# K1 chat-thread session actor 0.2.3
`kcode-k1-chat-thread-session-actor` owns the concrete asynchronous actor loop for one durable K1 chat thread. It composes `kcode-k1-chat-thread-actor-channel` with the Cargo-compatible 0.4.3 lower bound, `kcode-k1-chat-thread-durable-state` with the Cargo-compatible 0.4.2 lower bound, `kcode-k1-chat-codex-state` with the Cargo-compatible 0.7.3 lower bound, and the approved fail-closed `kcode-k1-chat-thread-web-search` compatibility boundary with the Cargo-compatible 0.2.0 lower bound. It spawns exactly one actor and returns the established channel `Handle`.
The actor owns FIFO commands, Codex turn effects, exact model-input observations, stage acknowledgements, waiters, restart generations, disabled WebSearch task completion and cancellation epochs, and teardown. A provider stage is durably accepted before dispatch. Prepared calls are consumed in provider order. An `ImmediateError` call is never externally dispatched: the actor synchronously accepts its detailed deterministic failure as an ordinary metadata-bearing Tool Result v2. External calls retain the existing WebSearch or Ktool handling. The initial active-turn mailbox flush commits before the stage acknowledgement.
The actor continues the same provider generation through the external compatibility API `Adapter::steer`. Committing an active-turn mailbox flush does not independently schedule redundant inference. Independently running tool tasks may outlive the provider turn, and terminal tool results request an active-turn mailbox flush in the active turn or defer it to a later turn. Synthetic provider input is exactly `[Box N | Agent Response]\n`. Provider failure fences and aborts tasks, while successful completion retains live tasks.
Durable state exclusively owns canonical Agent Response, Agent Message, Tool Call, Tool Message and Tool Result transitions; persistence; fresh-thread replay; same-thread delta input; authorization; synchronous action dispatch; restart; and success-only prepared frontiers. This package owns no persistence format, authorization policy, native tool implementation, HTTP, migration, daemon composition, deployment, or public facade.