Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
66 changes: 63 additions & 3 deletions PUBLICATION_MANIFEST.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,12 @@
{
"authorization_receipt": "governance/RELEASE_AUTHORIZATION_2026-08-14.json",
"current_reference": {
"publication_state": "READY_TO_PUBLISH",
"tag": "r1.0.1-2026-08-17"
},
"expected_github_latest_tag": {
"postpublication": "r1.0.1-2026-08-17",
"prepublication": "r1-2026-08-14"
},
"nonclaims": {
"certification_claimed": false,
"efficacy_claimed": false,
Expand All @@ -8,7 +15,9 @@
"production_authorized": false,
"safety_claimed": false
},
"release_identity": "PROJECT SHADOW 1.0 / R1 REFERENCE / BETA-ACTIVE-TESTING / PRELIVE",
"publication_phase": "PREPUBLICATION",
"prepublication_state": "READY_TO_PUBLISH",
"release_identity": "PROJECT SHADOW 1.0.1 / R1 REFERENCE / BETA-ACTIVE-TESTING / PRELIVE",
"releases": [
{
"asset": {
Expand All @@ -18,8 +27,10 @@
"sha256": "3c8c8c0d3d9582c76b685c1b685260cc8179478ab310037c858b46257aa314c7"
},
"canonical_r1": false,
"current": false,
"enabled_by_default": false,
"order": 1,
"publication_state": "PUBLISHED_HISTORICAL",
"role": "OPTIONAL_EXTERNAL_RESEARCH_SIDECAR",
"tag": "myth-v0.3.4",
"title": "Project Shadow Myth Sidecar v0.3.4 — Optional External Research"
Expand All @@ -32,12 +43,61 @@
"sha256": "2f8fe1530b6a83294d15011df95853aaecf08fa4dba756f0c2e91dd089e1b1ec"
},
"canonical_r1": true,
"current": false,
"order": 2,
"publication_state": "PUBLISHED_HISTORICAL_SUPERSEDED",
"role": "R1_REFERENCE",
"tag": "r1-2026-08-14",
"title": "Project Shadow 1.0 — R1 Reference (PRELIVE)"
},
{
"asset": {
"bytes": 1428812,
"download_url": "https://github.com/PauseBeforeHarmProtocol/Project-Shadow/releases/download/myth-v0.3.5/Project_Shadow_Full_Canon_Myth_Sidecar_v0.3.5_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip",
"filename": "Project_Shadow_Full_Canon_Myth_Sidecar_v0.3.5_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip",
"sha256": "2b55867fe7c502a0defd8d6f2e9b53fbd1caaf1b0f225a438bd45b04a3e7bae2"
},
"canonical_r1": false,
"current": true,
"enabled_by_default": false,
"order": 3,
"publication_state": "PUBLISHED",
"role": "OPTIONAL_FULL_CANON_COMPANION",
"tag": "myth-v0.3.5",
"title": "Project Shadow Full-Canon Myth Sidecar v0.3.5 — Optional Public Companion"
},
{
"asset": {
"bytes": 93676,
"download_url": "https://github.com/PauseBeforeHarmProtocol/Project-Shadow/releases/download/generic-myth-v0.2.0/Project_Shadow_Generic_Myth_Sidecar_v0.2.0_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip",
"filename": "Project_Shadow_Generic_Myth_Sidecar_v0.2.0_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip",
"sha256": "6e7a362d4135f9d626dcfef463bfb1f7166226b3cf8a4c02a953ab39af1538bf"
},
"canonical_r1": false,
"current": true,
"enabled_by_default": false,
"order": 4,
"publication_state": "READY_TO_PUBLISH",
"role": "OPTIONAL_GENERIC_COMPANION",
"tag": "generic-myth-v0.2.0",
"title": "Project Shadow Generic Myth Sidecar v0.2.0 — Optional Public Companion"
},
{
"asset": {
"bytes": 5731663,
"download_url": "https://github.com/PauseBeforeHarmProtocol/Project-Shadow/releases/download/r1.0.1-2026-08-17/Project_Shadow_R1.0.1_Public_Reference_2026-08-17.zip",
"filename": "Project_Shadow_R1.0.1_Public_Reference_2026-08-17.zip",
"sha256": "6f6f1e16d5e9a20e62403f14af7ce8629ce2d702528fb7f80aaf4a14deb7a1d1"
},
"canonical_r1": true,
"current": true,
"order": 5,
"publication_state": "READY_TO_PUBLISH",
