# K1 Rust code Ktool process service
`RustCodeKtoolService` owns authenticated persistent Rust source operations and per-user disposable checking state. `create` creates only a previously absent authority/library family, persists the approved `0.0.0` worktree through KTO, and returns its unpublished selector. `open` resolves the exact selector or current family head. `latest_published` ignores unpublished heads. Published selectors are public; create, unpublished reads, default-head reads, forks, overwrites, and publication require the selected user or ordinary unfiltered shared-group authority.
`overwrite` compares the caller's complete opened source with the current unpublished source before submitting an expected-revision overwrite. Overwriting published source creates a new branch. Every successful write returns the canonical source selected from the synchronous projection. `versioned` changes only `[package].version` and returns the exact publication candidate without mutating the worktree.
`check_fresh` and `current_check` bind opaque receipts to the authenticated user and exact complete source. `publish_checked` rejects a mismatched receipt or already-used semantic version, saves the exact publication event as a private K1 Object, reauthorizes immediately before the projection effect, and returns the KTO publication outcome. Published dependencies remain public. Per-user Podman/cache operations serialize without holding the user-map lock; different users remain independent.
The service performs no retries, background work, migration, history recovery, model argument parsing, message emission, deployment, or cleanup. KTO is canonical for authored source; coding caches and projection files are disposable.