kcode-k1-daemon-lib 0.12.1

Library-only private K1 loopback daemon composition root
Documentation
# kcode-k1-daemon-lib

`kcode-k1-daemon-lib` is the library-only composition root for the private K1 loopback daemon.

## Public API

```text
pub fn run(k1_root: PathBuf) -> ExitCode;
```

`run` builds the multithreaded Tokio runtime, prompts for the Vault unlock, starts the complete daemon beneath `<k1_root>/state`, writes readiness, serves the loopback HTTP boundary, and returns success only after graceful shutdown. Startup or listener failure returns exit code 1 through the fixed safe daemon error surface.

## Composition

Version 0.12.1 composes the current Accounts, People, Persons, Chat, Audio and artifact reads, Launch Nodes, Access, Profiles, Authority Filters, Invites, Groups, Objects, providers, replay protection, and loopback HTTP routes.

The selected Chat chain includes:

- `kcode-k1-chat-service` 0.10.0 at the concrete HTTP type boundary
- `kcode-k1-daemon-provider-config` 0.1.6, which supplies the strict native `agent_message` definition
- `kcode-k1-codex-adapter` 0.5.2
- `kcode-k1-codex-websearch` 0.1.0
- `kcode-k1-http-chat` 0.7.1

The daemon constructs the WebSearch runner from the same configured Codex executable and supplies it to Chat Service.

This release intentionally adopts the David-approved breaking HTTP Chat mailbox-flush migration: a mailbox-flush model input has `model_input.kind` equal to `mailbox_flush`. Callers that consumed the previous mailbox-flush HTTP representation must migrate to this discriminant; all other known-value and known-field behavior is retained.

This selection retains `K1-CHAT-MALFORMED-TOOL-RECOVERY-001 r4` at the daemon composition boundary. Malformed native calls remain durably ordinary Tool Calls with normal ToolCallIds. They immediately receive one detailed ordinary failed Tool Result without external dispatch, continue the same native turn through active-turn mailbox flush, and do not themselves stall the conversation. Chat registers exactly the approved native `call_ktool` and `agent_message` definitions. Canonical Agent Responses and explicit Agent Messages remain ordinary generic Chat boxes; every native generation receives the synthetic unpersisted open Agent Response header; existing native threads receive only new external input; and recovery or explicit restart replays complete canonical history once on a fresh native thread. All seven existing Chat HTTP routes remain unchanged.

The selected profile-presentation chain remains:

- `kcode-k1-access` 0.6.1
- `kcode-k1-access-profiles` 0.6.2
- `kcode-k1-http-access-profile-presentation` 0.1.0

The authenticated router mounts `POST /api/access/profile-presentations`. Its dedicated `K1HttpAccessContext` uses the shared Authority Filters facade and `chat_access_model()`. The adapter receives shared `Arc<K1Access>` and `Arc<K1AccessProfiles>` handles rather than opening another subsystem instance.

After Chat Service opens the sole process-lifetime Kmap and Access-Kmap facade, composition obtains one `Arc` clone of that exact facade and supplies it to the launch-node HTTP adapter; no second Kmap is opened. The authenticated adapter mounts `POST /api/launch-nodes/details`, which returns authorized full node text and source-ordered visible Navigation and Other connection metadata without raw Kmap identities, hidden connections, evidence mass, policies, or edit rights.

The selected `kcode-k1-http-audio-artifacts` 0.4 line retains the approved K1 Audio artifact inspector. The authenticated fragment-artifacts route returns retained analysis artifacts plus derived successful LLM calls reconstructed from those artifacts and the immutable Speaker V3 protocol.

Other than the intentional `model_input.kind = "mailbox_flush"` HTTP break and the approved one-shot WebSearch capability, this release adds no route, persistence format, migration, compatibility reader, provider call, retry, streaming surface, or failed-call capture. It changes no persisted state root or schema.

## State and startup

All durable daemon state remains beneath `<k1_root>/state`, including transaction ordering, peering, Vault, Persons, Invites, Groups, Access Profiles, Authority Filters, Access, Launch Nodes, Audio classification, Objects, replay state, invite links, and Chat v2.

Startup opens each subsystem once for process lifetime, unlocks the Vault, resolves Gemini and Codex/FFmpeg configuration, reconciles at least 100 unused wildcard Account invite links, opens replay protection, composes the authenticated API, binds the private loopback boundary, and writes readiness only after successful preparation. Startup taking more than 100 ms emits the existing readiness warning.

The HTTP boundary retains public origin `http://localhost:4450`, authenticated `/api` behavior, replay protection, existing CORS and security behavior, and graceful signal handling. Invite links remain rooted at `http://localhost:4321/lib/kcode-k1-ui/*/account.html`.

## Lifecycle boundary

This package release proves package composition and managed checks only. It does not prove local adoption, live behavior, a local dependency update, daemon rebuild or restart, signed provider traffic, browser integration, deployment, or any visible live outcome.

Startup performs delegated local and provider setup and has no finite completion guarantee; the existing warning reports startup beyond 100 ms. Request-path performance and isolation are owned by the composed HTTP adapters.