From 6a26369168fb6436f7ccaafe883b5a7c20bf7f64 Mon Sep 17 00:00:00 2001 From: Phillip Linstrum Date: Tue, 18 Aug 2026 06:08:59 -0400 Subject: [PATCH 01/11] Align postpublication status: PUBLICATION_MANIFEST.json --- PUBLICATION_MANIFEST.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/PUBLICATION_MANIFEST.json b/PUBLICATION_MANIFEST.json index f13725f..ef95867 100644 --- a/PUBLICATION_MANIFEST.json +++ b/PUBLICATION_MANIFEST.json @@ -1,6 +1,6 @@ { "current_reference": { - "publication_state": "READY_TO_PUBLISH", + "publication_state": "PUBLISHED", "tag": "r1.0.1-2026-08-17" }, "expected_github_latest_tag": { @@ -15,8 +15,8 @@ "production_authorized": false, "safety_claimed": false }, - "publication_phase": "PREPUBLICATION", - "prepublication_state": "READY_TO_PUBLISH", + "postpublication_state": "PUBLISHED_PENDING_EFFECTIVENESS", + "publication_phase": "POSTPUBLICATION", "release_identity": "PROJECT SHADOW 1.0.1 / R1 REFERENCE / BETA-ACTIVE-TESTING / PRELIVE", "releases": [ { @@ -77,7 +77,7 @@ "current": true, "enabled_by_default": false, "order": 4, - "publication_state": "READY_TO_PUBLISH", + "publication_state": "PUBLISHED", "role": "OPTIONAL_GENERIC_COMPANION", "tag": "generic-myth-v0.2.0", "title": "Project Shadow Generic Myth Sidecar v0.2.0 — Optional Public Companion" @@ -92,7 +92,7 @@ "canonical_r1": true, "current": true, "order": 5, - "publication_state": "READY_TO_PUBLISH", + "publication_state": "PUBLISHED", "role": "R1_REFERENCE_CORRECTED", "tag": "r1.0.1-2026-08-17", "title": "Project Shadow 1.0.1 — R1 Reference Packaging Correction (PRELIVE)" From d4ce4bb6be08b29bbe32b0ae028d0c55bd72005d Mon Sep 17 00:00:00 2001 From: Phillip Linstrum Date: Tue, 18 Aug 2026 06:09:03 -0400 Subject: [PATCH 02/11] Align postpublication status: PUBLIC_RELEASE_STATUS_2026-08-17.json --- PUBLIC_RELEASE_STATUS_2026-08-17.json | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/PUBLIC_RELEASE_STATUS_2026-08-17.json b/PUBLIC_RELEASE_STATUS_2026-08-17.json index 3a435ea..b6bf5ee 100644 --- a/PUBLIC_RELEASE_STATUS_2026-08-17.json +++ b/PUBLIC_RELEASE_STATUS_2026-08-17.json @@ -9,7 +9,7 @@ "final_outer_identity_bound": true, "inner_exact_hash_admitted": true, "myth_payload_required": false, - "publication_state": "READY_TO_PUBLISH", + "publication_state": "PUBLISHED", "tag": "r1.0.1-2026-08-17", "zero_operational_descendant_bytes_changed": true }, @@ -19,7 +19,7 @@ "default_off": true, "final_hardened_identity_bound": true, "publication_authorization_recorded": true, - "publication_state": "READY_TO_PUBLISH", + "publication_state": "PUBLISHED", "required_for_r1": false, "tag": "generic-myth-v0.2.0", "terminal_only": true @@ -39,7 +39,7 @@ "production_authorized": false, "safety_claimed": false }, - "publication_phase": "PREPUBLICATION", + "publication_phase": "POSTPUBLICATION", "published_optional_companion": { "default_off": true, "filename": "Project_Shadow_Full_Canon_Myth_Sidecar_v0.3.5_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip", @@ -55,5 +55,5 @@ "governance/R1_0_1_OUTER_RELEASE_AUTHORIZATION_2026-08-17.json", "governance/CAPA_PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001_2026-08-17.json" ], - "warning": "READY_TO_PUBLISH is still PREPUBLICATION. Exact-hash authorities are recorded, but public release, anonymous redownload verification, six-site effectiveness checks, and CAPA closure have not yet occurred." + "warning": "Generic Myth v0.2.0 and R1.0.1 are published on GitHub and Hugging Face. Anonymous GitHub and Hugging Face redownload identity verification and six-site effectiveness checks remain pending; CAPA remains IMPLEMENTED_PENDING_EFFECTIVENESS and is not closed." } From a4fe62968ec854c3a8675c879195e887faa11203 Mon Sep 17 00:00:00 2001 From: Phillip Linstrum Date: Tue, 18 Aug 2026 06:09:07 -0400 Subject: [PATCH 03/11] Align postpublication status: README.md --- README.md | 48 ++++++++++++++++++++++++++---------------------- 1 file changed, 26 insertions(+), 22 deletions(-) diff --git a/README.md b/README.md index ecd3232..5cf2a01 100644 --- a/README.md +++ b/README.md @@ -9,17 +9,17 @@ **PROJECT SHADOW 1.0.1 / R1 REFERENCE / BETA-ACTIVE-TESTING / PRELIVE** -Project Shadow 1.0.1 is a packaging-boundary correction in preparation. Its -release design removes Myth from the R1 runtime-family package while preserving -all 27 active operational descendants byte-for-byte. The Generic Myth v0.2.0 -identity is frozen and authorized for separate publication, the exact Myth-free -inner family is admitted, and the final R1.0.1 outer identity is frozen. The -outer archive now has its own exact-hash publication authorization. The staged -repository is ready to publish, but no new artifact is represented as public -until the upload exists and can be independently redownloaded. - -No pending artifact is represented as published. The machine-readable phase is -[`PREPUBLICATION`](PUBLIC_RELEASE_STATUS_2026-08-17.json). +Project Shadow 1.0.1 is the corrected current R1 reference. It removes Myth +from the R1 runtime-family package while preserving all 27 active operational +descendants byte-for-byte. Generic Myth v0.2.0 is published separately as an +optional companion, the exact Myth-free inner family is admitted, and the final +R1.0.1 outer identity has its own exact-hash publication authorization. + +Generic Myth v0.2.0 and R1.0.1 now exist as public GitHub and Hugging Face +releases. Anonymous redownload identity verification and six-site effectiveness +checks remain pending. The machine-readable phase is +[`POSTPUBLICATION`](PUBLIC_RELEASE_STATUS_2026-08-17.json), and CAPA +`PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001` remains open. ## Current contact @@ -41,8 +41,8 @@ contact routes. | R1, 2026-08-14 | Preserved historical release; superseded as the current reference | Contains a historically nested Generic Myth v0.1.1 member whose own metadata was non-public; the released bytes remain immutable evidence | | Full-Canon Myth v0.3.4 | Preserved historical optional sidecar | External, default off, nonauthorizing | | Full-Canon Myth v0.3.5 | Published optional companion | External, default off, terminal-only, nonauthorizing | -| Generic Myth v0.2.0 | Ready to publish; not yet published | Separate optional companion; never embedded in R1 | -| R1.0.1 | Ready to publish; not yet published | Corrected current reference; publication contract requires zero Myth payload | +| Generic Myth v0.2.0 (`generic-myth-v0.2.0`) | Published optional companion | Separate, default-off, terminal-only, nonauthorizing; never embedded in R1 | +| R1.0.1 (`r1.0.1-2026-08-17`) | Published corrected current reference | Publication contract requires zero Myth payload | The exact historical, published, authorized, and frozen identities are in [`PUBLICATION_MANIFEST.json`](PUBLICATION_MANIFEST.json). A concrete identity @@ -59,28 +59,30 @@ deployment. - **Generic Myth Sidecar v0.2.0** is a generic mnemonic presentation with no named third-party expressive material. Its frozen exact-hash build has passed - final tests and is authorized for separate publication on GitHub and Hugging - Face; it is not yet represented as published. + final tests and is published separately on GitHub and Hugging Face. - **Full-Canon Myth Sidecar v0.3.5** is an optional mixed-rights interpretive companion published separately from R1. -R1.0.1 will contain neither sidecar. The August 14 bytes are preserved rather +R1.0.1 contains neither sidecar. The August 14 bytes are preserved rather than silently edited; the correction is a separately versioned successor. ## Verify before use -Run the repository evidence verifier in the phase you intend to validate: +Run the repository evidence verifier for the current lifecycle phase: ```bash -python3 -I -S -B tools/verify_repository_evidence.py --phase prepublication +python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication ``` -Postpublication mode fails closed until every placeholder is replaced, both -new release assets have anonymous redownload evidence, and the CAPA is closed -with effectiveness evidence: +This validates the published