- `record_model_usage(&mut self, connected_box_id: u64, usage: ModelUsage) -> Result<(), String>` forwards one usage record to Durable Turn unchanged. A persistence failure is returned unchanged; nonzero connections require Durable Turn's canonical Agent Response contract.
- `TransitionError` is `Unauthorized`, `NotStalled`, `NotRestartable`, or `Internal(String)`.
- `recover(session, kmap) -> Result<DurableThread, String>` reconstructs one thread with no authorization bound. `boxes`, `status`, `accept_box`, `accept_tool_message`, `accept_tool_return`, `accept_tool_return_v2`, `prepare_stage`, `prepare_mailbox_flush`, `prepared_input`, `commit_mailbox_flush`, `begin_input`, `complete`, `fail`, and `restart` retain their existing Durable Turn transition semantics and error results.
- `accept_user(context, profile_id, policy, contents)` binds authorization if needed, accepts one user message, and clears only an authorization installed by the failed acceptance. `clear_authorization` removes the bound authorization.
- `launch_action("SendMessage", arguments)` accepts exactly `{"message":"<nonempty string>"}`, durably appends one visible Agent Message, and returns `success`; malformed arguments return `invalid SendMessage arguments` without appending a message. Other action names retain `ChatThreadActions` dispatch.
Provider stages durably record Agent Responses, explicit Agent Messages, and Tool Calls before dispatch. Prepared provider input contains the external prefix and ends at the exact synthetic unpersisted `[Box N | Agent Response]\n` boundary. Recovery preserves Durable Turn's complete-history fresh-thread replay and same-thread delta behavior. An active-turn mailbox-flush commit does not independently schedule inference.
For a worst-practical session history, forwarding `events` is linear in the durable record count and clones the returned records; recording model usage performs Durable Turn's synchronous persistence transaction.