Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
15 commits
Select commit Hold shift + click to select a range
4247bdd
Close R1.0.1 effectiveness record: PUBLICATION_MANIFEST.json
PauseBeforeHarmProtocol Aug 18, 2026
5f2ebd0
Close R1.0.1 effectiveness record: PUBLIC_RELEASE_STATUS_2026-08-17.json
PauseBeforeHarmProtocol Aug 18, 2026
b81af81
Close R1.0.1 effectiveness record: README.md
PauseBeforeHarmProtocol Aug 18, 2026
4a0a7b5
Close R1.0.1 effectiveness record: RELEASES.md
PauseBeforeHarmProtocol Aug 18, 2026
7e8daab
Close R1.0.1 effectiveness record: docs/VERIFY_RELEASES.md
PauseBeforeHarmProtocol Aug 18, 2026
32358e7
Close R1.0.1 effectiveness record: governance/CAPA_PS-R1-PRIVATE-MYTH…
PauseBeforeHarmProtocol Aug 18, 2026
dab9d74
Close R1.0.1 effectiveness record: governance/README.md
PauseBeforeHarmProtocol Aug 18, 2026
23fe294
Close R1.0.1 effectiveness record: release-notes/GENERIC_MYTH_SIDECAR…
PauseBeforeHarmProtocol Aug 18, 2026
7f203bc
Close R1.0.1 effectiveness record: release-notes/PROJECT_SHADOW_R1_0_…
PauseBeforeHarmProtocol Aug 18, 2026
b28f68a
Close R1.0.1 effectiveness record: tests/test_verify_repository_evide…
PauseBeforeHarmProtocol Aug 18, 2026
f1e51c7
Harden R1.0.1 effectiveness verification: tools/verify_repository_evi…
PauseBeforeHarmProtocol Aug 18, 2026
2ee4205
Add R1.0.1 effectiveness evidence: governance/R1_0_1_PUBLIC_REDOWNLOA…
PauseBeforeHarmProtocol Aug 18, 2026
d6cbc9e
Add R1.0.1 effectiveness evidence: governance/R1_0_1_SIX_PUBLIC_SITES…
PauseBeforeHarmProtocol Aug 18, 2026
855f50f
Add R1.0.1 effectiveness evidence: tools/verify_generic_myth_v0_2_0.py
PauseBeforeHarmProtocol Aug 18, 2026
b8ba2ba
Add R1.0.1 effectiveness evidence: tools/verify_outer_release.py
PauseBeforeHarmProtocol Aug 18, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions PUBLICATION_MANIFEST.json
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@
"production_authorized": false,
"safety_claimed": false
},
"postpublication_state": "PUBLISHED_PENDING_EFFECTIVENESS",
"postpublication_state": "PUBLISHED_EFFECTIVENESS_VERIFIED",
"publication_phase": "POSTPUBLICATION",
"release_identity": "PROJECT SHADOW 1.0.1 / R1 REFERENCE / BETA-ACTIVE-TESTING / PRELIVE",
"releases": [
Expand All @@ -33,7 +33,7 @@
"publication_state": "PUBLISHED_HISTORICAL",
"role": "OPTIONAL_EXTERNAL_RESEARCH_SIDECAR",
"tag": "myth-v0.3.4",
"title": "Project Shadow Myth Sidecar v0.3.4 — Optional External Research"
"title": "Project Shadow Myth Sidecar v0.3.4 — Public Release · Optional Companion"
},
{
"asset": {
Expand Down Expand Up @@ -64,7 +64,7 @@
"publication_state": "PUBLISHED",
"role": "OPTIONAL_FULL_CANON_COMPANION",
"tag": "myth-v0.3.5",
"title": "Project Shadow Full-Canon Myth Sidecar v0.3.5 — Optional Public Companion"
"title": "Project Shadow Myth Sidecar v0.3.5 — Public Release · Optional Companion"
},
{
"asset": {
Expand Down
14 changes: 10 additions & 4 deletions PUBLIC_RELEASE_STATUS_2026-08-17.json
Original file line number Diff line number Diff line change
@@ -1,8 +1,12 @@
{
"capa": {
"effectiveness_verified": false,
"effectiveness_verified": true,
"id": "PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001",
"status": "IMPLEMENTED_PENDING_EFFECTIVENESS"
"status": "CLOSED_EFFECTIVE",
"verification_records": [
"governance/R1_0_1_PUBLIC_REDOWNLOAD_VERIFICATION_2026-08-17.json",
"governance/R1_0_1_SIX_PUBLIC_SITES_EFFECTIVENESS_VERIFICATION_2026-08-17.json"
]
},
"current_reference": {
"active_descendant_count": 27,
Expand Down Expand Up @@ -53,7 +57,9 @@
"governance/GENERIC_MYTH_v0.2.0_EXACT_HASH_PUBLIC_RELEASE_AUTHORIZATION_2026-08-17.json",
"governance/R1_0_1_INNER_EXACT_HASH_ADMISSION_2026-08-17.json",
"governance/R1_0_1_OUTER_RELEASE_AUTHORIZATION_2026-08-17.json",
"governance/CAPA_PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001_2026-08-17.json"
"governance/CAPA_PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001_2026-08-17.json",
"governance/R1_0_1_PUBLIC_REDOWNLOAD_VERIFICATION_2026-08-17.json",
"governance/R1_0_1_SIX_PUBLIC_SITES_EFFECTIVENESS_VERIFICATION_2026-08-17.json"
],
"warning": "Generic Myth v0.2.0 and R1.0.1 are published on GitHub and Hugging Face. Anonymous GitHub and Hugging Face redownload identity verification and six-site effectiveness checks remain pending; CAPA remains IMPLEMENTED_PENDING_EFFECTIVENESS and is not closed."
"warning": "Generic Myth v0.2.0 and R1.0.1 are published on GitHub and Hugging Face. Anonymous exact-identity redownloads from both hosts, bounded package verification, recursive zero-Myth verification, and corrected-boundary checks across all six public sites passed. CAPA is CLOSED_EFFECTIVE for this packaging correction only; no production, deployment, efficacy, safety, certification, or legal-compliance claim is made."
}
33 changes: 21 additions & 12 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,10 +16,12 @@ optional companion, the exact Myth-free inner family is admitted, and the final
R1.0.1 outer identity has its own exact-hash publication authorization.

