# Consumer contract
`K1WebCodeKtoolService` is a cloneable synchronous process service. Its exact API is:
```rust
pub struct ServiceRevisions { pub boot: String, pub schema: String, pub route: String, pub harness: String, pub check_policy: String }
pub struct ServiceConfig;
impl ServiceConfig { pub fn new(cache_root: PathBuf, projection_root: PathBuf, revisions: ServiceRevisions, podman: WebPodmanConfig) -> Self; }
pub enum DocumentPart { Documentation, Code }
pub struct OpenedLibrary;
impl OpenedLibrary { pub fn document(&self) -> &CodeDocument; }
pub struct CheckEvidence;
pub struct FreshCheck { pub outcome: CheckOutcome, /* private evidence */ }
impl FreshCheck { pub fn evidence(&self) -> &CheckEvidence; }
pub struct PublishCompletion { pub source_object: TxId, pub publication: PublishResult, pub precheck: Option<CheckOutcome>, pub evidence: CheckEvidence }
pub enum ServiceFailure { State, Authorization, WorkspaceDenied, SourceUnavailable, LanguageRequired, LanguageMismatch, ForeignHandle, StaleSource, InvalidDocument, CheckFailed, SourcePreservation, PublicReleaseDenied, Publication, Dependency }
pub struct ServiceError;
impl ServiceError { pub fn failure(&self) -> ServiceFailure; pub fn source_object(&self) -> Option<TxId>; }
pub struct K1WebCodeKtoolService;
impl K1WebCodeKtoolService {
pub fn new(config: ServiceConfig, groups: Arc<K1Groups>, objects: Arc<K1Objects>, projection: Arc<K1WebProjection>) -> Self;
pub fn docs(&self, context: &AccessContext, id: &WebId) -> Result<Option<String>, ServiceError>;
pub fn open(&self, context: &AccessContext, id: &WebId, language: Option<Language>) -> Result<OpenedLibrary, ServiceError>;
pub fn validate_current(&self, context: &AccessContext, opened: &OpenedLibrary) -> Result<(), ServiceError>;
pub fn overwrite(&self, context: &AccessContext, opened: &OpenedLibrary, part: DocumentPart, contents: String) -> Result<OpenedLibrary, ServiceError>;
pub fn check(&self, context: &AccessContext, opened: &OpenedLibrary) -> Result<FreshCheck, ServiceError>;
pub fn publish(&self, context: &AccessContext, opened: &OpenedLibrary, evidence: Option<&CheckEvidence>) -> Result<PublishCompletion, ServiceError>;
}
```
`Language` and `CodeDocument`, coding `CheckOutcome` and `PublishResult`, and Objects `TxId` are reexported. `ServiceConfig` and `ServiceRevisions` are public aliases of the runtime leaf's `RuntimeConfig` and `RuntimeRevisions`. `DocumentPart`, `OpenedLibrary`, and `CheckEvidence` are reexported from the pure `kcode-k1-web-code-session` owner, which owns session recovery, validation, replacement, and evidence matching. `ServiceRevisions`, `DocumentPart`, `OpenedLibrary`, `CheckEvidence`, `ServiceFailure`, and the service implement `Clone` where meaningful; `DocumentPart` and `ServiceFailure` are also `Copy`.
The `kcode-k1-web-code-runtime` leaf owns lazy coding construction, cache and projection configuration, user-path derivation, and independently locked per-user coding slots. Every service operation runs through that runtime. Separate users do not block one another while opening or operating, while operations for one authenticated user's 12 bytes remain serialized. The runtime's global slot-map mutex is held only while looking up or inserting a slot; it never spans authorization, Groups, filesystem, Podman, Objects, projection, or caller callbacks.
Workspace and release decisions delegate to `authorize_workspace`. `docs` does not create a candidate. `open` authorizes first, canonically recovers or creates a code document, writes its exact projection, and returns a service/user/source-bound handle. `validate_current` uses the same per-user runtime slot and the same authorized current-source view as overwrite, check, and publish, then validates the supplied handle through `SessionScope` against that exact current `SourcePackage`. It performs no mutation, check, Objects operation, or publication. Foreign, denied, unavailable, and stale sources retain the existing `ServiceFailure` classification and error text. Overwrite and check reject foreign or stale handles. Check is always fresh and returns similarly bound evidence.
Publish validates the handle and current exact source. Supplied matching evidence skips the explicit precheck; missing or mismatching evidence causes exactly one `check_fresh` before source preservation and public release. Coding still owns receipt-aware publication admission. A successful completion contains evidence minted only after current handle/source validation and matching the exact source handled by publication. `precheck` is `Some` only when the service ran that explicit fresh precheck. Source preservation delegates canonical package encoding, the one Objects save, and captured-ID finalization to `kcode-k1-web-source-object`. The Object metadata is filename `""`, file type `"k1-web-source-package-v1"`, and description `""`. An Object ID is retained on later authorization or projection failure. Objects failures are returned without parsing or retry, and no operation retries.
Local validation, recovery, encoding, and copying are linear in the relevant source bytes. Slot lookup is expected constant time. `validate_current` adds one authorized current-source view and exact local session validation; it has no service-owned finite wall-clock bound because the view and authorization may perform dependency I/O or callbacks. Opening may perform filesystem work; checks add one fresh bounded Podman execution when requested; publication adds preservation, authorization, and projection effects. Dependency I/O, scheduling, callbacks, and publication have no service-owned finite wall-clock bound. The service owns no background work, deployment, protocol JSON, or live adoption.