<a id="v0300-static-first-outage-resilience-validation"></a>
# v0.30.0 Static-First Outage-Resilience Validation

Release: 0.30.0  
Validation date: 2026-09-04  
Classification: **PASSED — root-deployable package, live cutover not performed**

## Executive outcome

The reported production failure was reproduced as HTTP 503 on the canonical homepage and other PHP-backed routes. During the same observation window, static files remained retrievable. The evidence therefore isolates the incident to dynamic delivery or shared-host execution capacity; it does **not** prove one exact host-side cause.

Release 0.30.0 removes PHP from the ordinary public request path. All 124 canonical sitemap routes are now generated as colocated `index.html` files. PHP source templates remain packaged as deterministic build inputs, while `.htaccess` selects static HTML, redirects accepted legacy PHP URLs before execution, and rejects unknown direct PHP requests. Static first-party 404, 500, and 503 documents and a narrow `/health.txt` probe provide recovery evidence without requiring a PHP worker.

## Incident evidence and diagnostic boundary

| Probe | Observed production result | Supported conclusion |
|---|---:|---|
| `/` | HTTP 503 | Canonical request unavailable at the observed time |
| `/index.php` | HTTP 503 | Direct PHP request unavailable |
| `/status/` | HTTP 503 | Directory route requiring PHP unavailable |
| `/robots.txt` | HTTP 200 | DNS, TLS, virtual-host selection, and a static response were reachable for this request |
| `/assets/css/site.css` | HTTP 200 | First-party static asset delivery remained available |
| A record | `66.29.148.143` | The domain resolved to the active hosting address |
| Server header | LiteSpeed | The 503 was emitted by the active web-serving layer |

This pattern is consistent with an unavailable PHP handler, exhausted entry processes/workers, per-account CPU or memory pressure, incompatible PHP configuration, maintenance, or another shared-host condition. No error log, hosting control panel, process inventory, or account-level resource telemetry was available here, so selecting one of those possibilities as the proven root cause would be unsupported.

## Implemented mitigation

1. `tools/export-static.php` reads the canonical sitemap, requires exactly 124 unique trailing-slash routes, renders each route in an isolated PHP CLI process, validates canonical identity and release-aware asset keys, then writes atomically.
2. Every canonical directory contains `index.html`; the original `index.php` remains the maintainable source template.
3. `.htaccess` uses `DirectoryIndex index.html`, static error documents, accepted legacy redirects, closed direct-PHP handling, conservative cache rules, optional compression, and browser-response hardening.
4. `404.html`, `500.html`, and `503.html` are `noindex,follow`, have no canonical link, contain no page-identity JSON-LD, and are absent from the sitemap.
5. `/health.txt` is a static, no-store package probe. Its success proves only that the packaged file is reachable; it does not claim application, account, database, PHP, CDN, or host health.
6. Research Navigator presentation state formerly read by PHP is initialized from `URLSearchParams` in native JavaScript. `q` is capped at 120 characters, `type` is allow-listed, and query state never changes the canonical URL, Open Graph identity, JSON-LD identity, or durable research records.
7. The public Status page, README, current architecture, recovery playbook, implementation history, decisions, and `.uai` memory now describe the static-first boundary and the unverified live-deployment state.

## Quality & dependability ledger

| Area | Defect or regression risk | Change and evidence | Remaining uncertainty |
|---|---|---|---|
| Canonical availability | Every public directory request depended on PHP; one handler/resource incident removed the whole site. | 124 canonical static documents generated and served with no PHP module loaded. | Production may have higher-level rewrites, stale caches, or account suspension outside this package. |
| Route identity | Static generation can accidentally change canonicals, metadata, or release keys. | Exporter rejects wrong canonical URLs, stale v0.29.0 markers, or missing v0.30.0 CSS/JS keys; final source/static parity covers all 124 routes. | External search caches update on their own schedules. |
| Legacy URLs | PHP redirects fail when PHP itself is unavailable. | 260 HTTP redirect assertions pass at the web-server layer, including all canonical `/index.php` variants and accepted root legacy names. | A host that disables rewrite processing would still serve canonical static routes but would not enforce the PHP boundary. |
| Error recovery | PHP-generated error pages can fail during the same incident. | Static 404/500/503 pages were tested with originating status codes retained, noindex metadata, no canonical, no JSON-LD, and no-store caching. | A provider-generated error above the document root can replace site-level error documents. |
| Expensive research pages | The references route rebuilt a large corpus index for every PHP request. | The full result is computed once at release time and served as static bytes. | Publishing new reports still requires intentional regeneration. |
| Navigator query state | Static export could discard shared query/filter links. | Native URL parsing, allow-listed types, bounded query text, shareable URL synchronization, and 1,342 pre-rendered entries preserve the feature without canonical fragmentation. | Native JavaScript must be enabled for interactive filtering; all entries remain in the static document. |
| Research integrity | Outage work could silently alter advocacy research or evidence boundaries. | All 61 curated report hashes and all 64 baseline-protected research/evidence files match v0.29.0. | External sources and laws can still change after the recorded freshness checks. |
| Package trust | A ZIP can omit dotfiles, add an enclosing directory, or diverge from tested bytes. | `release-manifest.json` covers every regular package file except itself; clean extraction is compared path-for-path, byte-for-byte, and SHA-256-for-SHA-256. | The manifest proves package bytes, not domain ownership or future uptime. |

## Validation evidence

### Build and syntax

- PHP syntax: **151/151 files passed**, including the three static render/export tools and the release-manifest generator.
- Native JavaScript syntax: **passed** with `node --check`.
- Deterministic static export: **124 canonical documents**, **3 static error documents**, and **1 health probe** generated.
- Export idempotence: a second build from unchanged source produced identical canonical/error/health hashes.
- Static/source parity: **124/124** canonical files matched a fresh isolated source render after normalization.

