kcode-k1-rust-code-ktool-service 0.1.0

Coordinate authenticated K1 Rust code Ktool operations
Documentation
# K1 Rust code Ktool process service 0.1.0

`RustCodeKtoolService` is the synchronous process owner for public K1 Rust source reads and authenticated per-user check and publication operations.

## Public API

```rust
use std::{path::Path, sync::Arc};
use kcode_k1_access_types::AccessContext;
use kcode_k1_groups::K1Groups;
use kcode_k1_objects::K1Objects;
use kcode_k1_rust_code_document::RustCodeDocument;
use kcode_k1_rust_coding::RustCodingConfig;
use kcode_k1_rust_package::LibraryId;
use kcode_k1_rust_projection::{K1RustProjection, PublishOutcome};
use kcode_k1_rust_code_ktool_service::{
    PublicPackageError, RustCodeKtoolService, RustCodeKtoolServiceError, ServiceCheck,
};

pub enum PublicPackageError {
    Absent,
    Unsupported(kcode_k1_rust_code_document::RustCodeDocumentError),
    Backend(String),
}

pub enum RustCodeKtoolServiceError {
    State(String),
    CodingInitialization(String),
    Coding(kcode_k1_rust_coding::RustCodingError),
    SourceEncoding(kcode_k1_rust_transaction::TransactionError),
    Object(String),
    CheckMismatch,
}

pub struct ServiceCheck { /* private */ }
pub struct RustCodeKtoolService { /* private */ }

impl RustCodeKtoolService {
    pub fn new(
        cache_root: impl AsRef<Path>,
        config: RustCodingConfig,
        projection: Arc<K1RustProjection>,
        objects: Arc<K1Objects>,
        groups: Arc<K1Groups>,
    ) -> Self;
    pub fn load_document(&self, id: &LibraryId) -> Result<RustCodeDocument, PublicPackageError>;
    pub fn identity_exists(&self, id: &LibraryId) -> Result<bool, PublicPackageError>;
    pub fn check_fresh(
        &self,
        authenticated: &AccessContext,
        document: &RustCodeDocument,
    ) -> Result<ServiceCheck, RustCodeKtoolServiceError>;
    pub fn current_check(
        &self,
        authenticated: &AccessContext,
        document: &RustCodeDocument,
    ) -> Result<Option<ServiceCheck>, RustCodeKtoolServiceError>;
    pub fn publish_checked(
        &self,
        authenticated: &AccessContext,
        document: &RustCodeDocument,
        checked: ServiceCheck,
    ) -> Result<PublishOutcome, RustCodeKtoolServiceError>;
}
```

`load_document` loads only the exact public `LibraryId`. It distinguishes absence, a published package outside the exact three-file `RustCodeDocument` shape, and projection failure. `identity_exists` reports exact publication presence without imposing the document shape; only its `Backend` error is produced. Reads require no access context.

The process caller supplies an authenticated `AccessContext`, whose concrete user, active model, and filtered authorities are used directly. The service opens one user coding backend lazily. Its first initialization result is retained for the service lifetime, so the service performs no implicit retry.

`check_fresh` always invokes the backend fresh check. `current_check` performs no Podman operation and returns a token only for the backend's current receipt. `ServiceCheck` is opaque and privately binds the backend receipt, authenticated user, exact identity, and exact source bytes.

`publish_checked` rejects a different user or package before any effect. It encodes the exact `SourcePackage` with the canonical Rust publication encoder and saves those bytes as one private-metadata K1 Object before attempting publication. The Object ID is not exposed; a later rejection or ambiguous publication may leave that Object orphaned and is never retried.

The backend calls the private authorization gate immediately before projection publication. The gate permits the exact authenticated user authority, or one nonsentinel group authority present in the current ordinary shared groups of that user and active model and absent from the context filter. Backend `PublishOutcome` is returned unchanged. Backend errors, including `AfterPublish` with its outcome, remain inside the typed `Coding` error.

The user map lock covers only slot lookup or insertion. Initialization for different users proceeds in separate slots, and every completed backend is held in one per-user mutex. Operations for one user serialize; different users enter independently. Podman, Objects, Groups, and KTO work never runs under the user-map lock. The service has no worker, queue, timeout, retry, deployment, migration, snapshot, or additional durable state.