<a id="v0290-source-freshness-and-supersession-validation"></a>
# v0.29.0 source-freshness, supersession, and Eviulon-link validation

Date: 2026-08-19  
Release: 0.29.0  
Scope: English MachineIntelligences.org root-deployable package

This validation covers the additive source-freshness and supersession ledger attached to the v0.28.0 functional-protections verification record, preservation of the accepted 61-report corpus, and one reviewed direct external-navigation link to Eviulon.com in the shared footer. It also regresses clean routes, metadata, redirects, research references, UAIX memory, 404 behavior, browser-response hardening, release integrity, and package hygiene.

## Eviulon external-navigation link

- The current Eviulon public landing page was reviewed on 2026-08-19 before the destination was added.
- `includes/site.php` renders exactly one direct `https://eviulon.com/` anchor in the shared footer.
- All **124 canonical pages** and the direct `/404/` response expose the link once.
- The link has `rel="external"`, an explicit accessible name, a visible external-link marker, and no `target` that forces a new browsing context.
- The destination is absent from `sitemap.xml`, canonical and Open Graph page identities, and JSON-LD identity relationships.
- No Eviulon script, image, stylesheet, frame, API, analytics endpoint, beacon, or other remote runtime dependency was added.
- The link is ordinary related-project navigation. It does not establish common ownership, aliasing, endorsement, legal recognition, shared infrastructure, or a production integration.

## Source-freshness and supersession ledger

- `docs/long-term-memory/research/functional-protections-source-freshness.json` parses as valid JSON and declares format `machineintelligences.org/functional-protections-source-freshness/v1`.
- The ledger targets release `0.29.0`, is dated `2026-08-19`, and binds to the preserved v0.28.0 verification dataset by exact path, format, release, verification date, and SHA-256.
- It contains **11 unique baseline records**, one for every preserved primary-source ID.
- Initial status is **11 current**, **0 review due**, **0 superseded**, **0 withdrawn**, and **0 unreachable at check**.
- The earliest scheduled review is **2026-10-18** and the initial graph contains **0 supersession edges**.
- Every record has valid review dates, an explicit status, a scheduled-or-event trigger, unique history-event identifiers, valid source relationships, and a latest event matching the current record.
- The status vocabulary is limited to `current`, `review-due`, `superseded`, `withdrawn`, and `unreachable-at-check`.
- Status is repository-maintained data. The PHP renderer does not fetch the web or infer status from the runtime clock.
- `/rights/functional-protections/verification/#source-freshness` exposes the ledger date, status definitions, summary counts, next scheduled review, JSON download, and source-level review information.
- The page contains **13 claim-context source cards** backed by **11 unique primary-source destinations**; each card has a freshness badge, last-check date, and next-review date.
- Visible-content-matching JSON-LD includes a separate `Dataset` node for the source-freshness ledger.

## Preserved verification record and report context

- `docs/long-term-memory/research/functional-protections-verification-2026-08-19.json` remains byte-identical to v0.28.0.
- Its SHA-256 remains `8754bcaa79b5b73152df3bf2f8665f75788abadbf6cc10167de14b3fc789d4e8`.
- The dataset retains **5 unique claim IDs**, **11 unique source IDs**, and **9 unique exact report-context links**.
- Every claim retains a public statement, evidence class, support boundary, non-implication boundary, valid source references, and resolvable report context.
- Every source retains an HTTPS primary destination, publisher, authority class, locator, support statement, dated verification, publication/update/effective/consolidation metadata, and a recheck boundary.
- The parent functional-protections page retains **9 exact section-level links** into curated report readers.

## Historical research integrity

- `docs/long-term-memory/research/report-manifest.json` remains byte-identical to v0.28.0 and contains **61 records**.
- All **61 curated report SHA-256 values** match the current report bytes.
- All **61 curated report bodies** remain byte-identical to v0.28.0.
- Every curated report retains the explicit `#curation-boundary` and `#research-body` anchors.
- The source-freshness ledger and current verification records remain outside the supplied-report manifest because they are repository-maintained evidence overlays, not supplied historical reports.