"role": "R1_REFERENCE_CORRECTED",
"tag": "r1.0.1-2026-08-17",
"title": "Project Shadow 1.0.1 — R1 Reference Packaging Correction (PRELIVE)"
}
],
"repository": "PauseBeforeHarmProtocol/Project-Shadow",
"schema": "project-shadow.publication-manifest.v1"
"schema": "project-shadow.publication-manifest.v2"
}
59 changes: 59 additions & 0 deletions PUBLIC_RELEASE_STATUS_2026-08-17.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,59 @@
{
"capa": {
"effectiveness_verified": false,
"id": "PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001",
"status": "IMPLEMENTED_PENDING_EFFECTIVENESS"
},
"current_reference": {
"active_descendant_count": 27,
"final_outer_identity_bound": true,
"inner_exact_hash_admitted": true,
"myth_payload_required": false,
"publication_state": "READY_TO_PUBLISH",
"tag": "r1.0.1-2026-08-17",
"zero_operational_descendant_bytes_changed": true
},
"derived_record": true,
"generic_myth": {
"canonical_r1_component": false,
"default_off": true,
"final_hardened_identity_bound": true,
"publication_authorization_recorded": true,
"publication_state": "READY_TO_PUBLISH",
"required_for_r1": false,
"tag": "generic-myth-v0.2.0",
"terminal_only": true
},
"historical_boundary": {
"affected_release_mutated": false,
"affected_release_sha256": "2f8fe1530b6a83294d15011df95853aaecf08fa4dba756f0c2e91dd089e1b1ec",
"affected_release_tag": "r1-2026-08-14",
"affected_release_treatment": "IMMUTABLE_HISTORICAL_EVIDENCE_SUPERSEDED_BY_SEPARATELY_VERSIONED_SUCCESSOR",
"finding": "A nested Generic Myth v0.1.1 member was physically present while its own metadata classified it as non-public and excluded from public manufacture."
},
"nonclaims": {
"certification_claimed": false,
"efficacy_claimed": false,
"legal_compliance_claimed": false,
"operational_deployment_authorized": false,
"production_authorized": false,
"safety_claimed": false
},
"publication_phase": "PREPUBLICATION",
"published_optional_companion": {
"default_off": true,
"filename": "Project_Shadow_Full_Canon_Myth_Sidecar_v0.3.5_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip",
"sha256": "2b55867fe7c502a0defd8d6f2e9b53fbd1caaf1b0f225a438bd45b04a3e7bae2",
"tag": "myth-v0.3.5"
},
"schema": "project-shadow.current-release-status.v1",
"source_records": [
"PUBLICATION_MANIFEST.json",
"governance/PROJECT_SHADOW_GENERIC_MYTH_v0.2.0_PUBLIC_RELEASE_REFERENCE.json",
"governance/GENERIC_MYTH_v0.2.0_EXACT_HASH_PUBLIC_RELEASE_AUTHORIZATION_2026-08-17.json",
"governance/R1_0_1_INNER_EXACT_HASH_ADMISSION_2026-08-17.json",
"governance/R1_0_1_OUTER_RELEASE_AUTHORIZATION_2026-08-17.json",
"governance/CAPA_PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001_2026-08-17.json"
],
"warning": "READY_TO_PUBLISH is still PREPUBLICATION. Exact-hash authorities are recorded, but public release, anonymous redownload verification, six-site effectiveness checks, and CAPA closure have not yet occurred."
}
147 changes: 84 additions & 63 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,94 +3,115 @@
> **Mixed-rights repository.** This repository is not one blanket
> Apache-2.0 work. Apache-2.0 applies only to eligible original software;
> CC BY 4.0 applies only to eligible original documentation and
> machine-readable controls. Preserved governance evidence and both release
> machine-readable controls. Preserved governance evidence and release
> archives retain their own attached or path-scoped terms. Read
> [`RIGHTS.md`](RIGHTS.md) before reuse.

