Skip to main content

Crate kcode_k1_daemon_lib

Crate kcode_k1_daemon_lib 

Source
Expand description

§kcode-k1-daemon-lib

Version 0.13.1 is the library-only composition root for the private K1 loopback daemon and its authority-owned Web serving.

§Public API

pub fn run(k1_root: PathBuf) -> ExitCode;

run builds the multithreaded Tokio runtime, prompts once for Vault unlock, starts the complete daemon beneath <k1_root>/state, writes readiness, serves the loopback HTTP boundary, and returns success only after graceful shutdown. Startup or listener failure returns exit code 1 through the fixed safe daemon error surface.

§Composition

The daemon composes one process-lifetime instance of transaction ordering, peering, Vault, Persons, Invites, Accounts, Users, Groups, saved Access Profiles, Authority Filters, Access, Objects, Audio, Chat, Launch Nodes, replay protection, providers, authenticated HTTP adapters, and the prefixless authority-owned KTO Web adapter.

The Web startup leaf selects the optional public origin and opens the public router from the shared transaction-ordering and peering instances. Its projection and control roots are fixed at <k1_root>/state/web/projection and <k1_root>/state/web/control; they are disposable derived state while KTO remains canonical product state.

Launch Nodes retains its append-only startup projection at <k1_root>/state/launch-nodes. Only ordered KTO callbacks append to that rebuildable projection. Chat Service opens the sole raw Kmap and Access-Kmap facade. The Launch Nodes and Kmap HTTP adapters share that Access-Kmap, saved Profiles, Authority Filters, and the Chat access model.

Social is composed once for Chat from the process-owned Users, Groups, and Access Launch Nodes facades. Social and People share the same immutable snapshot returned by the single people_models() call; Social maps every snapshot model ID to that model’s exact configured human-readable name.

The authenticated router mounts signed Kmap creation and the current Accounts, People, Persons, Chat, Audio, Launch Nodes, and profile-presentation routes. Kmap creation is non-idempotent: clients must not retry an ambiguous failure, and an unexpected Access failure after raw-node creation can leave an inaccessible raw-node orphan.

WebSearch is constructed from the existing Chat Codex Adapter clone, so Audio, Chat, and WebSearch share one persistent app-server while each WebSearch receives a fresh one-shot thread.

§State and startup

Durable product state remains beneath <k1_root>/state and is committed through the composed KTO-backed subsystem owners. Disposable projections remain non-authoritative. Audio classification opens without a filesystem root. The concrete kcode-k1-daemon-audio-lifetime guard preserves explicit and Drop-driven synchronous shutdown on every post-open startup failure, readiness failure, and serving exit.

Startup selects the public origin once, opens each subsystem once for process lifetime, unlocks Vault, resolves provider and FFmpeg configuration, reconciles at least 100 unused wildcard Account invite links, opens replay protection, composes the authenticated API and public Web router, binds the private loopback boundary, and writes readiness only after successful preparation. Startup taking more than 100 ms emits the readiness warning.

The listener is fixed at loopback port 4450. Without K1_PUBLIC_ORIGIN, the canonical public origin is http://localhost:4450; otherwise its UTF-8 value must pass canonical HTTP/HTTPS-origin validation. The selected origin controls API config, /config.json, exact Host acceptance, and readiness. Existing API fallback, authentication, replay protection, CORS, security, and graceful signal behavior are retained. Invite links remain rooted at http://localhost:4321/lib/kcode-k1-ui/*/account.html.

UI selection, proxy and TLS ownership, deployment, and live adoption remain outside this package.

§Lifecycle boundary

This release proves package composition and managed checks only. It does not prove local dependency selection, daemon rebuild or restart, signed provider traffic, browser integration, deployment, or live behavior. Startup and request paths inherit delegated local and provider work without adding a finite completion guarantee.

Functions§

run