Expand description
§kcode-k1-daemon-lib
kcode-k1-daemon-lib is the library-only composition root for the private K1 loopback daemon.
§Public API
pub fn run(k1_root: PathBuf) -> ExitCode;run builds the multithreaded Tokio runtime, prompts for the Vault unlock, starts the complete daemon beneath <k1_root>/state, writes readiness, serves the loopback HTTP boundary, and returns success only after graceful shutdown. Startup or listener failure returns exit code 1 through the fixed safe daemon error surface.
§Composition
Version 0.10.6 composes the current Accounts, People, Persons, Chat, Audio and artifact reads, Launch Nodes, Access, Profiles, Authority Filters, Invites, Groups, Objects, providers, replay protection, and loopback HTTP routes.
The selected profile-presentation chain is:
kcode-k1-access0.6.1kcode-k1-access-profiles0.6.2kcode-k1-http-access-profile-presentation0.1.0
The authenticated router mounts POST /api/access/profile-presentations. Its dedicated K1HttpAccessContext uses the shared Authority Filters facade and chat_access_model(). The adapter receives shared Arc<K1Access> and Arc<K1AccessProfiles> handles rather than opening another subsystem instance.
This release changes no persisted state root, schema, wire format, migration policy, or compatibility reader.
§State and startup
All durable daemon state remains beneath <k1_root>/state, including transaction ordering, peering, Vault, Persons, Invites, Groups, Access Profiles, Authority Filters, Access, Launch Nodes, Audio classification, Objects, replay state, invite links, and Chat v2.
Startup opens each subsystem once for process lifetime, unlocks the Vault, resolves Gemini and Codex/FFmpeg configuration, reconciles at least 100 unused wildcard Account invite links, opens replay protection, composes the authenticated API, binds the private loopback boundary, and writes readiness only after successful preparation. Startup taking more than 100 ms emits the existing readiness warning.
The HTTP boundary retains public origin http://localhost:4450, authenticated /api behavior, replay protection, existing CORS and security behavior, and graceful signal handling. Invite links remain rooted at http://localhost:4321/lib/kcode-k1-ui/*/account.html.
§Lifecycle boundary
This package release proves source composition and managed checks only. It does not prove a local dependency update, daemon rebuild or restart, live signed profile-presentation traffic, browser integration, deployment, or any visible live outcome.
Startup performs delegated local and provider setup and has no finite completion guarantee; the existing warning reports startup beyond 100 ms. Request-path performance and isolation are owned by the composed HTTP adapters.