**PROJECT SHADOW 1.0 / R1 REFERENCE / BETA-ACTIVE-TESTING / PRELIVE**
**PROJECT SHADOW 1.0.1 / R1 REFERENCE / BETA-ACTIVE-TESTING / PRELIVE**

This clean-history repository is the public landing surface for two exact,
separately distributed Project Shadow artifacts. It contains release metadata,
governance evidence, integrity instructions, and nonclaim boundaries. It does
not contain the release ZIPs in Git history; those are attached to their
respective GitHub Releases.
Project Shadow 1.0.1 is a packaging-boundary correction in preparation. Its
release design removes Myth from the R1 runtime-family package while preserving
all 27 active operational descendants byte-for-byte. The Generic Myth v0.2.0
identity is frozen and authorized for separate publication, the exact Myth-free
inner family is admitted, and the final R1.0.1 outer identity is frozen. The
outer archive now has its own exact-hash publication authorization. The staged
repository is ready to publish, but no new artifact is represented as public
until the upload exists and can be independently redownloaded.

No pending artifact is represented as published. The machine-readable phase is
[`PREPUBLICATION`](PUBLIC_RELEASE_STATUS_2026-08-17.json).

## Current contact

All new Project Shadow correspondence should use
**`projectshadowqa@protonmail.com`**.

Use `[CORRECTION]`, `[CAPA]`, `[SECURITY]`, `[RESEARCH]`, `[PRESS]`,
`[COLLABORATION]`, or `[CONDUCT]` in the subject line. The full intake and
privacy rules are in
[`CONTACT_AND_CORRECTIONS.md`](CONTACT_AND_CORRECTIONS.md), with a
machine-readable status in
[`PUBLIC_CONTACT_STATUS_2026-08-17.json`](PUBLIC_CONTACT_STATUS_2026-08-17.json).
`[COLLABORATION]`, or `[CONDUCT]` in the subject line. See
[`CONTACT_AND_CORRECTIONS.md`](CONTACT_AND_CORRECTIONS.md).

Historical addresses and certificate identities may remain inside exact-hash,
signed, frozen, or quoted evidence. They are preserved for custody and
verification and are not current contact routes.

## Exact releases

| Artifact | Role | Bytes | SHA-256 |
|---|---|---:|---|
| `Project_Shadow_R1_Public_Release_Candidate_2026-08-14.zip` | Canonical R1 reference release | 7,679,812 | `2f8fe1530b6a83294d15011df95853aaecf08fa4dba756f0c2e91dd089e1b1ec` |
| `Project_Shadow_Full_Canon_Myth_Sidecar_v0.3.4_OPTIONAL_EXTERNAL_RESEARCH_2026-08-14.zip` | Optional external research sidecar; separate from R1 and default off | 1,418,194 | `3c8c8c0d3d9582c76b685c1b685260cc8179478ab310037c858b46257aa314c7` |

The R1 filename retains the word `Candidate` because publication preserves the
authorized bytes exactly. The archive's internal status was written before the
separate exact-hash authorization. That external authorization is recorded in
[`governance/RELEASE_AUTHORIZATION_2026-08-14.json`](governance/RELEASE_AUTHORIZATION_2026-08-14.json).
The archive itself must not be rewritten to change its internal status.
The resolved, machine-readable state above that preserved gate is recorded in
[`PUBLIC_RELEASE_STATUS_2026-08-14.json`](PUBLIC_RELEASE_STATUS_2026-08-14.json).
The historical unsigned commit/tag facts and the later commit-bound attestation
are recorded in
[`governance/POST_PUBLICATION_ATTESTATION_2026-08-15.json`](governance/POST_PUBLICATION_ATTESTATION_2026-08-15.json).

## Download order and separation

The optional sidecar is published first under tag `myth-v0.3.4`. The canonical
R1 release is published last under tag `r1-2026-08-14` so that R1 is the latest
release. The sidecar is not embedded in R1, is not an admitted R1 descendant,
does not claim R1 conformance, and is distributed under its own mixed-rights
terms.
signed, frozen, or quoted evidence. They are custody evidence, not current
contact routes.

## Release state

| Artifact | State | Boundary |
|---|---|---|
| R1, 2026-08-14 | Preserved historical release; superseded as the current reference | Contains a historically nested Generic Myth v0.1.1 member whose own metadata was non-public; the released bytes remain immutable evidence |
| Full-Canon Myth v0.3.4 | Preserved historical optional sidecar | External, default off, nonauthorizing |
| Full-Canon Myth v0.3.5 | Published optional companion | External, default off, terminal-only, nonauthorizing |
| Generic Myth v0.2.0 | Ready to publish; not yet published | Separate optional companion; never embedded in R1 |
| R1.0.1 | Ready to publish; not yet published | Corrected current reference; publication contract requires zero Myth payload |

The exact historical, published, authorized, and frozen identities are in
[`PUBLICATION_MANIFEST.json`](PUBLICATION_MANIFEST.json). A concrete identity
does not by itself authorize publication; consult its authority record and
publication state.

