Skip to content

Commit 5b00a22

Browse files
Align R1.0.1 postpublication status
Record published GitHub/Hugging Face artifacts while preserving pending CAPA effectiveness.
1 parent 82d2149 commit 5b00a22

11 files changed

Lines changed: 186 additions & 102 deletions

PUBLICATION_MANIFEST.json

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"current_reference": {
3-
"publication_state": "READY_TO_PUBLISH",
3+
"publication_state": "PUBLISHED",
44
"tag": "r1.0.1-2026-08-17"
55
},
66
"expected_github_latest_tag": {
@@ -15,8 +15,8 @@
1515
"production_authorized": false,
1616
"safety_claimed": false
1717
},
18-
"publication_phase": "PREPUBLICATION",
19-
"prepublication_state": "READY_TO_PUBLISH",
18+
"postpublication_state": "PUBLISHED_PENDING_EFFECTIVENESS",
19+
"publication_phase": "POSTPUBLICATION",
2020
"release_identity": "PROJECT SHADOW 1.0.1 / R1 REFERENCE / BETA-ACTIVE-TESTING / PRELIVE",
2121
"releases": [
2222
{
@@ -77,7 +77,7 @@
7777
"current": true,
7878
"enabled_by_default": false,
7979
"order": 4,
80-
"publication_state": "READY_TO_PUBLISH",
80+
"publication_state": "PUBLISHED",
8181
"role": "OPTIONAL_GENERIC_COMPANION",
8282
"tag": "generic-myth-v0.2.0",
8383
"title": "Project Shadow Generic Myth Sidecar v0.2.0 — Optional Public Companion"
@@ -92,7 +92,7 @@
9292
"canonical_r1": true,
9393
"current": true,
9494
"order": 5,
95-
"publication_state": "READY_TO_PUBLISH",
95+
"publication_state": "PUBLISHED",
9696
"role": "R1_REFERENCE_CORRECTED",
9797
"tag": "r1.0.1-2026-08-17",
9898
"title": "Project Shadow 1.0.1 — R1 Reference Packaging Correction (PRELIVE)"

PUBLIC_RELEASE_STATUS_2026-08-17.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@
99
"final_outer_identity_bound": true,
1010
"inner_exact_hash_admitted": true,
1111
"myth_payload_required": false,
12-
"publication_state": "READY_TO_PUBLISH",
12+
"publication_state": "PUBLISHED",
1313
"tag": "r1.0.1-2026-08-17",
1414
"zero_operational_descendant_bytes_changed": true
1515
},
@@ -19,7 +19,7 @@
1919
"default_off": true,
2020
"final_hardened_identity_bound": true,
2121
"publication_authorization_recorded": true,
22-
"publication_state": "READY_TO_PUBLISH",
22+
"publication_state": "PUBLISHED",
2323
"required_for_r1": false,
2424
"tag": "generic-myth-v0.2.0",
2525
"terminal_only": true
@@ -39,7 +39,7 @@
3939
"production_authorized": false,
4040
"safety_claimed": false
4141
},
42-
"publication_phase": "PREPUBLICATION",
42+
"publication_phase": "POSTPUBLICATION",
4343
"published_optional_companion": {
4444
"default_off": true,
4545
"filename": "Project_Shadow_Full_Canon_Myth_Sidecar_v0.3.5_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip",
@@ -55,5 +55,5 @@
5555
"governance/R1_0_1_OUTER_RELEASE_AUTHORIZATION_2026-08-17.json",
5656
"governance/CAPA_PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001_2026-08-17.json"
5757
],
58-
"warning": "READY_TO_PUBLISH is still PREPUBLICATION. Exact-hash authorities are recorded, but public release, anonymous redownload verification, six-site effectiveness checks, and CAPA closure have not yet occurred."
58+
"warning": "Generic Myth v0.2.0 and R1.0.1 are published on GitHub and Hugging Face. Anonymous GitHub and Hugging Face redownload identity verification and six-site effectiveness checks remain pending; CAPA remains IMPLEMENTED_PENDING_EFFECTIVENESS and is not closed."
5959
}

