Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions PUBLICATION_MANIFEST.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"current_reference": {
"publication_state": "READY_TO_PUBLISH",
"publication_state": "PUBLISHED",
"tag": "r1.0.1-2026-08-17"
},
"expected_github_latest_tag": {
Expand All @@ -15,8 +15,8 @@
"production_authorized": false,
"safety_claimed": false
},
"publication_phase": "PREPUBLICATION",
"prepublication_state": "READY_TO_PUBLISH",
"postpublication_state": "PUBLISHED_PENDING_EFFECTIVENESS",
"publication_phase": "POSTPUBLICATION",
"release_identity": "PROJECT SHADOW 1.0.1 / R1 REFERENCE / BETA-ACTIVE-TESTING / PRELIVE",
"releases": [
{
Expand Down Expand Up @@ -77,7 +77,7 @@
"current": true,
"enabled_by_default": false,
"order": 4,
"publication_state": "READY_TO_PUBLISH",
"publication_state": "PUBLISHED",
"role": "OPTIONAL_GENERIC_COMPANION",
"tag": "generic-myth-v0.2.0",
"title": "Project Shadow Generic Myth Sidecar v0.2.0 — Optional Public Companion"
Expand All @@ -92,7 +92,7 @@
"canonical_r1": true,
"current": true,
"order": 5,
"publication_state": "READY_TO_PUBLISH",
"publication_state": "PUBLISHED",
"role": "R1_REFERENCE_CORRECTED",
"tag": "r1.0.1-2026-08-17",
"title": "Project Shadow 1.0.1 — R1 Reference Packaging Correction (PRELIVE)"
Expand Down
8 changes: 4 additions & 4 deletions PUBLIC_RELEASE_STATUS_2026-08-17.json
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@
"final_outer_identity_bound": true,
"inner_exact_hash_admitted": true,
"myth_payload_required": false,
"publication_state": "READY_TO_PUBLISH",
"publication_state": "PUBLISHED",
"tag": "r1.0.1-2026-08-17",
"zero_operational_descendant_bytes_changed": true
},
Expand All @@ -19,7 +19,7 @@
"default_off": true,
"final_hardened_identity_bound": true,
"publication_authorization_recorded": true,
"publication_state": "READY_TO_PUBLISH",
"publication_state": "PUBLISHED",
"required_for_r1": false,
"tag": "generic-myth-v0.2.0",
"terminal_only": true
Expand All @@ -39,7 +39,7 @@
"production_authorized": false,
"safety_claimed": false
},
"publication_phase": "PREPUBLICATION",
"publication_phase": "POSTPUBLICATION",
"published_optional_companion": {
"default_off": true,
"filename": "Project_Shadow_Full_Canon_Myth_Sidecar_v0.3.5_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip",
Expand All @@ -55,5 +55,5 @@
"governance/R1_0_1_OUTER_RELEASE_AUTHORIZATION_2026-08-17.json",
"governance/CAPA_PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001_2026-08-17.json"
],
"warning": "READY_TO_PUBLISH is still PREPUBLICATION. Exact-hash authorities are recorded, but public release, anonymous redownload verification, six-site effectiveness checks, and CAPA closure have not yet occurred."
"warning": "Generic Myth v0.2.0 and R1.0.1 are published on GitHub and Hugging Face. Anonymous GitHub and Hugging Face redownload identity verification and six-site effectiveness checks remain pending; CAPA remains IMPLEMENTED_PENDING_EFFECTIVENESS and is not closed."
}
48 changes: 26 additions & 22 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,17 +9,17 @@

**PROJECT SHADOW 1.0.1 / R1 REFERENCE / BETA-ACTIVE-TESTING / PRELIVE**

Project Shadow 1.0.1 is a packaging-boundary correction in preparation. Its
release design removes Myth from the R1 runtime-family package while preserving
all 27 active operational descendants byte-for-byte. The Generic Myth v0.2.0
identity is frozen and authorized for separate publication, the exact Myth-free
inner family is admitted, and the final R1.0.1 outer identity is frozen. The
outer archive now has its own exact-hash publication authorization. The staged
repository is ready to publish, but no new artifact is represented as public
until the upload exists and can be independently redownloaded.

