# K1 chat-thread session actor
## Public contract
- `open(adapter, key, session, kmap, web_search)` retains its established behavior: it recovers one durable thread without Social composition, spawns its serialized actor, and returns its command handle.
- `open_with_social(adapter, key, session, kmap, social, web_search)` additively configures `kcode-k1-ktool-social::SocialKtools` through durable recovery and otherwise uses the same actor spawn and lifecycle. `social` is adjacent to `kmap`, before the configured `kcode-k1-codex-websearch::Runner`.
- Before WebSearch parsing or any other execution, every external Tool Call name is checked against the exact, case-sensitive KtoolDocs registry. An absent name durably receives its correlated Tool Result `Err("unknown Ktool")`. Exact WebSearch alone uses the actor-owned asynchronous path; every other registered name delegates to Durable Thread, which gates it again. SetLaunchNode remains registered but unwired.
- The public inner Ktool is the strict object `WebSearch { query: string, model: string, reasoning_effort?: string }`. Unknown fields, aliases, nulls, and nonstrings fail locally. The model must start with exact case-sensitive `codex/`; the prefix is stripped once. Omitted effort becomes `medium`; supplied strings pass unchanged.
- Each accepted WebSearch Tool Call records its absolute 60-minute deadline before launch, runs once in the background, emits no progress messages, and later records exactly one correlated terminal Tool Result while this actor remains alive. Concurrent calls retain their original ToolCallId. Actor teardown or inference failure cancels all outstanding calls.
- `Handle` retains the actor-channel contract. `snapshot()` retains its live snapshot, while `snapshot_with_events()` returns that snapshot with cloned durable events in recorded order.
The actor owns FIFO commands, Codex turn effects, managed runtime model-usage lifecycle, stage acknowledgements, restart generations, WebSearch task correlation, registry preflight, and teardown.
Durable state owns canonical conversation transitions, persistence, and registered non-WebSearch Ktool dispatch. This package owns no persistence format, provider prompt, HTTP, migration, daemon composition, deployment, or progress-event surface.