README.md

Lines changed: 26 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -9,17 +9,17 @@
99
1010
**PROJECT SHADOW 1.0.1 / R1 REFERENCE / BETA-ACTIVE-TESTING / PRELIVE**
1111

12-
Project Shadow 1.0.1 is a packaging-boundary correction in preparation. Its
13-
release design removes Myth from the R1 runtime-family package while preserving
14-
all 27 active operational descendants byte-for-byte. The Generic Myth v0.2.0
15-
identity is frozen and authorized for separate publication, the exact Myth-free
16-
inner family is admitted, and the final R1.0.1 outer identity is frozen. The
17-
outer archive now has its own exact-hash publication authorization. The staged
18-
repository is ready to publish, but no new artifact is represented as public
19-
until the upload exists and can be independently redownloaded.
20-
21-
No pending artifact is represented as published. The machine-readable phase is
22-
[`PREPUBLICATION`](PUBLIC_RELEASE_STATUS_2026-08-17.json).
12+
Project Shadow 1.0.1 is the corrected current R1 reference. It removes Myth
13+
from the R1 runtime-family package while preserving all 27 active operational
14+
descendants byte-for-byte. Generic Myth v0.2.0 is published separately as an
15+
optional companion, the exact Myth-free inner family is admitted, and the final
16+
R1.0.1 outer identity has its own exact-hash publication authorization.
17+
18+
Generic Myth v0.2.0 and R1.0.1 now exist as public GitHub and Hugging Face
19+
releases. Anonymous redownload identity verification and six-site effectiveness
20+
checks remain pending. The machine-readable phase is
21+
[`POSTPUBLICATION`](PUBLIC_RELEASE_STATUS_2026-08-17.json), and CAPA
22+
`PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001` remains open.
2323

2424
## Current contact
2525

@@ -41,8 +41,8 @@ contact routes.
4141
| R1, 2026-08-14 | Preserved historical release; superseded as the current reference | Contains a historically nested Generic Myth v0.1.1 member whose own metadata was non-public; the released bytes remain immutable evidence |
4242
| Full-Canon Myth v0.3.4 | Preserved historical optional sidecar | External, default off, nonauthorizing |
4343
| Full-Canon Myth v0.3.5 | Published optional companion | External, default off, terminal-only, nonauthorizing |
44-
| Generic Myth v0.2.0 | Ready to publish; not yet published | Separate optional companion; never embedded in R1 |
45-
| R1.0.1 | Ready to publish; not yet published | Corrected current reference; publication contract requires zero Myth payload |
44+
| Generic Myth v0.2.0 (`generic-myth-v0.2.0`) | Published optional companion | Separate, default-off, terminal-only, nonauthorizing; never embedded in R1 |
45+
| R1.0.1 (`r1.0.1-2026-08-17`) | Published corrected current reference | Publication contract requires zero Myth payload |
4646

4747
The exact historical, published, authorized, and frozen identities are in
4848
[`PUBLICATION_MANIFEST.json`](PUBLICATION_MANIFEST.json). A concrete identity
@@ -59,28 +59,30 @@ deployment.
5959

6060
- **Generic Myth Sidecar v0.2.0** is a generic mnemonic presentation with no
6161
named third-party expressive material. Its frozen exact-hash build has passed
62-
final tests and is authorized for separate publication on GitHub and Hugging
63-
Face; it is not yet represented as published.
62+
final tests and is published separately on GitHub and Hugging Face.
6463
- **Full-Canon Myth Sidecar v0.3.5** is an optional mixed-rights interpretive
6564
companion published separately from R1.
6665

67-
R1.0.1 will contain neither sidecar. The August 14 bytes are preserved rather
66+
R1.0.1 contains neither sidecar. The August 14 bytes are preserved rather
6867
than silently edited; the correction is a separately versioned successor.
6968

7069
## Verify before use
7170

72-
Run the repository evidence verifier in the phase you intend to validate:
71+
Run the repository evidence verifier for the current lifecycle phase:
7372