No pending artifact is represented as published. The machine-readable phase is
[`PREPUBLICATION`](PUBLIC_RELEASE_STATUS_2026-08-17.json).
Project Shadow 1.0.1 is the corrected current R1 reference. It removes Myth
from the R1 runtime-family package while preserving all 27 active operational
descendants byte-for-byte. Generic Myth v0.2.0 is published separately as an
optional companion, the exact Myth-free inner family is admitted, and the final
R1.0.1 outer identity has its own exact-hash publication authorization.

Generic Myth v0.2.0 and R1.0.1 now exist as public GitHub and Hugging Face
releases. Anonymous redownload identity verification and six-site effectiveness
checks remain pending. The machine-readable phase is
[`POSTPUBLICATION`](PUBLIC_RELEASE_STATUS_2026-08-17.json), and CAPA
`PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001` remains open.

## Current contact

Expand All @@ -41,8 +41,8 @@ contact routes.
| R1, 2026-08-14 | Preserved historical release; superseded as the current reference | Contains a historically nested Generic Myth v0.1.1 member whose own metadata was non-public; the released bytes remain immutable evidence |
| Full-Canon Myth v0.3.4 | Preserved historical optional sidecar | External, default off, nonauthorizing |
| Full-Canon Myth v0.3.5 | Published optional companion | External, default off, terminal-only, nonauthorizing |
| Generic Myth v0.2.0 | Ready to publish; not yet published | Separate optional companion; never embedded in R1 |
| R1.0.1 | Ready to publish; not yet published | Corrected current reference; publication contract requires zero Myth payload |
| Generic Myth v0.2.0 (`generic-myth-v0.2.0`) | Published optional companion | Separate, default-off, terminal-only, nonauthorizing; never embedded in R1 |
| R1.0.1 (`r1.0.1-2026-08-17`) | Published corrected current reference | Publication contract requires zero Myth payload |

The exact historical, published, authorized, and frozen identities are in
[`PUBLICATION_MANIFEST.json`](PUBLICATION_MANIFEST.json). A concrete identity
Expand All @@ -59,28 +59,30 @@ deployment.

- **Generic Myth Sidecar v0.2.0** is a generic mnemonic presentation with no
named third-party expressive material. Its frozen exact-hash build has passed
final tests and is authorized for separate publication on GitHub and Hugging
Face; it is not yet represented as published.
final tests and is published separately on GitHub and Hugging Face.
- **Full-Canon Myth Sidecar v0.3.5** is an optional mixed-rights interpretive
companion published separately from R1.

R1.0.1 will contain neither sidecar. The August 14 bytes are preserved rather
R1.0.1 contains neither sidecar. The August 14 bytes are preserved rather
than silently edited; the correction is a separately versioned successor.

## Verify before use

Run the repository evidence verifier in the phase you intend to validate:
Run the repository evidence verifier for the current lifecycle phase:

```bash
python3 -I -S -B tools/verify_repository_evidence.py --phase prepublication
python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication
```

Postpublication mode fails closed until every placeholder is replaced, both
new release assets have anonymous redownload evidence, and the CAPA is closed
with effectiveness evidence:
This validates the published identities, scoped authorities, optional-sidecar
boundaries, and current open CAPA state. Online mode additionally redownloads
the exact GitHub assets and checks live release metadata; it does not create the
missing Hugging Face redownload receipt, establish six-site effectiveness, or
close the CAPA:

```bash
python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication
python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication \
--online --download-dir /tmp/project-shadow-release-assets
```

Exact Windows, macOS, and Linux instructions are in
Expand All @@ -95,6 +97,8 @@ CAPA `PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001` is
Hugging Face redownload identity checks for the corrected artifacts plus live
verification of the six Project Shadow public sites. See the
[`CAPA record`](governance/CAPA_PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001_2026-08-17.json).
Only after those criteria are evidenced may this state become
`CLOSED_EFFECTIVE`.

## Scope boundary

Expand Down
28 changes: 14 additions & 14 deletions RELEASES.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,21 +4,22 @@ Release assets are kept out of Git history and attached to separate GitHub
Releases. Automatically generated source ZIP/TAR archives are repository
snapshots, not Project Shadow release artifacts.

## Current release plan
## Current public releases

Publication phase: **PREPUBLICATION**.
Publication phase: **POSTPUBLICATION**. Effectiveness verification remains
pending.