identities, scoped authorities, optional-sidecar +boundaries, and current open CAPA state. Online mode additionally redownloads +the exact GitHub assets and checks live release metadata; it does not create the +missing Hugging Face redownload receipt, establish six-site effectiveness, or +close the CAPA: ```bash -python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication +python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication \ + --online --download-dir /tmp/project-shadow-release-assets ``` Exact Windows, macOS, and Linux instructions are in @@ -95,6 +97,8 @@ CAPA `PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001` is Hugging Face redownload identity checks for the corrected artifacts plus live verification of the six Project Shadow public sites. See the [`CAPA record`](governance/CAPA_PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001_2026-08-17.json). +Only after those criteria are evidenced may this state become +`CLOSED_EFFECTIVE`. ## Scope boundary From a3081bcbd1ba39eac088f7c1c1ffa7f9ffc02b25 Mon Sep 17 00:00:00 2001 From: Phillip Linstrum Date: Tue, 18 Aug 2026 06:09:09 -0400 Subject: [PATCH 04/11] Align postpublication status: RELEASES.md --- RELEASES.md | 28 ++++++++++++++-------------- 1 file changed, 14 insertions(+), 14 deletions(-) diff --git a/RELEASES.md b/RELEASES.md index 1abf98e..cd42c18 100644 --- a/RELEASES.md +++ b/RELEASES.md @@ -4,21 +4,22 @@ Release assets are kept out of Git history and attached to separate GitHub Releases. Automatically generated source ZIP/TAR archives are repository snapshots, not Project Shadow release artifacts. -## Current release plan +## Current public releases -Publication phase: **PREPUBLICATION**. +Publication phase: **POSTPUBLICATION**. Effectiveness verification remains +pending. 1. `generic-myth-v0.2.0` — Generic Myth Sidecar v0.2.0, optional public companion. Its final identity is frozen, its final tests pass, and its exact - hash is authorized for separate GitHub and Hugging Face publication. + hash is published separately on GitHub and Hugging Face. 2. `r1.0.1-2026-08-17` — Project Shadow 1.0.1 R1 reference packaging correction. Its exact inner is admitted and its deterministic outer build is - frozen and separately exact-hash authorized. It is ready to publish, not yet - published. + frozen, separately exact-hash authorized, and published on GitHub and + Hugging Face. -The Generic sidecar must be published first. R1.0.1 must be published last so -the corrected R1 becomes the latest release. Neither pending release is marked -published in repository evidence before the public asset exists. +The Generic sidecar was published first. R1.0.1 was published last so the +corrected R1 is the latest release. Publication does not by itself verify +anonymous redownload identity or close the packaging-boundary CAPA. ## Existing public releases @@ -32,16 +33,15 @@ Historical release notes and governance records remain in place. Nothing in the 2026-08-17 correction back-writes the August 14 authorization, status, redownload receipt, tags, or archive. -## Required publication sequence +## Remaining effectiveness sequence 1. Preserve the recorded Generic, inner, and outer exact-hash authorities without broadening them. -2. Run `tools/verify_repository_evidence.py --phase prepublication`. -3. Publish Generic v0.2.0, then R1.0.1. -4. Anonymously redownload the GitHub and Hugging Face assets and verify exact +2. Run `tools/verify_repository_evidence.py --phase postpublication`. +3. Anonymously redownload the GitHub and Hugging Face assets and verify exact byte counts and SHA-256 values. -5. Verify all six public sites, add the redownload record, close the CAPA, and - run postpublication mode. +4. Verify all six public sites and add the redownload/effectiveness record. +5. Close the CAPA only if every effectiveness criterion passes. ## Prospective custody procedure From 7e793a7c21b07d4c2092e1e1f2f817eae7b6e7d9 Mon Sep 17 00:00:00 2001 From: Phillip Linstrum Date: Tue, 18 Aug 2026 06:09:10 -0400 Subject: [PATCH 05/11] Align postpublication status: docs/VERIFY_RELEASES.md --- docs/VERIFY_RELEASES.md | 42 +++++++++++++++++++++++------------------ 1 file changed, 24 insertions(+), 18 deletions(-) diff --git a/docs/VERIFY_RELEASES.md b/docs/VERIFY_RELEASES.md index bbe9c84..0da908c 100644 --- a/docs/VERIFY_RELEASES.md +++ b/docs/VERIFY_RELEASES.md @@ -9,25 +9,30 @@ extracting an archive. ## Current phase -The repository is in `PREPUBLICATION` for Generic Myth v0.2.0 and R1.0.1. -Their final identities are concrete and frozen. Generic Myth v0.2.0 has scoped -exact-hash publication authorization, and the exact Myth-free R1.0.1 inner is -admitted. The final outer R1.0.1 archive also has its separate exact-hash -publication authorization. The repository is `READY_TO_PUBLISH`, which is -still a prepublication state; it does not assert that the public assets exist. +The repository is in `POSTPUBLICATION` for Generic Myth v0.2.0 and R1.0.1. +Their final identities are concrete, frozen, separately authorized, and +published on GitHub and Hugging Face. The exact Myth-free R1.0.1 inner remains +the scoped admitted packaging identity; its admission does not independently +authorize publication. -Validate the repository state before any upload: +Validate the current published repository state: ```bash -python3 -I -S -B tools/verify_repository_evidence.py --phase prepublication +python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication ``` -Postpublication mode must fail until final identities, exact-hash -authorizations, anonymous redownload evidence, and CAPA closure are all -present: +The current postpublication state does not claim effectiveness. Anonymous +GitHub and Hugging Face redownload identity evidence and six-site verification +remain pending, so CAPA `PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001` remains +`IMPLEMENTED_PENDING_EFFECTIVENESS`, not `CLOSED_EFFECTIVE`. + +Online mode can redownload and verify the exact GitHub assets and live release +metadata. It does not create the separate Hugging Face redownload evidence or +close the CAPA: ```bash -python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication +python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication \ + --online --download-dir /tmp/project-shadow-release-assets ``` ## Published and preserved exact identities @@ -43,7 +48,7 @@ not the corrected current reference because its nested runtime-family package included Generic Myth v0.1.1 carrying non-public metadata. Do not edit or silently replace the historical asset. -## Frozen prepublication identities +## Published corrected identities | File | Bytes | SHA-256 | |---|---:|---| @@ -51,12 +56,13 @@ silently replace the historical asset. | `Project_Shadow_R1.0.1_Runtime_Family_Myth_Decoupled_2026-08-17.zip` | 5,463,189 | `c8c32b12432c954b1a6f852c0c9f81bbbd40167e936be057d4c3de1a0aa3a623` | | `Project_Shadow_R1.0.1_Public_Reference_2026-08-17.zip` | 5,731,663 | `6f6f1e16d5e9a20e62403f14af7ce8629ce2d702528fb7f80aaf4a14deb7a1d1` | -The Generic identity has scoped GitHub/Hugging Face publication authorization. +The Generic identity is published under scoped GitHub/Hugging Face publication +authorization. The inner identity has the maintainer's scoped packaging admission, which -explicitly does not authorize publication. The outer identity is recorded only -with a separate exact-hash authorization covering GitHub, Hugging Face, the -verified repository update, and six GPT Site updates. Neither authority permits -production or operational deployment. +explicitly does not authorize publication. The outer identity has a separate +exact-hash authorization covering GitHub, Hugging Face, the verified repository +update, and six GPT Site updates. Neither authority permits production or +operational deployment. ## Windows PowerShell From e200cce412c715635ce38de48884b06ef7adf725 Mon Sep 17 00:00:00 2001 From: Phillip Linstrum Date: Tue, 18 Aug 2026 06:09:12 -0400 Subject: [PATCH 06/11] Align postpublication status: governance/README.md --- governance/README.md | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/governance/README.md b/governance/README.md index 5275ffc..a2044d6 100644 --- a/governance/README.md +++ b/governance/README.md @@ -51,8 +51,12 @@ verification, or postpublication attestation. wording on all six public sites. Concrete identity fields are not self-authorizing; the separate authority -records supply the scoped decisions. `tools/verify_repository_evidence.py ---phase postpublication` must still reject this ready-but-unpublished state. +records supply the scoped decisions. Generic Myth v0.2.0 and R1.0.1 are now +published on GitHub and Hugging Face, but publication is not CAPA effectiveness +evidence. `tools/verify_repository_evidence.py --phase postpublication` +therefore validates the published identities while preserving +`IMPLEMENTED_PENDING_EFFECTIVENESS` until anonymous redownload and six-site +criteria are evidenced. The signed admission record did not self-authorize public release. The later authorization does not modify the signed record or the exact R1 archive; it From a840c7e811c86207b62735804bcb4e3a88ffe0b8 Mon Sep 17 00:00:00 2001 From: Phillip Linstrum Date: Tue, 18 Aug 2026 06:09:14 -0400 Subject: [PATCH 07/11] Align postpublication status: governance/PROJECT_SHADOW_GENERIC_MYTH_v0.2.0_PUBLIC_RELEASE_REFERENCE.json --- ...ECT_SHADOW_GENERIC_MYTH_v0.2.0_PUBLIC_RELEASE_REFERENCE.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/governance/PROJECT_SHADOW_GENERIC_MYTH_v0.2.0_PUBLIC_RELEASE_REFERENCE.json b/governance/PROJECT_SHADOW_GENERIC_MYTH_v0.2.0_PUBLIC_RELEASE_REFERENCE.json index d1e185f..73a6960 100644 --- a/governance/PROJECT_SHADOW_GENERIC_MYTH_v0.2.0_PUBLIC_RELEASE_REFERENCE.json +++ b/governance/PROJECT_SHADOW_GENERIC_MYTH_v0.2.0_PUBLIC_RELEASE_REFERENCE.json @@ -38,7 +38,7 @@ "expected_asset_path": "releases/generic-myth-v0.2.0/Project_Shadow_Generic_Myth_Sidecar_v0.2.0_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip", "repository": "ProjectShadow/project-shadow-r1-reference" }, - "state": "READY_TO_PUBLISH" + "state": "PUBLISHED" }, "authorization_record": "governance/GENERIC_MYTH_v0.2.0_EXACT_HASH_PUBLIC_RELEASE_AUTHORIZATION_2026-08-17.json", "schema": "project-shadow.generic-myth-public-release-reference.v1", From c590d2ed4ff8c98277bd3604a8ff871aeee2a8a4 Mon Sep 17 00:00:00 2001 From: Phillip Linstrum Date: Tue, 18 Aug 2026 06:09:15 -0400 Subject: [PATCH 08/11] Align postpublication status: release-notes/GENERIC_MYTH_SIDECAR_v0.2.0.md --- release-notes/GENERIC_MYTH_SIDECAR_v0.2.0.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/release-notes/GENERIC_MYTH_SIDECAR_v0.2.0.md b/release-notes/GENERIC_MYTH_SIDECAR_v0.2.0.md index 38b505d..0a64f1d 100644 --- a/release-notes/GENERIC_MYTH_SIDECAR_v0.2.0.md +++ b/release-notes/GENERIC_MYTH_SIDECAR_v0.2.0.md @@ -1,4 +1,4 @@ -**READY TO PUBLISH · NOT YET PUBLISHED · OPTIONAL · DEFAULT OFF · TERMINAL-ONLY · NONAUTHORIZING** +**PUBLISHED · OPTIONAL · DEFAULT OFF · TERMINAL-ONLY · NONAUTHORIZING** # Project Shadow Generic Myth Sidecar v0.2.0 — Optional Public Companion @@ -10,9 +10,9 @@ **SHA-256:** `6e7a362d4135f9d626dcfef463bfb1f7166226b3cf8a4c02a953ab39af1538bf` -The exact artifact above was built reproducibly, tested, frozen, and authorized -for separate public release on GitHub and Hugging Face. This staged repository -state is not evidence that the public uploads already exist. +The exact artifact above was built reproducibly, tested, frozen, authorized, +and published separately on GitHub and Hugging Face. Publication is not +anonymous redownload identity evidence and does not close the CAPA. ## What it provides From b9df2b3a11a340adef831285bdf0a33512490f85 Mon Sep 17 00:00:00 2001 From: Phillip Linstrum Date: Tue, 18 Aug 2026 06:09:17 -0400 Subject: [PATCH 09/11] Align postpublication status: release-notes/PROJECT_SHADOW_R1_0_1_2026-08-17.md --- release-notes/PROJECT_SHADOW_R1_0_1_2026-08-17.