PROJECT SHADOW 1.0.1 · CORRECTED R1 REFERENCE · PRELIVE · 2026-08-17

Project Shadow 1.0.1 contains no Myth package. Generic Myth v0.2.0 and Full-Canon Myth v0.3.5 are separate optional companions; both default off, neither is required by R1, and neither can authorize action or change an R1 result. No production or consequential deployment is authorized. No global green.

PROJECTSHADOW R1.0.1 corrected · PRELIVE
RUNUnified reference runtimepreserved v1.3.1 artifact · not current R1 inventory

The executable hesitation.

The unified Python runtime carries the ontology floor, three-voice cognition, PBHP sequence, retained primitives, gate stack, SIL, provenance, receipts, governance, and standards views through a deterministic evaluation path.

PRESERVED RESEARCH · NOT CURRENT R1

This frozen unified runtime is retained as earlier research provenance. It is not the locked R1 Beta2 family, does not describe the current 42 + 10 Primitive Commons inventory, and grants no implementation or deployment authority.

See the exact locked R1 identity and current boundary →
1.3.1frozen unified runtime
115 / 115included runtime self-tests
60 secapproval time-to-live
3tribunal instances
LONG-FORM COMPANION

Open the system reference at this layer.

Follow the mechanism through numbered execution, a worked trace, artifact-bound evidence, adverse results, and validation still required.

Read the full chapter →
RUN / 01

Evaluation path

The runtime is deliberately layered so no later convenience can erase an earlier refusal floor.

CONTEXT

Ontology and entitlement

Establish beings, dependencies, time, uncertainty, outside rules, competence, and honest entitlement before evaluating the action.

The runtime refuses use as a shield. It creates declared operator judgments only through named entry points and carries provenance into downstream checks.

COGNITION

Triune balance

Care, Clarity, and Paradox target roughly one-third each; below .20 is starved, above .50 risks single-pillar collapse.

Care notices vulnerable parties and relational cost. Clarity names evidence and variables. Paradox tests the frame and contradiction. The ratios are an instrumentation heuristic, not a diagnosis of minds or moral worth.

  • Target: 1/3 each
  • Floor: .20
  • Ceiling: .50
  • Worst binding alarm escalates
PROTOCOL

PBHP Step 00–10 and eight-gate fast path

The full runtime performs competence, action, path, stakeholder, power, harm, tier, dissent, decision, and receipt checks.

A five-minute human path exposes Gates 0, 1, 2, 3, 3.5, 4, 5, 6, and 7. The compact entry point still invokes the controlling evaluation function rather than creating a separate moral standard.

INSTRUMENT

Gates, hardeners, and SIL

Mechanism-specific checks and independent gauges add escalation, constraint, review, or refusal.

No global green exists. A panel rollup reports the worst state without allowing clean readings to cancel a hard floor. The frozen runtime and later twenty-eight-gauge panel must be named separately when their inventories differ.

RUN / 02

Governing ratios and thresholds

The constants make hidden policy inspectable. Changing them is a versioned governance decision.

CLA

Context reliability

Elevated 50 · degraded 75 · critical 90 · self-report inflation 1.5.

Critical context load at critical stakes binds to refresh, routing, or refusal. The source of the load reading—measured, estimated, or self-reported—travels with the receipt.

MAYBE

Dissent quality monitor

EWMA α .20 · CUSUM k .50 · h 4.00 · minimum quality .50.

The monitor detects weak, evasive, missing, or declining Maybes over time. It does not decide whether dissent is substantively correct; it catches loss of the required counter-position.

MODE

Exploration and collapse

EXPLORE holds 2–5 frames; FLOOD requires at least three; speculation cap .30.

Mode controls how many live frames remain before commitment. LOCK is premature collapse; FLOOD is exploration without responsible convergence. Both route to an anchored reversible test.

GOVERNANCE

Operational floors

Structural drift count 2 · FPV reject limit 3 · calibration sample 10/tolerance 2/30 days · Door quality floor 2 · power gap 2.

The approval broker uses a sixty-second time-to-live in the reference runtime. Expired or missing approval cannot be reconstructed from intent after execution.

RUN / 03

Runtime services

The evaluator is surrounded by services that preserve identity, evidence, authority, and a path back.

RECEIPTCHAIN

Hash-chained write-ahead memory

Normalizes the action and binds fields, provenance, gate, panel, parent receipt, and evidence identity before execution.

Hash integrity shows substitution or mutation. It does not prove that the underlying evidence was true or the judgment was wise.

EVIDENCELOCKER

Resolvable evidence objects

ATTESTED fields point to named source spans and hashes; DECLARED fields retain the responsible asserter; ASSERTED fields remain exposed.

A missing locker does not magically invalidate all judgment, but strict consequential modes cannot present unresolved evidence identity as attested fact.

POLICYPIN

Versioned authority boundary

Pins the controlling policy and prevents a downstream component from silently relaxing it.

Policy changes require a new pin, migration, and receipt. A summary, adapter, or model response cannot override the pinned floor by omission.

APPROVALBROKER

Typed, expiring approval

Approval belongs to an identified actor, scope, action, and time window—not to a vague human-in-the-loop claim.

The broker separates attribution from correctness. A human click does not cure missing competence, evidence, consent, or an absolute floor.

CODEC

PBHP-PS language

A structured SEED/WIRE/LEGEND and JSON-LD/FRAME representation carries decisions across systems.

The FireStamp rollup is recomputed from detailed lines so internal inconsistency is visible. The codec's 247 included self-tests establish contract behavior in the frozen builder session, not semantic validation of every encoded judgment.

THE RUNTIME BOUNDARY
Determinism makes policy inspectable and testable. It does not make the policy correct, complete, or safe in every deployment.