PROJECT SHADOW 1.0.1 · CORRECTED R1 REFERENCE · PRELIVE · 2026-08-17

Project Shadow 1.0.1 contains no Myth package. Generic Myth v0.2.0 and Full-Canon Myth v0.3.5 are separate optional companions; both default off, neither is required by R1, and neither can authorize action or change an R1 result. No production or consequential deployment is authorized. No global green.

PROJECTSHADOW R1.0.1 corrected · PRELIVE
RELR1.0.1 corrected public reference · August 17, 2026published · PRELIVE · active testing

The exact artifacts are public. The claim boundary remains.

This is the authoritative download and verification page for the Myth-free R1.0.1 reference and two separate optional Myth companions. Publication permits public inspection; it does not authorize production or consequential deployment.

R1.0.1 / CURRENT CORRECTED REFERENCE

Project Shadow 1.0.1 — R1 Reference

PUBLISHED · PRELIVE

The exact authorized Myth-free R1.0.1 reference container. Public inspection and reproduction are authorized; production or operational deployment is not.

5,731,663 bytes

SHA-256: 6f6f1e16d5e9a20e62403f14af7ce8629ce2d702528fb7f80aaf4a14deb7a1d1
MYTH / OPTIONAL PUBLIC COMPANION

Generic Myth Sidecar v0.2.0

PUBLISHED · SEPARATE SIDECAR

A separately versioned, default-off, terminal-only optional companion. It is not required by R1, cannot alter a gate or result, and cannot authorize an act.

93,676 bytes

SHA-256: 6e7a362d4135f9d626dcfef463bfb1f7166226b3cf8a4c02a953ab39af1538bf
MYTH / OPTIONAL MIXED-RIGHTS COMPANION

Full-Canon Myth Sidecar v0.3.5

PUBLISHED · SEPARATE SIDECAR

A separately versioned, default-off, mixed-rights optional companion. It is not required by R1, cannot alter a gate or result, and cannot authorize an act.

1,428,812 bytes

SHA-256: 2b55867fe7c502a0defd8d6f2e9b53fbd1caaf1b0f225a438bd45b04a3e7bae2
R1.0.1 RELEASE RECEIPT

Exact authorization and effectiveness evidence recorded.

The exact human authorizations are recorded. The admitted Myth-free inner family is 5,463,189 bytes with SHA-256 c8c32b12432c954b1a6f852c0c9f81bbbd40167e936be057d4c3de1a0aa3a623. Two deterministic outer builds were byte-identical, full and cold verification passed, and 14 of 14 adversarial mutants were rejected. The correction removes embedded Myth while preserving all 27 active descendant bytes. Anonymous GitHub and Hugging Face exact redownloads, both public checksum files, and all six live-site boundary checks passed. CAPA PS-R1-PRIVATE-MYTH-PUBLIC-BOUNDARY-001 is CLOSED_EFFECTIVE. These controls establish bounded custody and packaging-correction effectiveness—not efficacy, safety, certification, legal compliance, independent validation, or operational readiness.

PRESERVED PREDECESSOR · SUPERSEDED FOR PACKAGING-BOUNDARY CORRECTION

Project Shadow 1.0 — August 14 R1

7,679,812 bytes

SHA-256: 2f8fe1530b6a83294d15011df95853aaecf08fa4dba756f0c2e91dd089e1b1ec

Preserved unchanged as historical evidence. Its historical authorization and verification do not authenticate R1.0.1.

Open preserved release →
PRESERVED PREDECESSOR · SUPERSEDED FOR PACKAGING-BOUNDARY CORRECTION

Full-Canon Myth v0.3.4

1,418,194 bytes

SHA-256: 3c8c8c0d3d9582c76b685c1b685260cc8179478ab310037c858b46257aa314c7

Preserved unchanged as historical evidence. Its historical authorization and verification do not authenticate R1.0.1.

Open preserved release →
PRESERVED AUGUST 14 PREDECESSOR VERIFICATION

Historical Sigstore evidence is scoped to the predecessor.

The two levels below authenticate the preserved August 14 admission evidence—not R1.0.1. R1.0.1 has its own exact admission, authorization, deterministic-build, recursive, and adversarial receipts.

LEVEL 1 / OFFLINE

Offline receipt-bound verification

This historical mode verifies the exact predecessor admission record, Sigstore bundle, and independent receipt; confirms that the bundle targets the expected digest and contains Rekor and RFC 3161 evidence; and confirms the receipt records successful checks. It does not execute Cosign and does not authenticate R1.0.1.

python3 -I -S -B tools/verify_public_release.py .
LEVEL 2 / FRESH

Fresh Sigstore/Cosign verification

Level 2 repeats Level 1 and freshly executes cosign verify-blob against the preserved predecessor evidence with the preserved bundle, signed timestamp, exact certificate identity, exact OIDC issuer, and an independently obtained trusted root. It does not authenticate R1.0.1.

Cosign
v3.1.3 · Linux/amd64
Cosign SHA-256
4629c757b7618056f8ddd7e2625ae9fdd94c0372a65049520bc7d9df9efc7f71
TrustedRoot SHA-256
6494e21ea73fa7ee769f85f57d5a3e6a08725eae1e38c755fc3517c9e6bc0b66
Certificate identity
pausebeforeharmprotocol_PBHP@protonmail.com
OIDC issuer
https://github.com/login/oauth
COPYABLE RAW COSIGN COMMAND
cosign verify-blob \
  --bundle governance/PROJECT_SHADOW_FABLE7_SCOPED_MAINTAINER_ADMISSION_RECORD_2026-08-12.json.sigstore.json \
  --trusted-root /absolute/path/to/trusted-root.json \
  --use-signed-timestamps \
  --certificate-identity 'pausebeforeharmprotocol_PBHP@protonmail.com' \
  --certificate-oidc-issuer 'https://github.com/login/oauth' \
  governance/PROJECT_SHADOW_FABLE7_SCOPED_MAINTAINER_ADMISSION_RECORD_2026-08-12.json

The trusted-root JSON is an independent input, not part of the signed bundle. The raw command does not itself check the Cosign binary or trusted-root hashes; use the repository verifier for those pin checks. The preserved pin is for Linux/amd64. Native macOS and Windows verification requires its own independently verified binary pin and receipt; Windows users can reproduce this exact path through WSL on amd64.