1. `generic-myth-v0.2.0` — Generic Myth Sidecar v0.2.0, optional public
companion. Its final identity is frozen, its final tests pass, and its exact
hash is authorized for separate GitHub and Hugging Face publication.
hash is published separately on GitHub and Hugging Face.
2. `r1.0.1-2026-08-17` — Project Shadow 1.0.1 R1 reference packaging
correction. Its exact inner is admitted and its deterministic outer build is
frozen and separately exact-hash authorized. It is ready to publish, not yet
published.
frozen, separately exact-hash authorized, and published on GitHub and
Hugging Face.

The Generic sidecar must be published first. R1.0.1 must be published last so
the corrected R1 becomes the latest release. Neither pending release is marked
published in repository evidence before the public asset exists.
The Generic sidecar was published first. R1.0.1 was published last so the
corrected R1 is the latest release. Publication does not by itself verify
anonymous redownload identity or close the packaging-boundary CAPA.

## Existing public releases

Expand All @@ -32,16 +33,15 @@ Historical release notes and governance records remain in place. Nothing in
the 2026-08-17 correction back-writes the August 14 authorization, status,
redownload receipt, tags, or archive.

## Required publication sequence
## Remaining effectiveness sequence

1. Preserve the recorded Generic, inner, and outer exact-hash authorities
without broadening them.
2. Run `tools/verify_repository_evidence.py --phase prepublication`.
3. Publish Generic v0.2.0, then R1.0.1.
4. Anonymously redownload the GitHub and Hugging Face assets and verify exact
2. Run `tools/verify_repository_evidence.py --phase postpublication`.
3. Anonymously redownload the GitHub and Hugging Face assets and verify exact
byte counts and SHA-256 values.
5. Verify all six public sites, add the redownload record, close the CAPA, and
run postpublication mode.
4. Verify all six public sites and add the redownload/effectiveness record.
5. Close the CAPA only if every effectiveness criterion passes.

## Prospective custody procedure

Expand Down
42 changes: 24 additions & 18 deletions docs/VERIFY_RELEASES.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,25 +9,30 @@ extracting an archive.

## Current phase

The repository is in `PREPUBLICATION` for Generic Myth v0.2.0 and R1.0.1.
Their final identities are concrete and frozen. Generic Myth v0.2.0 has scoped
exact-hash publication authorization, and the exact Myth-free R1.0.1 inner is
admitted. The final outer R1.0.1 archive also has its separate exact-hash
publication authorization. The repository is `READY_TO_PUBLISH`, which is
still a prepublication state; it does not assert that the public assets exist.
The repository is in `POSTPUBLICATION` for Generic Myth v0.2.0 and R1.0.1.
Their final identities are concrete, frozen, separately authorized, and
published on GitHub and Hugging Face. The exact Myth-free R1.0.1 inner remains
the scoped admitted packaging identity; its admission does not independently
authorize publication.

Validate the repository state before any upload:
Validate the current published repository state:

```bash
python3 -I -S -B tools/verify_repository_evidence.py --phase prepublication
python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication
```

Postpublication mode must fail until final identities, exact-hash
authorizations, anonymous redownload evidence, and CAPA closure are all
present:
The current postpublication state does not claim effectiveness. Anonymous
GitHub and Hugging Face redownload identity evidence and six-site verification
remain pending, so CAPA `PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001` remains
`IMPLEMENTED_PENDING_EFFECTIVENESS`, not `CLOSED_EFFECTIVE`.

Online mode can redownload and verify the exact GitHub assets and live release
metadata. It does not create the separate Hugging Face redownload evidence or
close the CAPA:

```bash
python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication
python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication \
--online --download-dir /tmp/project-shadow-release-assets
```

## Published and preserved exact identities
Expand All @@ -43,20 +48,21 @@ not the corrected current reference because its nested runtime-family package
included Generic Myth v0.1.1 carrying non-public metadata. Do not edit or
silently replace the historical asset.

## Frozen prepublication identities
## Published corrected identities

| File | Bytes | SHA-256 |
|---|---:|---|
| `Project_Shadow_Generic_Myth_Sidecar_v0.2.0_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip` | 93,676 | `6e7a362d4135f9d626dcfef463bfb1f7166226b3cf8a4c02a953ab39af1538bf` |
| `Project_Shadow_R1.0.1_Runtime_Family_Myth_Decoupled_2026-08-17.zip` | 5,463,189 | `c8c32b12432c954b1a6f852c0c9f81bbbd40167e936be057d4c3de1a0aa3a623` |
| `Project_Shadow_R1.0.1_Public_Reference_2026-08-17.zip` | 5,731,663 | `6f6f1e16d5e9a20e62403f14af7ce8629ce2d702528fb7f80aaf4a14deb7a1d1` |