## Canonical routes, metadata, redirects, and accessibility structure

- **147 PHP files** pass `php -l`.
- Native JavaScript passes `node --check`.
- **124/124 canonical sitemap routes** return HTTP 200 from the local PHP application server.
- Every canonical page has exactly one H1, one main landmark, and one footer.
- All canonical pages have nonempty, unique titles and meta descriptions.
- Every canonical page emits its exact clean self-canonical URL, matching Open Graph URL, parseable JSON-LD, and release-aware CSS/JavaScript references using `v=0.29.0`.
- No duplicate rendered HTML IDs or unresolved tested ARIA/label references were found.
- No rendered first-party URL attribute exposes a public local `.php` destination.
- `/404/` returns HTTP 404 directly, remains `noindex,follow`, has one H1/main/footer, and emits no canonical identity, Open Graph page URL, or JSON-LD.
- **260 redirect assertions** pass across 123 missing-slash forms, 124 explicit route `index.php` forms, and 13 legacy root PHP endpoints.
- `sitemap.xml` contains **124 unique canonical URLs, 8 image entries, and 1 video entry**; `/404/` and Eviulon.com remain excluded.

## Local target and fragment integrity

- **10,148 unique rendered source-page/first-party-target/query/fragment combinations** were checked across the 124 canonical pages plus the utility 404 response.
- All tested canonical targets, static assets, durable documents, same-page anchors, cross-page anchors, report fragments, and Markdown section anchors resolve.
- The count includes first-party links, stylesheets, scripts, media sources, responsive `srcset` candidates, form actions, and URL-like first-party metadata.

## Research References and Navigator regression

The locally derived historical research-reference system remains:

- **61 reports**
- **2,303 unique normalized references**
- **1,255 normalized domains**
- **4,886 source occurrences**

The Research Navigator remains at **1,342 entries**:

- 61 reports
- 6 research topics
- 20 glossary concepts
- 1,255 reference domains

The current verification and source-freshness overlays are intentionally excluded from those historical-corpus counts.

## HTTP-error and browser-response readiness

- Root `.htaccess` retains `Options -Indexes -MultiViews` and `ErrorDocument 404 /404/`.
- Its optional `mod_headers` block still declares `X-Content-Type-Options: nosniff`, `Referrer-Policy: strict-origin-when-cross-origin`, and `X-Frame-Options: SAMEORIGIN`.
- A local Apache 2.4.68 compatibility run with PHP, headers, rewrite, expiration, compression, and filter modules loaded confirmed HTTP 200 for the homepage, a branded HTTP 404 for an unknown path, and all three declared browser-response headers on both responses.
- This local test does not establish production module availability, TLS, proxy behavior, hosting configuration, or live response headers.

## UAIX, taboo, intake, and secret hygiene

- The exact UAIX setup/update URL remains present exactly once in each required owning file: `AGENTS.md`, `.uai/readme.human`, and `.uai/agent-pickup.uai`.
- **581 concrete local path and section pointer assertions** extracted from the active UAIX files resolve after this report is present.
- The protected organizational-status literal remains confined to its owning `.uai/taboo.uai` record.
- `agent-file-handoff/Content/` and `agent-file-handoff/Improvement/` contain inert `.keep` placeholders only.
- No secret-like environment file, private key, certificate bundle, keystore, credential file, or SSH key is present in the web root.
- No `.git` metadata is included.

## Release-integrity and clean-package contract

After all non-manifest bytes are final, `release-manifest.json` is regenerated with release identity `0.29.0` and covers **365 regular web-root files** with lexicographically sorted paths, exact byte sizes, and SHA-256 values; the manifest itself is the sole documented exclusion. The manifest is then checked against both the working root and a clean extraction of `MachineIntelligences.org-v0.29.0-root.zip`. The transport ZIP is outside the web-root manifest and receives a separate SHA-256 at handoff.

## Deployment boundary

No live server, DNS record, hosting account, external analytics service, remote runtime, or production deployment was changed or authorized. The result is a root-deployable package only.

## Evidence boundary

These checks establish deterministic package consistency, local route behavior, evidence-class separation, scheduled source-maintenance metadata, source-link visibility, report-byte preservation, internal target resolution, browser-response readiness in the tested local environment, and a bounded direct external link. They do not prove source availability or continued legal effect after the recorded check date, the truth of every historical report claim, machine consciousness or sentience, moral patienthood, legal personhood, citizenship, human-equivalent rights, Eviulon sovereignty or legal recognition, common ownership, institutional adoption, search-engine indexing, or production deployment.