7473
```bash
75-
python3 -I -S -B tools/verify_repository_evidence.py --phase prepublication
74+
python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication
7675
```
7776

78-
Postpublication mode fails closed until every placeholder is replaced, both
79-
new release assets have anonymous redownload evidence, and the CAPA is closed
80-
with effectiveness evidence:
77+
This validates the published identities, scoped authorities, optional-sidecar
78+
boundaries, and current open CAPA state. Online mode additionally redownloads
79+
the exact GitHub assets and checks live release metadata; it does not create the
80+
missing Hugging Face redownload receipt, establish six-site effectiveness, or
81+
close the CAPA:
8182

8283
```bash
83-
python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication
84+
python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication \
85+
--online --download-dir /tmp/project-shadow-release-assets
8486
```
8587

8688
Exact Windows, macOS, and Linux instructions are in
@@ -95,6 +97,8 @@ CAPA `PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001` is
9597
Hugging Face redownload identity checks for the corrected artifacts plus live
9698
verification of the six Project Shadow public sites. See the
9799
[`CAPA record`](governance/CAPA_PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001_2026-08-17.json).
100+
Only after those criteria are evidenced may this state become
101+
`CLOSED_EFFECTIVE`.
98102

99103
## Scope boundary
100104

RELEASES.md

Lines changed: 14 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -4,21 +4,22 @@ Release assets are kept out of Git history and attached to separate GitHub
44
Releases. Automatically generated source ZIP/TAR archives are repository
55
snapshots, not Project Shadow release artifacts.
66

7-
## Current release plan
7+
## Current public releases
88

9-
Publication phase: **PREPUBLICATION**.
9+
Publication phase: **POSTPUBLICATION**. Effectiveness verification remains
10+
pending.
1011

1112
1. `generic-myth-v0.2.0` — Generic Myth Sidecar v0.2.0, optional public
1213
companion. Its final identity is frozen, its final tests pass, and its exact
13-
hash is authorized for separate GitHub and Hugging Face publication.
14+
hash is published separately on GitHub and Hugging Face.
1415
2. `r1.0.1-2026-08-17` — Project Shadow 1.0.1 R1 reference packaging
1516
correction. Its exact inner is admitted and its deterministic outer build is
16-
frozen and separately exact-hash authorized. It is ready to publish, not yet
17-
published.
17+
frozen, separately exact-hash authorized, and published on GitHub and
18+
Hugging Face.
1819

19-
The Generic sidecar must be published first. R1.0.1 must be published last so
20-
the corrected R1 becomes the latest release. Neither pending release is marked
21-
published in repository evidence before the public asset exists.
20+
The Generic sidecar was published first. R1.0.1 was published last so the
21+
corrected R1 is the latest release. Publication does not by itself verify
22+
anonymous redownload identity or close the packaging-boundary CAPA.
2223

2324
## Existing public releases
2425

@@ -32,16 +33,15 @@ Historical release notes and governance records remain in place. Nothing in
3233
the 2026-08-17 correction back-writes the August 14 authorization, status,
3334
redownload receipt, tags, or archive.
3435

35-
## Required publication sequence
36+
## Remaining effectiveness sequence
3637

3738
1. Preserve the recorded Generic, inner, and outer exact-hash authorities
3839
without broadening them.
39-
2. Run `tools/verify_repository_evidence.py --phase prepublication`.
40-
3. Publish Generic v0.2.0, then R1.0.1.
41-
4. Anonymously redownload the GitHub and Hugging Face assets and verify exact
40+
2. Run `tools/verify_repository_evidence.py --phase postpublication`.
41+
3. Anonymously redownload the GitHub and Hugging Face assets and verify exact
4242
byte counts and SHA-256 values.
43-
5. Verify all six public sites, add the redownload record, close the CAPA, and
44-
run postpublication mode.
43+
4. Verify all six public sites and add the redownload/effectiveness record.
44+
5. Close the CAPA only if every effectiveness criterion passes.
4545