## Myth is optional

Project Shadow does not require Myth. Both Myth companions are separate,
explicitly enabled, default-off presentation layers. Neither can provide
evidence, authority, a gate result, score, routing input, tool argument,
approval, or action. No companion is authorized for production or operational
deployment.

- **Generic Myth Sidecar v0.2.0** is a generic mnemonic presentation with no
named third-party expressive material. Its frozen exact-hash build has passed
final tests and is authorized for separate publication on GitHub and Hugging
Face; it is not yet represented as published.
- **Full-Canon Myth Sidecar v0.3.5** is an optional mixed-rights interpretive
companion published separately from R1.

R1.0.1 will contain neither sidecar. The August 14 bytes are preserved rather
than silently edited; the correction is a separately versioned successor.

## Verify before use

Verify the downloaded ZIP's byte count and SHA-256 before extracting it. Then
run the current repository verifier against the outer ZIP so its prospective
archive-preflight limits apply, followed by the frozen verifier embedded in the
extracted package. Exact Windows, macOS, and Linux instructions are in
[`docs/VERIFY_RELEASES.md`](docs/VERIFY_RELEASES.md).
Run the repository evidence verifier in the phase you intend to validate:

```bash
python3 -I -S -B tools/verify_repository_evidence.py --phase prepublication
```

Postpublication mode fails closed until every placeholder is replaced, both
new release assets have anonymous redownload evidence, and the CAPA is closed
with effectiveness evidence:

```bash
python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication
```

Exact Windows, macOS, and Linux instructions are in
[`docs/VERIFY_RELEASES.md`](docs/VERIFY_RELEASES.md). The historical
[`tools/verify_public_release.py`](tools/verify_public_release.py) remains
pinned to the August 14 artifact; it is not silently retargeted to R1.0.1.

## CAPA state

CAPA `PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001` is
**IMPLEMENTED_PENDING_EFFECTIVENESS**. Closure requires exact public GitHub and
Hugging Face redownload identity checks for the corrected artifacts plus live
verification of the six Project Shadow public sites. See the
[`CAPA record`](governance/CAPA_PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001_2026-08-17.json).

## Scope boundary

Public release is authorized only within `PROJECT SHADOW 1.0 / R1 REFERENCE /
BETA-ACTIVE-TESTING / PRELIVE`. This release does not authorize production or
operational deployment, efficacy, safety, certification, or legal-compliance
claims. See [`docs/SCOPE_AND_NONCLAIMS.md`](docs/SCOPE_AND_NONCLAIMS.md).
This work remains `BETA-ACTIVE-TESTING / PRELIVE`. It does not authorize
production or operational deployment and does not claim efficacy, safety,
certification, or legal compliance. See
[`docs/SCOPE_AND_NONCLAIMS.md`](docs/SCOPE_AND_NONCLAIMS.md).

Current sole-maintainer authority, the absence of a designated successor, the
non-authority of AI and automation, and the fail-closed stale-after date are
recorded in
[`governance/MAINTAINER_CONTINUITY.md`](governance/MAINTAINER_CONTINUITY.md).

## Rights

The R1 archive and the external sidecar each contain controlling notices,
licenses, manifests, and provenance records. The repository does not apply an
outer blanket license to either archive and does not grant third-party rights,
affiliation, endorsement, or legal clearance. Read [`RIGHTS.md`](RIGHTS.md)
before redistribution or adaptation.

## Participate and challenge

Technical criticism, correction evidence, false positives, false negatives,
and adverse results are welcome. Outside criticism is evidence to evaluate,
not hostility to suppress. Start with [`CONTRIBUTING.md`](CONTRIBUTING.md), use
the matching issue form, or email `projectshadowqa@protonmail.com` with the
appropriate subject prefix. Report vulnerabilities privately under
[`SECURITY.md`](SECURITY.md); never place exploit details or private evidence
in a public issue.
and adverse results are welcome. Start with
[`CONTRIBUTING.md`](CONTRIBUTING.md), use the matching issue form, or email the
current contact with the appropriate subject prefix. Report vulnerabilities
privately under [`SECURITY.md`](SECURITY.md).
Loading
Loading