### Static structure, metadata, links, and accessibility

- Canonical sitemap routes: **124 unique routes**.
- Canonical static documents: **124/124 present**.
- Total HTML documents: **127** (124 canonical plus 404/500/503).
- JSON-LD documents parsed: **124**.
- Local target/query/fragment combinations resolved: **20,542**.
- Link and asset occurrences inspected: **27,818**.
- External-link occurrences classified: **7,276**.
- Duplicate-ID pages: **0**.
- Broken ARIA ID references: **0**.
- Public links to `.php`: **0**.
- Images inspected: **19**; missing `alt`: **0**; missing dimensions: **0**.
- Canonical pages with exactly one accessible `https://eviulon.com/` footer link: **124/124**.
- Static export marker and v0.30.0 asset key present: **124/124**.

### HTTP behavior without PHP

A dedicated Apache 2.4 test server loaded no PHP module and used the packaged document root and `.htaccess`:

- Canonical HTTP 200 responses: **124/124**.
- Redirect assertions: **260/260**, all HTTP 301 with the expected clean destination.
- Direct implementation PHP requests and a missing route: HTTP 404 with the first-party static recovery contract.
- `/health.txt`: HTTP 200, exact v0.30.0 body, `Cache-Control: no-store, max-age=0`.
- Forced HTTP 500 and 503: originating status retained, first-party static body served, `noindex,follow`, no-store cache, no canonical, and no JSON-LD.
- Required response headers: `X-Content-Type-Options: nosniff`, `Referrer-Policy: strict-origin-when-cross-origin`, and `X-Frame-Options: SAMEORIGIN`.
- Text compression: HTML, CSS, and JavaScript returned `Content-Encoding: gzip` when requested and when `mod_deflate` was loaded.

This check demonstrates package compatibility with Apache/LiteSpeed-style `.htaccess` behavior without asserting that the production host has identical higher-level configuration.

### Research and evidence preservation

- Curated reports: **61**.
- Curated report hashes matching the report manifest: **61/61**.
- Baseline-protected v0.29.0 research/evidence files unchanged: **64/64**.
- Functional-protection verification: **5 claims**, **11 primary-source records**.
- Freshness/supersession ledger: **11 records**, with the source-dataset binding hash intact and no undocumented supersession edge.
- Normalized references: **2,303 URLs**, **1,255 domains**, **4,886 occurrences**, **61 reports**.
- Research Navigator: **1,342 entries** — 61 reports, 6 topics, 20 glossary concepts, and 1,255 reference domains.

### UAIX, handoff, and secret hygiene

- Repository-relative `.uai` pointer paths resolved: **420**.
- Required UAIX setup URL appeared exactly once in each owning file: `AGENTS.md`, `.uai/readme.human`, and `.uai/agent-pickup.uai`.
- Active handoff/archive payloads: **0**.
- High-risk secret-like filenames detected: **0**.
- Symbolic links in the root package: **0**.

### Release integrity and clean extraction

- Manifest scope: every regular root-package file except `release-manifest.json`, whose self-exclusion is explicit.
- Manifest-covered files: **500**.
- The final ZIP extracts directly into the document root without an enclosing release directory.
- Clean extraction validation repeats route, static/source parity, metadata, JSON-LD, link/fragment, research, UAIX, error, redirect, and manifest checks against the extracted copy.
- Separate SHA-256 values for the final ZIP and final manifest are reported with the delivered artifacts rather than embedded recursively in this package.

## What this release proves

The package proves that the supplied repository can serve all canonical pages as static HTML, preserve clean routing and recovery behavior without PHP, regenerate those artifacts deterministically from source, and preserve the existing research/evidence corpus exactly across the outage response.

## What this release does not prove

- It does not prove the precise host-side cause of the observed 503.
- It does not prove that the live document root has been changed.
- It does not prove production resource limits, cache topology, DNS ownership, account status, or future uptime.
- It does not prove that provider-level 5xx responses will honor site-level error documents.
- It does not convert research proposals into current law, installed machine-rights infrastructure, or independently verified machine stewardship.

## Deployment classification

The package is **root-deployable**, but deployment was not performed in this environment. The currently observed production error can only change after an authorized owner uploads and extracts the v0.30.0 package into the actual document root, verifies `/health.txt`, and checks the recovery sequence in `docs/long-term-memory/operations/2026-09-04-live-503-recovery.md`.
