kcode-k1-chat-thread-session-actor 0.3.11

Concrete asynchronous session actor for one durable K1 chat thread
Documentation
# K1 chat-thread session actor public contract 0.3.11

## Constructors

- `open(adapter, key, session, kmap, web_search)` recovers one durable thread without Social, SetLaunchNode, RustCode, or WebCode composition.
- `open_with_social(adapter, key, session, kmap, social, web_search)` additionally configures `kcode-k1-ktool-social::SocialKtools`.
- `open_with_social_and_set_launch_node(adapter, key, session, kmap, social, set_launch_node, web_search)` additionally configures `SetLaunchNodeKtool`.
- `open_with_social_and_set_launch_node_and_rust_code(adapter, key, session, kmap, social, set_launch_node, rust_code, web_search)` configures persistent selector-aware V1 RustCode without WebCode.
- `open_with_social_and_set_launch_node_and_rust_code_and_web_code(adapter, key, session, kmap, social, set_launch_node, rust_code, web_code, web_search)` is the full constructor. `web_code: K1WebCodeKtoolService` is immediately before `web_search`.

Every constructor first performs exact `DurableThread` recovery, recovers `SessionCodeRuntime` from those durable boxes and its optional code services, then constructs one `StageRuntime`. The first three modes configure neither code service. RustCode uses service 0.1.4 through session-code runtime 0.1.4 and Stage runtime 0.1.2; the full mode also adopts WebCode service 0.2.0.

## Runtime behavior and limits

The actor retains the ordered command receiver and event loop, durable state, adapter, shim and inference ownership, model-usage lifecycle, active conversation key and restart generation, session view and snapshots, and fatal handling. Its single `StageRuntime` owns provider-stage coordination, exact registry preflight, RustCode and WebCode lanes, asynchronous WebSearch correlation, mailbox flushes, and Stage acknowledgement order.

RustCode recovery preserves the V1 published or unpublished selector, exact unpublished KTO revision, retained editable source boxes, and check state. WebCode Open state remains process-local. Successful user acceptance, restart, authorization clearing, Stage handling, unified code receipt and completion, WebSearch completion, mailbox-flush completion, pending state, abort, failure, and shutdown delegate through `StageRuntime`.

After exact actor-owned inference correlation, `settle_stage_inference` owns accepted success or failure settlement across durable state, Stage, and model usage. Provider failure orders Stage abort, durable failure, mirror-only authorization clearing, then usage settlement. Success materializes terminal durable output before terminal code settlement.

The event context supplied for each Stage operation contains the actor's durable thread, adapter, active key, view, sender, and current job. The select loop awaits unified code completion only while `can_receive_code` is true. WebSearch retains its strict request, absolute 60-minute deadline, exact `ToolCallId` correlation, no-progress behavior, and terminal-result semantics. Registered non-code and non-WebSearch calls still delegate to durable state.

Restart preflights its next generation, active key, and shim, completes the Stage and durable restart, and installs replacements only after success. Abort and shutdown discard adoptable code work but do not claim cancellation of a blocking effect already started; stale correlation prevents detached output from being adopted.

This package owns no persistence format, provider prompt, HTTP implementation, migration, daemon composition, deployment, or live-behavior proof.