The Generic identity has scoped GitHub/Hugging Face publication authorization.
The Generic identity is published under scoped GitHub/Hugging Face publication
authorization.
The inner identity has the maintainer's scoped packaging admission, which
explicitly does not authorize publication. The outer identity is recorded only
with a separate exact-hash authorization covering GitHub, Hugging Face, the
verified repository update, and six GPT Site updates. Neither authority permits
production or operational deployment.
explicitly does not authorize publication. The outer identity has a separate
exact-hash authorization covering GitHub, Hugging Face, the verified repository
update, and six GPT Site updates. Neither authority permits production or
operational deployment.

## Windows PowerShell

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@
"expected_asset_path": "releases/generic-myth-v0.2.0/Project_Shadow_Generic_Myth_Sidecar_v0.2.0_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip",
"repository": "ProjectShadow/project-shadow-r1-reference"
},
"state": "READY_TO_PUBLISH"
"state": "PUBLISHED"
},
"authorization_record": "governance/GENERIC_MYTH_v0.2.0_EXACT_HASH_PUBLIC_RELEASE_AUTHORIZATION_2026-08-17.json",
"schema": "project-shadow.generic-myth-public-release-reference.v1",
Expand Down
8 changes: 6 additions & 2 deletions governance/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,8 +51,12 @@ verification, or postpublication attestation.
wording on all six public sites.

Concrete identity fields are not self-authorizing; the separate authority
records supply the scoped decisions. `tools/verify_repository_evidence.py
--phase postpublication` must still reject this ready-but-unpublished state.
records supply the scoped decisions. Generic Myth v0.2.0 and R1.0.1 are now
published on GitHub and Hugging Face, but publication is not CAPA effectiveness
evidence. `tools/verify_repository_evidence.py --phase postpublication`
therefore validates the published identities while preserving
`IMPLEMENTED_PENDING_EFFECTIVENESS` until anonymous redownload and six-site
criteria are evidenced.

The signed admission record did not self-authorize public release. The later
authorization does not modify the signed record or the exact R1 archive; it
Expand Down
8 changes: 4 additions & 4 deletions release-notes/GENERIC_MYTH_SIDECAR_v0.2.0.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
**READY TO PUBLISH · NOT YET PUBLISHED · OPTIONAL · DEFAULT OFF · TERMINAL-ONLY · NONAUTHORIZING**
**PUBLISHED · OPTIONAL · DEFAULT OFF · TERMINAL-ONLY · NONAUTHORIZING**

# Project Shadow Generic Myth Sidecar v0.2.0 — Optional Public Companion

Expand All @@ -10,9 +10,9 @@

**SHA-256:** `6e7a362d4135f9d626dcfef463bfb1f7166226b3cf8a4c02a953ab39af1538bf`

The exact artifact above was built reproducibly, tested, frozen, and authorized
for separate public release on GitHub and Hugging Face. This staged repository
state is not evidence that the public uploads already exist.
The exact artifact above was built reproducibly, tested, frozen, authorized,
and published separately on GitHub and Hugging Face. Publication is not
anonymous redownload identity evidence and does not close the CAPA.

## What it provides

Expand Down
8 changes: 4 additions & 4 deletions release-notes/PROJECT_SHADOW_R1_0_1_2026-08-17.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
**READY TO PUBLISH · NOT YET PUBLISHED · PACKAGING-BOUNDARY CORRECTION · BETA-ACTIVE-TESTING · PRELIVE**
**PUBLISHED · PACKAGING-BOUNDARY CORRECTION · BETA-ACTIVE-TESTING · PRELIVE**

# Project Shadow 1.0.1 — R1 Reference Packaging Correction

Expand All @@ -11,9 +11,9 @@
**SHA-256:** `6f6f1e16d5e9a20e62403f14af7ce8629ce2d702528fb7f80aaf4a14deb7a1d1`

The values above identify the final deterministic outer archive. The maintainer
has separately authorized this exact filename, byte count, SHA-256, and tag for
public release. This staged note does not assert that the public upload already
exists.
separately authorized this exact filename, byte count, SHA-256, and tag, and the
artifact is published on GitHub and Hugging Face. Publication is not anonymous
redownload identity evidence and does not close the CAPA.

## What this corrects

Expand Down
Loading
Loading