Generic Myth v0.2.0 and R1.0.1 now exist as public GitHub and Hugging Face
releases. Anonymous redownload identity verification and six-site effectiveness
checks remain pending. The machine-readable phase is
releases. Anonymous exact-identity redownloads from both hosts, bounded package
verification, recursive zero-Myth verification, and corrected-boundary checks
across all six public sites passed. The machine-readable phase is
[`POSTPUBLICATION`](PUBLIC_RELEASE_STATUS_2026-08-17.json), and CAPA
`PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001` remains open.
`PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001` is `CLOSED_EFFECTIVE` for this
packaging correction.

## Current contact

Expand Down Expand Up @@ -75,10 +77,10 @@ python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication
```

This validates the published identities, scoped authorities, optional-sidecar
boundaries, and current open CAPA state. Online mode additionally redownloads
the exact GitHub assets and checks live release metadata; it does not create the
missing Hugging Face redownload receipt, establish six-site effectiveness, or
close the CAPA:
boundaries, retained redownload and six-site receipts, and closed CAPA state.
Online mode additionally redownloads the exact GitHub and Hugging Face assets,
runs the historical and current bounded package verifiers, checks live release
metadata, and rechecks the six-site boundary semantics:

```bash
python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication \
Expand All @@ -89,16 +91,23 @@ Exact Windows, macOS, and Linux instructions are in
[`docs/VERIFY_RELEASES.md`](docs/VERIFY_RELEASES.md). The historical
[`tools/verify_public_release.py`](tools/verify_public_release.py) remains
pinned to the August 14 artifact; it is not silently retargeted to R1.0.1.
The corrected archive is checked separately by
[`tools/verify_outer_release.py`](tools/verify_outer_release.py), and Generic
v0.2.0 by
[`tools/verify_generic_myth_v0_2_0.py`](tools/verify_generic_myth_v0_2_0.py).