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/release-notes/PROJECT_SHADOW_R1_0_1_2026-08-17.md b/release-notes/PROJECT_SHADOW_R1_0_1_2026-08-17.md index 18858ab..076913a 100644 --- a/release-notes/PROJECT_SHADOW_R1_0_1_2026-08-17.md +++ b/release-notes/PROJECT_SHADOW_R1_0_1_2026-08-17.md @@ -1,4 +1,4 @@ -**READY TO PUBLISH · NOT YET PUBLISHED · PACKAGING-BOUNDARY CORRECTION · BETA-ACTIVE-TESTING · PRELIVE** +**PUBLISHED · PACKAGING-BOUNDARY CORRECTION · BETA-ACTIVE-TESTING · PRELIVE** # Project Shadow 1.0.1 — R1 Reference Packaging Correction @@ -11,9 +11,9 @@ **SHA-256:** `6f6f1e16d5e9a20e62403f14af7ce8629ce2d702528fb7f80aaf4a14deb7a1d1` The values above identify the final deterministic outer archive. The maintainer -has separately authorized this exact filename, byte count, SHA-256, and tag for -public release. This staged note does not assert that the public upload already -exists. +separately authorized this exact filename, byte count, SHA-256, and tag, and the +artifact is published on GitHub and Hugging Face. Publication is not anonymous +redownload identity evidence and does not close the CAPA. ## What this corrects From 48eb96d28a4766d940946d316a4839a2606b796a Mon Sep 17 00:00:00 2001 From: Phillip Linstrum Date: Tue, 18 Aug 2026 06:09:19 -0400 Subject: [PATCH 10/11] Align postpublication status: tools/verify_repository_evidence.py --- tools/verify_repository_evidence.py | 77 ++++++++++++++++++++++------- 1 file changed, 59 insertions(+), 18 deletions(-) diff --git a/tools/verify_repository_evidence.py b/tools/verify_repository_evidence.py index 36e6c81..e64112f 100644 --- a/tools/verify_repository_evidence.py +++ b/tools/verify_repository_evidence.py @@ -824,7 +824,7 @@ def require_document_markers(label: str, path: Path, markers: Iterable[str]) -> def validate_public_documentation( - phase: str = "PREPUBLICATION", + phase: str = "POSTPUBLICATION", *, pending_identities: bool = False, ) -> None: @@ -944,7 +944,7 @@ def validate_public_documentation( ROOT / "README.md", ( "POSTPUBLICATION", - "CLOSED_EFFECTIVE", + "IMPLEMENTED_PENDING_EFFECTIVENESS", "r1.0.1-2026-08-17", "generic-myth-v0.2.0", ), @@ -1002,7 +1002,7 @@ def validate_current_redownload( raise EvidenceError("redownload record lacks GitHub/Hugging Face coverage") -def verify_repository_metadata(phase: str = "PREPUBLICATION") -> list[dict[str, Any]]: +def verify_repository_metadata(phase: str = "POSTPUBLICATION") -> list[dict[str, Any]]: phase = phase_name(phase) manifest = require_object(load_json(PUBLICATION_MANIFEST), "PUBLICATION_MANIFEST.json") authorization = require_object(load_json(AUTHORIZATION), AUTHORIZATION.name) @@ -1498,20 +1498,51 @@ def verify_repository_metadata(phase: str = "PREPUBLICATION") -> list[dict[str, if outer_asset.get(key) != current_r1_asset[key]: raise EvidenceError(f"R1.0.1 outer authorization mismatch: {key}") validate_outer_authority(outer_authorization) + current_capa = current_status.get("capa", {}) + closure = capa.get("closure", {}) + capa_status = current_capa.get("status") if ( - current_status.get("publication_phase") != "POSTPUBLICATION" - or current_status.get("capa", {}).get("status") != "CLOSED_EFFECTIVE" - or current_status.get("capa", {}).get("effectiveness_verified") is not True - or capa.get("status") != "CLOSED_EFFECTIVE" - or capa.get("closure", {}).get("effectiveness_verified") is not True - or capa.get("closure", {}).get("verification_record") - != "governance/R1_0_1_PUBLIC_REDOWNLOAD_VERIFICATION_2026-08-17.json" + manifest.get("current_reference") + != { + "publication_state": "PUBLISHED", + "tag": "r1.0.1-2026-08-17", + } + or current_status.get("publication_phase") != "POSTPUBLICATION" + or current_status.get("generic_myth", {}).get("publication_state") + != "PUBLISHED" + or current_status.get("current_reference", {}).get("publication_state") + != "PUBLISHED" + or capa_status != capa.get("status") ): - raise EvidenceError("current status/CAPA postpublication closure mismatch") - validate_current_redownload( - require_object(load_json(CURRENT_REDOWNLOAD), CURRENT_REDOWNLOAD.name), - by_tag, - ) + raise EvidenceError("current status/CAPA postpublication state mismatch") + if