kcode-k1-chat-thread-durable-state 0.4.17

Authorized durable state transitions for one K1 chat thread
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
# K1 chat-thread durable state 0.4.17

`DurableThread` is the synchronous, one-session state owner used by the session actor. It owns durable conversation transitions, bound Ktool authorization, and forwarding to Durable Turn; it owns no provider protocol, pricing, migration, boxes beyond Durable Turn, or asynchronous channel effects.

## Public contract

- Existing box, event, model-usage, transition, provider-stage, mailbox-flush, completion, restart and constructor contracts remain unchanged.
- `prepare_preflight` validates every Ktool call against the concrete synchronous dispatcher before effects, binds the supplied authorization, and forwards one fresh ordered preflight to Durable Turn. It returns stable prepared calls and persists no custom state beyond Durable Turn's ordinary boxes and `chat_preflight` event.
- `preflight_calls` exposes recovered prepared calls. `authorize_preflight` rebinds trusted request authority for recovery. `preflight_executor` returns a cloneable mutex-serialized executor so the preflight runtime can execute synchronous Ktools outside actor and persistence locks.
- Preflight supports only the calls reported by the configured `ChatThreadKtoolExecutor`; KtoolDocs, SendMessage, WebSearch, RustCode and WebCode are not in that executor.
- Authorization clearing is deferred while any prepared preflight call lacks a terminal Tool Result. This lets non-blocking calls finish safely after a provider turn; normal clearing resumes as soon as all preflight calls are terminal.
- `accept_user` and `restart` bind one exact context/profile/policy triple. The same triple is idempotent and a different active triple is unauthorized before partial effects. A failed newly installed transition clears authorization.
- `launch_action` preserves KtoolDocs, SendMessage and configured ordinary Ktool behavior. `SendMessage` durably appends one visible Agent Message.
- `complete_recoverable_failure_with_terminal_response` durably closes the affected provider operation with one caller-selected safe terminal Agent Response and returns its canonical ID. `reset_provider_context` then prepares complete canonical history for a replacement provider process while keeping the same Chat usable.
- `record_diagnostic` forwards one bounded typed `ChatDiagnostic`; raw provider or transport diagnostics are never persisted by this surface.
- `halt_critical` durably installs a first-write-wins, non-restartable stalled state and clears bound authorization. Callers select this typed policy without diagnostic-string parsing.

Preflight task scheduling, blocking coordination, HTTP, retries, timeouts, provider work, migration, deployment and process restart remain outside this package.