## CAPA state

CAPA `PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001` is
**IMPLEMENTED_PENDING_EFFECTIVENESS**. Closure requires exact public GitHub and
Hugging Face redownload identity checks for the corrected artifacts plus live
verification of the six Project Shadow public sites. See the
**CLOSED_EFFECTIVE** for the 2026-08-17 packaging-boundary correction. Exact
public GitHub and Hugging Face redownload identity checks, bounded Generic and
recursive R1.0.1 verification, and live checks across all six Project Shadow
public sites passed. See the
[`CAPA record`](governance/CAPA_PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001_2026-08-17.json).
Only after those criteria are evidenced may this state become
`CLOSED_EFFECTIVE`.
The retained evidence is the
[`redownload receipt`](governance/R1_0_1_PUBLIC_REDOWNLOAD_VERIFICATION_2026-08-17.json)
and
[`six-site receipt`](governance/R1_0_1_SIX_PUBLIC_SITES_EFFECTIVENESS_VERIFICATION_2026-08-17.json).

## Scope boundary

Expand Down
36 changes: 24 additions & 12 deletions RELEASES.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,8 @@ snapshots, not Project Shadow release artifacts.

## Current public releases

Publication phase: **POSTPUBLICATION**. Effectiveness verification remains
pending.
Publication phase: **POSTPUBLICATION**. Packaging-correction effectiveness is
verified.

1. `generic-myth-v0.2.0` — Generic Myth Sidecar v0.2.0, optional public
companion. Its final identity is frozen, its final tests pass, and its exact
Expand All @@ -18,8 +18,9 @@ pending.
Hugging Face.

The Generic sidecar was published first. R1.0.1 was published last so the
corrected R1 is the latest release. Publication does not by itself verify
anonymous redownload identity or close the packaging-boundary CAPA.
corrected R1 is the latest release. Subsequent anonymous GitHub and Hugging
Face redownloads, bounded package verification, and all six public-site checks
passed; the packaging-boundary CAPA is `CLOSED_EFFECTIVE`.

## Existing public releases

Expand All @@ -33,15 +34,26 @@ Historical release notes and governance records remain in place. Nothing in
the 2026-08-17 correction back-writes the August 14 authorization, status,
redownload receipt, tags, or archive.

## Remaining effectiveness sequence
Files under `release-notes/` are content-aligned publication-time snapshots of
the live GitHub release bodies (line endings and trailing Markdown spaces are
normalized). Any open/pending CAPA wording retained there records the
then-current release-time state; current lifecycle status is defined only by
`PUBLIC_RELEASE_STATUS_2026-08-17.json`, `PUBLICATION_MANIFEST.json`, and the
two retained effectiveness receipts.

1. Preserve the recorded Generic, inner, and outer exact-hash authorities
without broadening them.
2. Run `tools/verify_repository_evidence.py --phase postpublication`.
3. Anonymously redownload the GitHub and Hugging Face assets and verify exact
byte counts and SHA-256 values.
4. Verify all six public sites and add the redownload/effectiveness record.
5. Close the CAPA only if every effectiveness criterion passes.
## Completed effectiveness sequence

1. The recorded Generic, inner, and outer exact-hash authorities were
preserved without broadening them.
2. GitHub and Hugging Face copies of Generic v0.2.0 and R1.0.1 were anonymously
redownloaded and matched their exact byte counts and SHA-256 values.
3. Both downloaded Generic archives passed the bounded 23-path verifier, and
R1.0.1 passed recursive zero-Myth verification.
4. All six public sites passed the corrected-boundary semantic checks,
including the current Project Shadow status surface and the National Trump
Record route.
5. CAPA `PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001` was closed effective on the
retained redownload and six-site receipts.

