kcode-k1-web-coding 0.1.1

Orchestrate authorized per-user K1 Web coding operations
Documentation
# Consumer contract

`K1WebCoding` is the synchronous, exclusively caller-owned orchestration boundary for one user's disposable Web cache, projection view, and fresh Podman checks. Independent instances share no coding-layer lock. Stateful operations require `&mut self`; authorization gates are supplied per operation and are never retained.

```rust
pub struct WebCodingRevisions { pub boot: String, pub schema: String, pub route: String, pub harness: String, pub check_policy: String }
pub struct WebCodingConfig;
impl WebCodingConfig { pub fn new(revisions: WebCodingRevisions, projection_root: PathBuf, podman: WebPodmanConfig) -> Result<Self, WebCodingError>; }
pub struct CheckExecution { pub diagnostics: CommandDiagnostics, pub report: Report }
pub enum CheckOutcome { Reused, Checked(Box<CheckExecution>) }
pub struct PublishResult { pub check: CheckOutcome, pub outcome: PublishOutcome }
pub enum WebCodingError {
    State(String), Cache(String), Authorization(String), WorkspaceDenied, DependencyUnavailable,
    Podman(Box<WebPodmanError>), CheckFailed(Box<CheckExecution>), PublicReleaseDenied,
    Projection(String), ProjectionAfterSubmit { submitted: String, message: String },
}
pub struct K1WebCoding;
impl K1WebCoding {
    pub fn open(cache_root: impl AsRef<Path>, user: TxId, config: WebCodingConfig, projection: Arc<K1WebProjection>) -> Result<Self, WebCodingError>;
    pub fn cache_epoch(&self) -> u64;
    pub fn check(&mut self, candidate: &SourcePackage, authorize_workspace: &dyn Fn(&WebFamily) -> Result<bool, String>) -> Result<CheckOutcome, WebCodingError>;
    pub fn publish(&mut self, candidate: &SourcePackage, authorize_workspace: &dyn Fn(&WebFamily) -> Result<bool, String>, authorize_public_release: &dyn Fn(&SourcePackage, Digest) -> Result<bool, String>) -> Result<PublishResult, WebCodingError>;
    pub fn reset(&mut self) -> Result<(), WebCodingError>;
}
```

`CheckExecution`, `CheckOutcome`, `PublishResult`, and `WebCodingError` implement `Debug`; `WebCodingError` also implements `Display` and `std::error::Error`. Configuration requires nonempty cache and receipt-policy revisions, a canonical ordinary projection directory, and a valid `WebPodmanConfig`. `open` opens the exact per-user cache and Podman runner while retaining the supplied projection. Opens taking more than 100 milliseconds emit a secret-free warning. `reset` runs only between synchronous operations, when no container is retained, and wholly replaces the disposable cache.

Every check freshly invokes its candidate-family gate before staging private bytes, captures one coherent projection snapshot, and resolves each distinct recursive family-selector pair to the highest matching stable version. Every resolved route, including transitive routes, is paired with its exact selected package; the cache validates and materializes the complete closure under its resolution root. The canonical manifest digest binds selected versions, winners, and bytes without a projection cursor, supplies `CheckIdentity.graph`, and is routed to the checker as the frozen admitted view. Cycles are finite, multiple selectors for one family remain distinct, and absence is concealed as `DependencyUnavailable`.

An exact successful receipt returns `Reused` without Podman. Unrelated projection publication leaves the frozen manifest, resolution identity, and receipt unchanged; a changed selected version, winner, or byte invalidates them. A miss starts Podman once with the complete live public projection mounted separately read-only, returns complete execution data, and records only `Outcome::Success`; a completed failure is `CheckFailed`. `publish` then freshly invokes its public-release gate with the exact candidate and source digest immediately before one projection publication. Completed `Published`, `Idempotent`, and `Conflict` outcomes are preserved; an error carrying a submitted transaction exposes its canonical transaction ID text as `ProjectionAfterSubmit`. Installation and observation occur only through the projection.

Configuration validation, identity construction, and graph traversal are unbenchmarked and linear in supplied text, selected package bytes, or graph size as applicable; cache epoch access is constant-time. `open` and `reset` are unbenchmarked local filesystem operations. `check` adds one bounded local Podman execution on a miss, and `publish` adds projection/Peering work whose completion time this library does not own.