# K1 chat-thread session actor public contract 0.3.9
## Constructors
- `open(adapter, key, session, kmap, web_search)` recovers one durable thread without Social, SetLaunchNode, RustCode, or WebCode composition.
- `open_with_social(adapter, key, session, kmap, social, web_search)` additionally configures `kcode-k1-ktool-social::SocialKtools` through durable recovery.
- `open_with_social_and_set_launch_node(adapter, key, session, kmap, social, set_launch_node, web_search)` additionally configures `SetLaunchNodeKtool` through durable recovery.
- `open_with_social_and_set_launch_node_and_rust_code(adapter, key, session, kmap, social, set_launch_node, rust_code, web_search)` retains the existing RustCode constructor and configures RustCode without WebCode.
- `open_with_social_and_set_launch_node_and_rust_code_and_web_code(adapter, key, session, kmap, social, set_launch_node, rust_code, web_code, web_search)` is the additive full constructor. `web_code: K1WebCodeKtoolService` is immediately before `web_search: kcode_k1_codex_websearch::Runner`; this mode configures both RustCode and WebCode.
Every constructor first performs its exact `DurableThread` recovery, recovers `SessionCodeRuntime` from those durable boxes and its optional RustCode and WebCode services, then constructs one `StageRuntime` with the required WebSearch runner. The first three modes configure neither code service. Existing constructor parameter order, results, and behavior remain compatible.
## Runtime behavior and limits
The actor retains the ordered command receiver and event loop, `DurableThread`, adapter, shim and inference ownership, model-usage lifecycle, active conversation key and restart generation, session view and snapshots, and fatal handling. Its single `StageRuntime` owns provider Stage coordination, exact registry preflight, RustCode and WebCode lanes, asynchronous WebSearch correlation, mailbox flushes, and Stage acknowledgement order.
Successful user acceptance, restart, authorization clearing, Stage handling, unified code receive and completion, WebSearch completion, mailbox-flush completion, pending and searching state, abort, failure, and shutdown delegate through `StageRuntime`. After exact actor-owned inference correlation, `settle_stage_inference` owns accepted success or failure settlement across durable state, Stage, and model usage. Provider failure orders Stage abort, durable failure, mirror-only authorization clearing, then usage settlement; success materializes terminal durable output before terminal code settlement. The actor restores the accepted shim only when settlement permits it and sends a returned provider error through the current Stage failure path.
The event context supplied for each Stage operation contains the actor's durable thread, adapter, active key, view, sender, and current job. The select loop awaits unified code completion only while `can_receive_code` is true. WebSearch retains its strict request, absolute 60-minute deadline, exact `ToolCallId` correlation, no-progress behavior, and terminal-result semantics. Registered non-code and non-WebSearch calls still delegate to durable state. `Handle`, `snapshot()`, and `snapshot_with_events()` retain the actor-channel contracts.
WebCode Open state is process-local and is not recovered when an actor is reconstructed. Restart preflights its next generation, active key, and shim, completes the Stage and durable restart, and installs the replacements only after success. Abort and shutdown discard adoptable code work and tracked searches but do not claim cancellation of a blocking effect that has already started; stale correlation prevents detached WebCode output from being adopted.
This package owns no persistence format, provider prompt, HTTP implementation, migration, daemon composition, deployment, or live-behavior proof.