## Prospective custody procedure

Expand Down
20 changes: 12 additions & 8 deletions docs/VERIFY_RELEASES.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,14 +21,18 @@ Validate the current published repository state:
python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication
```

The current postpublication state does not claim effectiveness. Anonymous
GitHub and Hugging Face redownload identity evidence and six-site verification
remain pending, so CAPA `PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001` remains
`IMPLEMENTED_PENDING_EFFECTIVENESS`, not `CLOSED_EFFECTIVE`.

Online mode can redownload and verify the exact GitHub assets and live release
metadata. It does not create the separate Hugging Face redownload evidence or
close the CAPA:
The current postpublication state records packaging-correction effectiveness.
Anonymous GitHub and Hugging Face redownloads matched the exact current
identities; both downloaded Generic packages passed the bounded 23-path
verifier; R1.0.1 passed recursive zero-Myth verification; and all six public
sites passed the corrected-boundary checks. CAPA
`PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001` is `CLOSED_EFFECTIVE` for that bounded
correction.

Online mode redownloads and verifies the exact GitHub and Hugging Face assets,
runs the historical and current package verifiers, checks live release
metadata, and rechecks the six-site semantic boundary. It validates retained
evidence but does not rewrite receipts or publish anything:

```bash
python3 -I -S -B tools/verify_repository_evidence.py --phase postpublication \
Expand Down
Original file line number Diff line number Diff line change
@@ -1,9 +1,13 @@
{
"capa_id": "PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001",
"closure": {
"closed_at": null,
"effectiveness_verified": false,
"verification_record": null
"closed_at": "2026-08-18T10:39:24Z",
"effectiveness_verified": true,
"verification_record": "governance/R1_0_1_PUBLIC_REDOWNLOAD_VERIFICATION_2026-08-17.json",
"verification_records": [
"governance/R1_0_1_PUBLIC_REDOWNLOAD_VERIFICATION_2026-08-17.json",
"governance/R1_0_1_SIX_PUBLIC_SITES_EFFECTIVENESS_VERIFICATION_2026-08-17.json"
]
},
"corrective_action": {
"affected_august_14_release_mutated": false,
Expand Down Expand Up @@ -36,5 +40,5 @@
},
"opened_on": "2026-08-17",
"schema": "project-shadow.capa.v1",
"status": "IMPLEMENTED_PENDING_EFFECTIVENESS"
"status": "CLOSED_EFFECTIVE"
}
117 changes: 117 additions & 0 deletions governance/R1_0_1_PUBLIC_REDOWNLOAD_VERIFICATION_2026-08-17.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,117 @@
{
"schema": "project-shadow.r1.0.1-public-redownload-verification.v1",
"status": "VERIFIED",
"recorded_at": "2026-08-18T10:33:45Z",
"anonymous_download": true,
"method": {
"anonymous_https": true,
"exact_byte_count_and_sha256": true,
"http_status_required": 200
},
"observations": [
{
"role": "OPTIONAL_GENERIC_COMPANION",
"host": "GITHUB",
"filename": "Project_Shadow_Generic_Myth_Sidecar_v0.2.0_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip",
"download_url": "https://github.com/PauseBeforeHarmProtocol/Project-Shadow/releases/download/generic-myth-v0.2.0/Project_Shadow_Generic_Myth_Sidecar_v0.2.0_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip",
"final_host": "release-assets.githubusercontent.com",
"http_status": 200,
"bytes_expected": 93676,
"bytes_observed": 93676,
"sha256_expected": "6e7a362d4135f9d626dcfef463bfb1f7166226b3cf8a4c02a953ab39af1538bf",