capa_status == "IMPLEMENTED_PENDING_EFFECTIVENESS": + if ( + manifest.get("postpublication_state") + != "PUBLISHED_PENDING_EFFECTIVENESS" + or current_capa.get("effectiveness_verified") is not False + or closure.get("effectiveness_verified") is not False + or closure.get("closed_at") is not None + or closure.get("verification_record") is not None + ): + raise EvidenceError( + "pending-effectiveness postpublication state is inconsistent" + ) + elif capa_status == "CLOSED_EFFECTIVE": + if ( + manifest.get("postpublication_state") + != "PUBLISHED_EFFECTIVENESS_VERIFIED" + or current_capa.get("effectiveness_verified") is not True + or closure.get("effectiveness_verified") is not True + or closure.get("verification_record") + != "governance/R1_0_1_PUBLIC_REDOWNLOAD_VERIFICATION_2026-08-17.json" + ): + raise EvidenceError("current status/CAPA postpublication closure mismatch") + validate_current_redownload( + require_object(load_json(CURRENT_REDOWNLOAD), CURRENT_REDOWNLOAD.name), + by_tag, + ) + else: + raise EvidenceError(f"unsupported postpublication CAPA state: {capa_status!r}") validate_public_documentation(phase, pending_identities=pending_identities) return rows @@ -1748,7 +1779,11 @@ def verify_online( release_url = f"https://github.com/{repository}/releases/tag/{row['tag']}" check_link(release_url) verify_live_release_metadata(online_rows, expected_latest_tag) - if phase == "POSTPUBLICATION": + current_status = require_object(load_json(CURRENT_STATUS), CURRENT_STATUS.name) + if ( + phase == "POSTPUBLICATION" + and current_status.get("capa", {}).get("status") == "CLOSED_EFFECTIVE" + ): verify_public_site_release_links(rows) r1 = downloaded.get("R1_REFERENCE") @@ -1781,7 +1816,7 @@ def parse_args() -> argparse.Namespace: parser.add_argument( "--online", action="store_true", - help="redownload exact assets and check release/public-site URLs", + help="redownload exact assets and check phase-appropriate public URLs", ) parser.add_argument( "--download-dir", @@ -1843,8 +1878,14 @@ def main() -> int: print("PASS: nonclaim scan") if args.online: print("PASS: exact published assets and release metadata") - if phase == "POSTPUBLICATION": + current_status = require_object(load_json(CURRENT_STATUS), CURRENT_STATUS.name) + if ( + phase == "POSTPUBLICATION" + and current_status.get("capa", {}).get("status") == "CLOSED_EFFECTIVE" + ): print("PASS: six public-site release links") + elif phase == "POSTPUBLICATION": + print("INFO: six-site CAPA effectiveness verification remains pending") else: print("INFO: network verification skipped (use --online --download-dir DIR)") return 0 From ae9c408b44940a2f4dca6cddb59a5964b5a3ffdd Mon Sep 17 00:00:00 2001 From: Phillip Linstrum Date: Tue, 18 Aug 2026 06:09:21 -0400 Subject: [PATCH 11/11] Align postpublication status: tests/test_verify_repository_evidence.py --- tests/test_verify_repository_evidence.py | 49 +++++++++++++++++++----- 1 file changed, 39 insertions(+), 10 deletions(-) diff --git a/tests/test_verify_repository_evidence.py b/tests/test_verify_repository_evidence.py index f43e16d..cee31f4 100644 --- a/tests/test_verify_repository_evidence.py +++ b/tests/test_verify_repository_evidence.py @@ -23,11 +23,17 @@ class RepositoryEvidenceTests(unittest.TestCase): def test_current_repository_metadata_agrees(self) -> None: self.assertGreaterEqual(VERIFIER.parse_all_json(), 1) - rows = VERIFIER.verify_repository_metadata("PREPUBLICATION") + rows = VERIFIER.verify_repository_metadata("POSTPUBLICATION") self.assertEqual([row["order"] for row in rows], [1, 2, 3, 4, 5]) self.assertEqual( [row["tag"] for row in VERIFIER.published_rows(rows)], - ["myth-v0.3.4", "r1-2026-08-14", "myth-v0.3.5"], + [ + "myth-v0.3.4", + "r1-2026-08-14", + "myth-v0.3.5", + "generic-myth-v0.2.0", + "r1.0.1-2026-08-17", + ], ) self.assertEqual(VERIFIER.prohibited_claim_findings(), []) @@ -40,12 +46,35 @@ def test_historical_public_release_verifier_remains_byte_pinned(self) -> None: "f1358db6c824319501d0eabf341174eb96217e5d2545d9ac908a81d338c8afa8", ) - def