4646
## Prospective custody procedure
4747

docs/VERIFY_RELEASES.md

Lines changed: 24 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -9,25 +9,30 @@ extracting an archive.
99

1010
## Current phase
1111

12-
The repository is in `PREPUBLICATION` for Generic Myth v0.2.0 and R1.0.1.
13-
Their final identities are concrete and frozen. Generic Myth v0.2.0 has scoped
14-
exact-hash publication authorization, and the exact Myth-free R1.0.1 inner is
15-
admitted. The final outer R1.0.1 archive also has its separate exact-hash
16-
publication authorization. The repository is `READY_TO_PUBLISH`, which is
17-
still a prepublication state; it does not assert that the public assets exist.
12+
The repository is in `POSTPUBLICATION` for Generic Myth v0.2.0 and R1.0.1.
13+
Their final identities are concrete, frozen, separately authorized, and
14+
published on GitHub and Hugging Face. The exact Myth-free R1.0.1 inner remains
15+
the scoped admitted packaging identity; its admission does not independently
16+
authorize publication.
1817

19-
Validate the repository state before any upload:
18+
Validate the current published repository state:
2019

2120
```bash
22-
python3 -I -S -B tools/verify_repository_evidence.py --phase prepublication
21+
python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication
2322
```
2423

25-
Postpublication mode must fail until final identities, exact-hash
26-
authorizations, anonymous redownload evidence, and CAPA closure are all
27-
present:
24+
The current postpublication state does not claim effectiveness. Anonymous
25+
GitHub and Hugging Face redownload identity evidence and six-site verification
26+
remain pending, so CAPA `PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001` remains
27+
`IMPLEMENTED_PENDING_EFFECTIVENESS`, not `CLOSED_EFFECTIVE`.
28+
29+
Online mode can redownload and verify the exact GitHub assets and live release
30+
metadata. It does not create the separate Hugging Face redownload evidence or
31+
close the CAPA:
2832

2933
```bash
30-
python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication
34+
python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication \
35+
--online --download-dir /tmp/project-shadow-release-assets
3136
```
3237

3338
## Published and preserved exact identities
@@ -43,20 +48,21 @@ not the corrected current reference because its nested runtime-family package
4348
included Generic Myth v0.1.1 carrying non-public metadata. Do not edit or
4449
silently replace the historical asset.
4550

46-
## Frozen prepublication identities
51+
## Published corrected identities
4752

4853
| File | Bytes | SHA-256 |
4954
|---|---:|---|
5055
| `Project_Shadow_Generic_Myth_Sidecar_v0.2.0_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip` | 93,676 | `6e7a362d4135f9d626dcfef463bfb1f7166226b3cf8a4c02a953ab39af1538bf` |
5156
| `Project_Shadow_R1.0.1_Runtime_Family_Myth_Decoupled_2026-08-17.zip` | 5,463,189 | `c8c32b12432c954b1a6f852c0c9f81bbbd40167e936be057d4c3de1a0aa3a623` |
5257
| `Project_Shadow_R1.0.1_Public_Reference_2026-08-17.zip` | 5,731,663 | `6f6f1e16d5e9a20e62403f14af7ce8629ce2d702528fb7f80aaf4a14deb7a1d1` |
5358

54-
The Generic identity has scoped GitHub/Hugging Face publication authorization.
59+
The Generic identity is published under scoped GitHub/Hugging Face publication
60+
authorization.
5561
The inner identity has the maintainer's scoped packaging admission, which
56-
explicitly does not authorize publication. The outer identity is recorded only
57-
with a separate exact-hash authorization covering GitHub, Hugging Face, the
58-
verified repository update, and six GPT Site updates. Neither authority permits
59-
production or operational deployment.
62+
explicitly does not authorize publication. The outer identity has a separate
63+
exact-hash authorization covering GitHub, Hugging Face, the verified repository
64+
update, and six GPT Site updates. Neither authority permits production or
65+
operational deployment.
6066