"sha256_observed": "6e7a362d4135f9d626dcfef463bfb1f7166226b3cf8a4c02a953ab39af1538bf",
"identity_verified": true
},
{
"role": "OPTIONAL_GENERIC_COMPANION",
"host": "HUGGING_FACE",
"filename": "Project_Shadow_Generic_Myth_Sidecar_v0.2.0_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip",
"download_url": "https://huggingface.co/spaces/ProjectShadow/project-shadow-r1-reference/resolve/main/releases/generic-myth-v0.2.0/Project_Shadow_Generic_Myth_Sidecar_v0.2.0_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip",
"final_host": "us.aws.cdn.hf.co",
"http_status": 200,
"bytes_expected": 93676,
"bytes_observed": 93676,
"sha256_expected": "6e7a362d4135f9d626dcfef463bfb1f7166226b3cf8a4c02a953ab39af1538bf",
"sha256_observed": "6e7a362d4135f9d626dcfef463bfb1f7166226b3cf8a4c02a953ab39af1538bf",
"identity_verified": true
},
{
"role": "R1_REFERENCE_CORRECTED",
"host": "GITHUB",
"filename": "Project_Shadow_R1.0.1_Public_Reference_2026-08-17.zip",
"download_url": "https://github.com/PauseBeforeHarmProtocol/Project-Shadow/releases/download/r1.0.1-2026-08-17/Project_Shadow_R1.0.1_Public_Reference_2026-08-17.zip",
"final_host": "release-assets.githubusercontent.com",
"http_status": 200,
"bytes_expected": 5731663,
"bytes_observed": 5731663,
"sha256_expected": "6f6f1e16d5e9a20e62403f14af7ce8629ce2d702528fb7f80aaf4a14deb7a1d1",
"sha256_observed": "6f6f1e16d5e9a20e62403f14af7ce8629ce2d702528fb7f80aaf4a14deb7a1d1",
"identity_verified": true
},
{
"role": "R1_REFERENCE_CORRECTED",
"host": "HUGGING_FACE",
"filename": "Project_Shadow_R1.0.1_Public_Reference_2026-08-17.zip",
"download_url": "https://huggingface.co/spaces/ProjectShadow/project-shadow-r1-reference/resolve/main/releases/r1.0.1-2026-08-17/Project_Shadow_R1.0.1_Public_Reference_2026-08-17.zip",
"final_host": "us.aws.cdn.hf.co",
"http_status": 200,
"bytes_expected": 5731663,
"bytes_observed": 5731663,
"sha256_expected": "6f6f1e16d5e9a20e62403f14af7ce8629ce2d702528fb7f80aaf4a14deb7a1d1",
"sha256_observed": "6f6f1e16d5e9a20e62403f14af7ce8629ce2d702528fb7f80aaf4a14deb7a1d1",
"identity_verified": true
}
],
"generic_v0_2_0_bounded_verification": {
"tool": "tools/verify_generic_myth_v0_2_0.py",
"tool_sha256": "0d84c8f90da35a16abbd410744ebd7df6f06a836e0c0b830b5213fb598087e9b",
"target": {
"filename": "Project_Shadow_Generic_Myth_Sidecar_v0.2.0_OPTIONAL_PUBLIC_COMPANION_2026-08-17.zip",
"bytes": 93676,
"sha256": "6e7a362d4135f9d626dcfef463bfb1f7166226b3cf8a4c02a953ab39af1538bf"
},
"inventory_path_count": 23,
"bounded_archive_verifier": true,
"old_predecessor_embedded": false,
"observations": [
{
"host": "GITHUB",
"status": "PASS"
},
{
"host": "HUGGING_FACE",
"status": "PASS"
}
]
},
"r1_0_1_recursive_verification": {
"tool": "tools/verify_outer_release.py",
"tool_sha256": "721c384b245ca654c087d184bbfe5725d85d41536250140467d7cd913e6a1ccb",
"target": {
"filename": "Project_Shadow_R1.0.1_Public_Reference_2026-08-17.zip",
"bytes": 5731663,
"sha256": "6f6f1e16d5e9a20e62403f14af7ce8629ce2d702528fb7f80aaf4a14deb7a1d1"
},
"status": "PASS",
"recursive_forbidden_payload_scan": true,
"zero_embedded_myth_payload": true,
"observations": [
{
"host": "GITHUB",
"status": "PASS"
},
{
"host": "HUGGING_FACE",
"status": "PASS"
}
]
},
"nonclaims": {
"operational_deployment_authorized": false,
"production_authorized": false,
"efficacy_claimed": false,
"safety_claimed": false,
"certification_claimed": false,
"legal_compliance_claimed": false
}
}
Loading
Loading