test_ready_prepublication_has_no_release_placeholders(self) -> None: + def test_published_postpublication_has_no_release_placeholders(self) -> None: self.assertEqual(VERIFIER.release_placeholder_findings(), []) - def test_postpublication_mode_rejects_prepublication_manifest(self) -> None: + def test_prepublication_mode_rejects_postpublication_manifest(self) -> None: with self.assertRaisesRegex(VERIFIER.EvidenceError, "manifest phase mismatch"): - VERIFIER.verify_repository_metadata("POSTPUBLICATION") + VERIFIER.verify_repository_metadata("PREPUBLICATION") + + def test_postpublication_keeps_capa_pending_effectiveness(self) -> None: + status = json.loads(VERIFIER.CURRENT_STATUS.read_text(encoding="utf-8")) + capa = json.loads(VERIFIER.CAPA_RECORD.read_text(encoding="utf-8")) + self.assertEqual(status["publication_phase"], "POSTPUBLICATION") + self.assertEqual(status["capa"]["status"], "IMPLEMENTED_PENDING_EFFECTIVENESS") + self.assertFalse(status["capa"]["effectiveness_verified"]) + self.assertEqual(capa["status"], "IMPLEMENTED_PENDING_EFFECTIVENESS") + self.assertFalse(capa["closure"]["effectiveness_verified"]) + self.assertIsNone(capa["closure"]["verification_record"]) + + def test_false_postpublication_capa_closure_fails_closed(self) -> None: + status = json.loads(VERIFIER.CURRENT_STATUS.read_text(encoding="utf-8")) + status["capa"]["status"] = "CLOSED_EFFECTIVE" + with tempfile.TemporaryDirectory(prefix="shadow-capa-status-test-") as temp: + mutated = Path(temp) / "PUBLIC_RELEASE_STATUS_2026-08-17.json" + mutated.write_text(json.dumps(status), encoding="utf-8") + with mock.patch.object(VERIFIER, "CURRENT_STATUS", mutated): + with self.assertRaisesRegex( + VERIFIER.EvidenceError, + "current status/CAPA postpublication state mismatch", + ): + VERIFIER.verify_repository_metadata("POSTPUBLICATION") def test_generic_exact_identity_mutation_fails_closed(self) -> None: manifest = json.loads(VERIFIER.PUBLICATION_MANIFEST.read_text(encoding="utf-8")) @@ -63,7 +92,7 @@ def test_generic_exact_identity_mutation_fails_closed(self) -> None: VERIFIER.EvidenceError, "release notes for generic-myth-v0.2.0 omit", ): - VERIFIER.verify_repository_metadata("PREPUBLICATION") + VERIFIER.verify_repository_metadata("POSTPUBLICATION") def test_outer_authorized_action_mutation_fails_closed(self) -> None: record = json.loads(VERIFIER.OUTER_AUTHORIZATION.read_text(encoding="utf-8")) @@ -76,7 +105,7 @@ def test_outer_authorized_action_mutation_fails_closed(self) -> None: VERIFIER.EvidenceError, "outer authorization scope mismatch", ): - VERIFIER.verify_repository_metadata("PREPUBLICATION") + VERIFIER.verify_repository_metadata("POSTPUBLICATION") def test_generic_authorization_wording_mutation_fails_closed(self) -> None: record = json.loads(VERIFIER.GENERIC_AUTHORIZATION.read_text(encoding="utf-8")) @@ -89,7 +118,7 @@ def test_generic_authorization_wording_mutation_fails_closed(self) -> None: VERIFIER.EvidenceError, "Generic Myth maintainer confirmation wording mismatch", ): - VERIFIER.verify_repository_metadata("PREPUBLICATION") + VERIFIER.verify_repository_metadata("POSTPUBLICATION") def test_inner_admission_wording_mutation_fails_closed(self) -> None: record = json.loads(VERIFIER.INNER_ADMISSION.read_text(encoding="utf-8")) @@ -102,7 +131,7 @@ def test_inner_admission_wording_mutation_fails_closed(self) -> None: VERIFIER.EvidenceError, "inner maintainer confirmation wording mismatch", ): - VERIFIER.verify_repository_metadata("PREPUBLICATION") + VERIFIER.verify_repository_metadata("POSTPUBLICATION") def test_generic_release_note_identity_removal_fails_closed(self) -> None: original_path = VERIFIER.RELEASE_NOTES["generic-myth-v0.2.0"] @@ -119,7 +148,7 @@ def test_generic_release_note_identity_removal_fails_closed(self) -> None: VERIFIER.EvidenceError, "release notes for generic-myth-v0.2.0 omit", ): - VERIFIER.verify_repository_metadata("PREPUBLICATION") + VERIFIER.verify_repository_metadata("POSTPUBLICATION") def test_rekor_documentation_mutation_fails_closed(self) -> None: original = VERIFIER.VERIFICATION_GUIDE.read_text(encoding="utf-8")