kcode-k1-chat-thread-session-inference-settlement 0.1.2

One-shot provider inference settlement for the K1 chat-thread session actor
Documentation
# K1 chat-thread session inference settlement 0.1.2

`settle_inference` performs one accepted provider-inference settlement for the Session Actor Runtime.

```text
pub async fn settle_inference(
    durable: &mut DurableThread,
    provider: &mut SessionProvider,
    usage: &mut ModelUsageSession,
    searches: &mut WebSearchTasks,
    rust_code: Option<&mut RustCodeSession>,
    job: u64,
    shim: ActorShim,
    result: Result<ShimOutput<BoxValue>, String>,
) -> Result<InferenceSettlement, String>;
```

`InferenceSettlement::should_stop` reports only a critical settlement failure. `recoverable_failure` identifies a provider failure that was durably closed with a safe visible terminal Agent Response while leaving the Chat usable. `usage_diagnostic` returns a typed, bounded model-usage finish or restart failure for caller-owned fail-soft recording. `into_stage_error` returns only the safe public failure text for the caller-owned stage reply. Raw provider diagnostics are neither classified nor exposed.

`settle_stage_inference` performs one already-correlated provider-inference settlement for the current Stage Runtime architecture.

```text
pub async fn settle_stage_inference(
    durable: &mut DurableThread,
    usage: &mut ModelUsageSession,
    stage: &mut StageRuntime,
    active_key: &str,
    job: u64,
    result: Result<ShimOutput<BoxValue>, String>,
) -> Result<StageInferenceSettlement, String>;
```

`StageInferenceSettlement` exposes the same stop, recoverable-failure, safe-stage-error and typed usage-diagnostic boundaries. `restore_shim` is true only after successful provider completion. `settle_stage_failure` is the explicit typed entry point for provider or mailbox-transport failure.

For a recoverable Stage failure, settlement aborts Stage work, durably appends one safe terminal Agent Response, resets provider context from complete canonical history, best-effort records the caller-selected typed diagnostic, clears authorization at the idle boundary, and finishes model usage fail-soft. For success, it records the durable terminal response, settles terminal code, finishes model usage fail-soft, and clears authorization only at an idle boundary.

The original settlement preserves its existing order: provider acceptance and exact job correlation occur first. Recoverable provider failure aborts WebSearch and Rust code work, durably appends the safe terminal response, resets provider context, clears the Rust mirror, settles the failed provider, and finishes usage fail-soft. Success records the terminal response before retained Rust output; that output must yield exactly `PersistCompletion::Committed(None)`, usage is linked to the terminal response, the provider shim is restored, and authorization clears only when no durable resume or WebSearch work remains.

Model-usage finish and restart failures never replace a successful or recoverably failed core inference result. They return typed diagnostics without raw text. Correlation, durable persistence, retained-completion, terminal-boundary and canonical-state failures remain `Err` for caller-owned critical handling.

The package owns no stage reply, actor loop, provider launch, task queue, recovery, restart, retry, deployment, diagnostic-string classification, or external provider selection. It introduces no locks or waits. Each call mutates only caller-supplied session owners; distinct actors remain independent.