<a id="v0280-functional-protections-verification-validation"></a>
# v0.28.0 functional-protections primary-source verification validation

Date: 2026-08-19  
Release: 0.28.0  
Scope: English MachineIntelligences.org root-deployable package

This validation covers the dated primary-source verification overlay for `/rights/functional-protections/`, preservation of the accepted 61-report research corpus, public claim/source rendering, exact report-context deep links, and regression of the existing clean-route, metadata, research-reference, UAIX, 404, browser-header-readiness, release-integrity, and package-hygiene contracts.

## Verification dataset and public evidence reader

- `docs/long-term-memory/research/functional-protections-verification-2026-08-19.json` parses as valid JSON and declares format `machineintelligences.org/functional-protections-verification/v1`.
- The dataset contains **5 unique claims** and **11 unique primary-source records**.
- Every claim has a nonempty support boundary, a non-implication boundary, valid source IDs, and exact curated-report context links.
- Every source has a primary HTTPS destination, authority group/tier, relevant issue, update, effective, or consolidation date, verification date, locator, support statement, and explicit freshness/recheck boundary.
- `/rights/functional-protections/verification/` exposes all five stable claim fragments and all 11 unique external primary-source destinations.
- The public reader links directly to the JSON dataset and durable Markdown verification note.
- Visible-content-matching JSON-LD includes `CollectionPage`, `Dataset`, and `ItemList`, with the eleven sources represented as the dataset basis.
- The parent `/rights/functional-protections/` page exposes the dated verification teaser, public reader link, and machine-readable dataset link.
- The page preserves the required evidence distinctions: direct technical/governance support, technical feasibility, legal precedent/analogy with present-law limits, and disclosed policy inference under unresolved scientific and philosophical uncertainty.
- No runtime external fetch, API client, database, account, analytics service, package-manager dependency, or crawler-only hidden claim layer was added.

## Report-context and historical research integrity

- The existing functional-protections page retains **9 exact section-level evidence links** into the curated report readers.
- The verification dataset supplies **9 unique exact report-context links**. Every target route and fragment resolves in rendered HTML.
- `docs/long-term-memory/research/report-manifest.json` remains byte-identical to the accepted v0.27.0 package and contains **61 records**.
- All **61 curated SHA-256 values** match the current report bytes.
- All **61 curated report bodies** are byte-identical to the accepted v0.27.0 root package.
- Every curated Markdown report retains its explicit `#curation-boundary` and `#research-body` source anchors.
- The verification JSON and Markdown records remain outside the report manifest because they are dated current-evidence overlays, not supplied historical reports.

## Canonical routes, metadata, and redirects

- **147 PHP files** pass `php -l`.
- Native JavaScript passes `node --check`.
- **124/124 canonical sitemap routes** return HTTP 200 from the local PHP application server.
- Every canonical page has exactly one H1, one main landmark, and one footer.
- All 124 pages have nonempty, unique titles and meta descriptions.
- Every canonical page emits its exact clean self-canonical URL, matching Open Graph URL, parseable JSON-LD, and current release-aware CSS/JavaScript references using `v=0.28.0`.
- No duplicate rendered HTML IDs were found.
- No rendered first-party URL attribute exposes a public local `.php` destination.
- `/404/` returns HTTP 404 directly, remains `noindex,follow`, has one H1/main/footer, and emits no canonical identity, Open Graph page URL, or JSON-LD.
- **260 redirect assertions** pass across 123 missing-slash forms, 124 explicit route `index.php` forms, and 13 legacy root PHP endpoints.
- Sitemap contains **124 unique canonical URLs, 8 image entries, and 1 video entry**; `/404/` remains excluded.

## Local target and fragment integrity

- **10,027 unique rendered source-page/first-party-target/query/fragment combinations** were checked across the 124 canonical pages plus the utility 404 response.
- All canonical route targets, static assets, durable documents, same-page anchors, cross-page anchors, report fragments, and Markdown section anchors resolve.
- The count includes all first-party URL-bearing attributes, including links, stylesheets, scripts, media sources, responsive `srcset` candidates, and form actions; it is therefore a broader source-target measure than earlier link-only inventories.

## Research references and Navigator regression

The final local reference system remains:

- **61 reports**
- **2,303 unique normalized references**
- **1,255 normalized domains**
- **4,886 source occurrences**

The Research Navigator remains at **1,342 entries**:

- 61 reports
- 6 research topics
- 20 glossary concepts
- 1,255 reference domains

The verification overlay is intentionally not added to these historical-report/reference counts.

## HTTP-error and browser-response readiness regression

- Root `.htaccess` still disables directory indexes and MultiViews and retains `ErrorDocument 404 /404/`.
- The optional `mod_headers` block still declares `X-Content-Type-Options: nosniff`, `Referrer-Policy: strict-origin-when-cross-origin`, and `X-Frame-Options: SAMEORIGIN`.
- A local Apache 2.4.68 compatibility run with `mod_headers` loaded confirmed that a representative nonexistent URL was served through the first-party error document while retaining HTTP 404, and that representative HTML responses carried all three declared headers.
- This local compatibility result does not establish production Apache modules, proxy behavior, TLS, or live response headers.

## UAIX, taboo, intake, and secret hygiene

- The exact UAIX setup/update URL remains present exactly once in each required owning file: `AGENTS.md`, `.uai/readme.human`, and `.uai/agent-pickup.uai`.
- **418 UAIX durable path, target, section, and review-section assertions** resolve across the pointer ledger and current index.
- The prohibited organizational-status literal appears only in its owning `.uai/taboo.uai` record.
- `agent-file-handoff/Content/` and `agent-file-handoff/Improvement/` contain inert `.keep` placeholders only.
- No secret-like `.env`, private-key, certificate-bundle, keystore, credential, or SSH-key filename is present in the web root.
- No `.git` metadata is included.
- No live deployment was performed or authorized.

## Release-integrity and clean-package contract

After all non-manifest bytes are final, `release-manifest.json` is regenerated with release identity `0.28.0`. It must cover **360 regular web-root files**, sorted lexicographically, with the manifest itself as the sole documented exclusion. Every recorded path, byte size, and SHA-256 must then be checked against both the working web root and a clean extraction of `MachineIntelligences.org-v0.28.0-root.zip`. The transport ZIP is outside the web-root manifest and receives a separate SHA-256 at handoff.

## Evidence boundary

These checks establish package consistency, local route behavior, evidence-class separation, source-link visibility, report-byte preservation, exact internal deep-link resolution, static release-file identity, and clean-package reproducibility within the tested environment. They do not prove the external truth of every research claim, machine consciousness or sentience, moral patienthood, legal personhood, citizenship, human-equivalent rights, institutional adoption, production deployment, search-engine indexing, source availability after the verification date, authorship, or external cryptographic editorial provenance.