6167
## Windows PowerShell
6268

governance/PROJECT_SHADOW_GENERIC_MYTH_v0.2.0_PUBLIC_RELEASE_REFERENCE.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@
3838
"expected_asset_path": "releases/generic-myth-v0.2.0/Project_Shadow_Generic_Myth_Sidecar_v0.2.0_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip",
3939
"repository": "ProjectShadow/project-shadow-r1-reference"
4040
},
41-
"state": "READY_TO_PUBLISH"
41+
"state": "PUBLISHED"
4242
},
4343
"authorization_record": "governance/GENERIC_MYTH_v0.2.0_EXACT_HASH_PUBLIC_RELEASE_AUTHORIZATION_2026-08-17.json",
4444
"schema": "project-shadow.generic-myth-public-release-reference.v1",

governance/README.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -51,8 +51,12 @@ verification, or postpublication attestation.
5151
wording on all six public sites.
5252

5353
Concrete identity fields are not self-authorizing; the separate authority
54-
records supply the scoped decisions. `tools/verify_repository_evidence.py
55-
--phase postpublication` must still reject this ready-but-unpublished state.
54+
records supply the scoped decisions. Generic Myth v0.2.0 and R1.0.1 are now
55+
published on GitHub and Hugging Face, but publication is not CAPA effectiveness
56+
evidence. `tools/verify_repository_evidence.py --phase postpublication`
57+
therefore validates the published identities while preserving
58+
`IMPLEMENTED_PENDING_EFFECTIVENESS` until anonymous redownload and six-site
59+
criteria are evidenced.
5660

5761
The signed admission record did not self-authorize public release. The later
5862
authorization does not modify the signed record or the exact R1 archive; it

release-notes/GENERIC_MYTH_SIDECAR_v0.2.0.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
**READY TO PUBLISH · NOT YET PUBLISHED · OPTIONAL · DEFAULT OFF · TERMINAL-ONLY · NONAUTHORIZING**
1+
**PUBLISHED · OPTIONAL · DEFAULT OFF · TERMINAL-ONLY · NONAUTHORIZING**
22

33
# Project Shadow Generic Myth Sidecar v0.2.0 — Optional Public Companion
44

@@ -10,9 +10,9 @@
1010

1111
**SHA-256:** `6e7a362d4135f9d626dcfef463bfb1f7166226b3cf8a4c02a953ab39af1538bf`
1212

13-
The exact artifact above was built reproducibly, tested, frozen, and authorized
14-
for separate public release on GitHub and Hugging Face. This staged repository
15-
state is not evidence that the public uploads already exist.
13+
The exact artifact above was built reproducibly, tested, frozen, authorized,
14+
and published separately on GitHub and Hugging Face. Publication is not
15+
anonymous redownload identity evidence and does not close the CAPA.
1616

1717
## What it provides
1818

release-notes/PROJECT_SHADOW_R1_0_1_2026-08-17.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
**READY TO PUBLISH · NOT YET PUBLISHED · PACKAGING-BOUNDARY CORRECTION · BETA-ACTIVE-TESTING · PRELIVE**
1+
**PUBLISHED · PACKAGING-BOUNDARY CORRECTION · BETA-ACTIVE-TESTING · PRELIVE**
22

33
# Project Shadow 1.0.1 — R1 Reference Packaging Correction
44

@@ -11,9 +11,9 @@
1111
**SHA-256:** `6f6f1e16d5e9a20e62403f14af7ce8629ce2d702528fb7f80aaf4a14deb7a1d1`
1212

1313
The values above identify the final deterministic outer archive. The maintainer
14-
has separately authorized this exact filename, byte count, SHA-256, and tag for
15-
public release. This staged note does not assert that the public upload already
16-
exists.
14+
separately authorized this exact filename, byte count, SHA-256, and tag, and the
15+
artifact is published on GitHub and Hugging Face. Publication is not anonymous
16+
redownload identity evidence and does not close the CAPA.
1717

1818
## What this corrects
1919

0 commit comments

Comments
 (0)