# K1 Kmap
`kcode-k1-kmap` is the synchronous facade for KMAP-001 r1 and logical KTO subsystem `k1-kmap-subsystem`. It combines the versioned Kmap contract, callback-derived projection, Peering submission, and access-filtered probabilistic loading delegated to `kcode-k1-kmap-loader` 0.1.0.
## API
`K1Kmap::open(root, ordering, peering)` opens the projection, registers its callback strictly after the stored checkpoint, and retains the supplied Ordering and Peering instances. Format types, loader result types and costs, and `TxId` are reexported.
```rust
pub fn open(root: &Path, ordering: Arc<K1TxnOrdering>, peering: Arc<K1Peering>) -> Result<K1Kmap, String>;
pub fn create_node(&self, title: impl Into<String>, navigation_hint: impl Into<String>, narrative: impl Into<String>, connections: Vec<ConnectionSpec>) -> Result<TxId, String>;
pub fn update_node(&self, node_id: NodeId, title: Option<String>, navigation_hint: Option<String>, narrative: Option<String>, connection_changes: Vec<ConnectionChange>) -> Result<TxId, String>;
pub fn apply_measurements(&self, measurements: Vec<ConnectionMeasurement>) -> Result<TxId, String>;
pub fn get_node(&self, node_id: NodeId) -> Result<Option<Node>, String>;
pub fn open_node(&self, node_id: NodeId, budget: f64, temperature: f64, access_filter: impl FnMut(NodeId) -> bool) -> Result<OpenResult, String>;
```
Mutation methods build one version-1 `KmapAction`, validate and encode it once, and submit it once through the retained `K1Peering`. They never directly update projection state, retry, or correlate results, and return Peering's exact `TxId` or error.
Every callback decodes once and applies once with its callback `TxId`. `Applied`, `Unchanged`, and `Rejected` are callback successes. Malformed payloads and projection infrastructure failures mark the facade unavailable and fault the callback. Reorganization first marks the facade unavailable and then clears only derived projection state. A fresh successful open is the recovery boundary, and every public operation checks availability.
## Loading
`open_node` checks facade availability and delegates traversal to the loader with projection reads as its node callback. A projection read failure marks the facade unavailable. Budget and temperature must be finite and nonnegative. The caller-authorized root is opened and is not passed to the access predicate. Accessible root Navigation targets are free previews; other previews cost `PREVIEW_COST`, narratives cost `NARRATIVE_COST`, and `DEPTH_DECAY` discounts selection weight by depth.
The loader memoizes access decisions before target reads or probability contribution, omits denied metadata, reports missing allowed targets as integrity errors, and samples with operating-system randomness. Calls are synchronous; graph exploration, storage, callback lanes, entropy, and caller predicates have no finite wall-clock guarantee.
This crate provides no authentication, policy definition, seeded sampling, network client, retry, timeout, background work, deletion, migration, Server adoption, deployment, or live-behavior guarantee. Projection, Ordering, Peering, publication, deployment, and access policy remain separate concerns.