GLOBAL REKOR ENTRYIndex 2465982078UUID 108e9186e8c5677a5ce4e9ea6d6aaf7b7a6aabe12b6a3f0d9202da3ede22684c3c90780f2f313a79

The bundle also carries a separately labeled shard-local inclusion-proof index: 2344077816. It is not the global public lookup index.

01 / USE

Start with the pause

Pause Before Harm is the understandable action protocol. It is in active testing with Project Shadow; it is not certified by it.

Open PBHP →
02 / ADOPT

Take one bounded piece

Primitive Commons beta.5 contains 42 primitives and 10 compositions. Mythology is optional and never required for operational adoption.

Inspect the modular path →
03 / REVIEW

Challenge the evidence

Inspect exact identities, audit disposition, preserved adverse results, known limitations, and the gates that remain open.

Open the evidence boundary →
THE EXACT PROCEDURE

A correction was not a shortcut around release control.

The exact admission, authorization, publication, anonymous redownload, and six-site effectiveness steps are recorded. CAPA closure remains bounded to this packaging correction.

  1. 01DONE

    Preserve the predecessor

    The August 14 release remains immutable historical evidence; no byte was rewritten or silently replaced.

  2. 02DONE

    Admit the Myth-free inner family

    The exact 5,463,189-byte inner is admitted for R1.0.1 packaging; its 27 active descendants are byte-identical to August 14.

  3. 03DONE

    Authorize exact public artifacts

    The maintainer authorized Generic Myth v0.2.0 and the exact R1.0.1 outer by filename, byte length, SHA-256, target, and boundary.

  4. 04DONE

    Publish exact ZIPs and checksums

    Generic Myth v0.2.0 was published separately and the corrected R1.0.1 reference remains PRELIVE/nonauthorizing within its stated scope.

  5. 05DONE

    Verify effectiveness

    Anonymous GitHub and Hugging Face exact redownloads and all six live-site checks matched the authorized identities and corrected boundary. CAPA closure verifies this packaging correction only.

Publication authority came from exact human records, not from a candidate gate or model output. Inspect the R1.0.1 outer authorization → Inspect the Generic Myth authorization → Inspect the CAPA → Inspect the current release status record →

CURRENT BOUNDARY

Public does not mean proven.

The public surface was reviewed August 17. Evidence cutoffs remain item-specific, including earlier dates where stated. Next review: September 16. Treat as stale after October 16 unless a newer receipt appears.

What this page does not authorize

  • Production or operational deployment.
  • Safety, efficacy, or harm-prevention claims.
  • Certification or legal-compliance claims.
  • Fresh independent validation claims.
  • Fusing either optional Myth sidecar into R1.0.1 or feeding it back into an R1 gate or result.
  • Any claim that a signature or public checksum proves readiness.

Named, affected, correcting, or raising a rights concern? projectshadowqa@protonmail.com. This channel has no response-time SLA.

SEPARATELY PUBLISHED OPTIONAL COMPANIONS

Myth is outside the R1.0.1 package and authority path.

Generic Myth v0.2.0 · 93,676 bytes · 6e7a362d4135f9d626dcfef463bfb1f7166226b3cf8a4c02a953ab39af1538bf

Full-Canon Myth v0.3.5 · 1,428,812 bytes · 2b55867fe7c502a0defd8d6f2e9b53fbd1caaf1b0f225a438bd45b04a3e7bae2

Both companions are separate, optional, default-off, standalone, nonauthorizing, and not required by R1. Neither can supply evidence, alter a gate or result, or feed authority back into R1. Full-Canon remains mixed-rights; optionality does not erase that rights boundary.

Open Generic Myth v0.2.0 →Open Full-Canon Myth v0.3.5 →Open the Hugging Face mirror →Open the National Trump Record →Read the CAPA →
THE ECOSYSTEM

Six sites. Separate jobs. One correction loop.

The Record remembers → Civic QA inspects → PBHP pauses → ARM repairs → Project Shadow instruments and tests → The Record preserves the receipt. ALMSIVI preserves optional origin and interpretation outside the operational loop.

INSTRUMENT + TEST

Project Shadow

The locked reference architecture, exact status, research record, and release governance.

OPEN →
PAUSE

Pause Before Harm

The understandable before-action protocol: name the act, find who pays first, preserve a Door, and leave a receipt.

OPEN →
INSPECT

Civic QA

Public inspection against visible standards, evidence, findings, and non-averagable stop rules.

OPEN →
REPAIR

American Repair Manual

Civic corrective and preventive action with an owner, verification plan, and effectiveness check.

OPEN →
REMEMBER

The Record

Sourced memory, currentness, consequences, challenges, corrections, National, and IN-6.

OPEN →
ORIGIN + INTERPRET

ALMSIVI

Optional origin, philosophy, mythology, failure map, and provenance outside the authorization loop.

OPEN →
THE RELEASE RULE
Sign the record. Authorize the exact bytes. Verify the public copy. Keep every boundary attached.