Skip to content

WAVE 0 EVIDENCE RECEIPT

ContextControl.ai — bluefly.io

Receipt Type: Wave 0 — Evidence Collection Governing Standards: - Engineering-Standard/standards/drupal/07-CONTRIB-FIRST.md (BluTown-Docs) — Architectural principles, allowed primitives, forbidden implementations - Engineering-Standard/standards/drupal/12-DRUPAL-APPLICATION-GOVERNANCE.md (BluTown-Docs) — Delta Principle, Single Authority, Governance Lifecycle, Citizenship Criteria - Engineering-Standard/standards/drupal/11-DRUPAL-BUILD-CONTRACT.md (BluTown-Docs) — Build-time validation, module classifier, CI enforcement

Wave: 0 — Evidence Collection only. Per 12 §2 Wave 0: read-only inventory. No architectural replacements. No candidate owner assignments. Opinions are forbidden at this wave. Status: FROZEN — evidence only. All EVID items are observed facts. Date collected: 2026-07-01 Collected by: Agent — read-only filesystem inspection + git tracking verification + composer.json analysis + config/sync analysis.


SECTION 1 — ROOT FOLDER INVENTORY

Evidence collected per 12 §2 Wave 1 Artifact Taxonomy.

1.1 Standard Drupal Composer Project Artifacts

Artifact Class Git Tracked Observation
web/ SOURCE ✅ Drupal docroot
vendor/ GENERATED Gitignored Composer-managed
config/sync/ CONFIG ✅ 1,847+ config files observed
composer.json SOURCE ✅ 148 required packages
composer.lock GENERATED ✅ ~1MB
patches/ BUILD ✅ 6 patch files — see §4
recipes/ INSTALL ✅ Mixed contrib + custom — see §6
private/ RUNTIME ✅ (empty) Drupal private files dir
.ddev/ BUILD ✅ DDEV config, 30+ compose files
.gitlab-ci.yml BUILD ✅ CI pipeline config
Dockerfile BUILD ✅ OCI image build
lefthook.yml BUILD ✅ Git hooks
external/ BUILD ✅ Symlink → cloned-for-today/_DRUPAL

1.2 Non-Standard Artifacts — Classified

EVID Artifact Class Git Tracked Observation
EVID-001 app/ RUNTIME ✅ Next.js application: TSX pages, API routes (/api/activity, /api/webhooks, /api/tools), TypeScript stores. Contains full npm project with @bluefly/* dependencies.
EVID-002 lib/ RUNTIME ✅ TypeScript stores: activity-store.ts, webhook-store.ts, memory-store.ts, auth.ts. Part of EVID-001.
EVID-003 node_modules/ GENERATED Gitignored npm dependencies for EVID-001.
EVID-004 package.json BUILD ✅ Next.js + Radix UI + @bluefly/* npm packages. Script names include bluefly:validate, bluefly:workspace-status.
EVID-005 package-lock.json GENERATED ✅ 430KB npm lockfile.
EVID-006 agentblu-tools-mcp.mjs RUNTIME ✅ MCP stdio server. Comment: "Deploy to Oracle at /home/node/.openclaw/". Key: not a Drupal artifact; stated deployment target is Oracle/OpenClaw.
EVID-007 memory/ RUNTIME ✅ AI agent dream/memory logs. Contains dreaming/deep/, dreaming/rem/, dreaming/light/ JSONL + Markdown files dating 2026-05-22 through 2026-06-02.
EVID-008 _dev_scripts/ RECOVERY ✅ 11 PHP scripts tracked in git. See §2 for full inventory.
EVID-009 web/fix_versions.php RECOVERY ✅ PHP script in web docroot. Manipulates canvas_page entity storage directly. Publicly accessible via HTTP.
EVID-010 Plans/ DOCS ✅ 12 markdown planning files: REBUILD-MASTER.md, REDESIGN-ARCHITECTURE.md, SDC_COMPONENTS_MANIFEST.md, etc.
EVID-011 debug_altcha.html GENERATED ✅ 173KB debug HTML artifact.
EVID-012 debug_forms.html GENERATED ✅ 183KB debug HTML artifact.
EVID-013 debug_login.html GENERATED ✅ 15KB debug HTML artifact.
EVID-014 auth.json RUNTIME ✅ Content: {}. Empty Composer auth file tracked in source control.
EVID-015 openapi.yaml GENERATED ✅ 96KB OpenAPI specification at repo root. Authorship method (hand-written vs. generated) not determined at Wave 0.
EVID-016 data/ — ✅ Contains only .gitkeep. No other files observed.
EVID-017 deployment/ UNKNOWN ✅ Contains only index.html. Purpose not determined. Protected Until Ownership Proven.
EVID-018 api-reference/ DOCS Unknown Contains only introduction.mdx. Mintlify stub.
EVID-019 mint.json BUILD Unknown Mintlify documentation configuration.
EVID-020 screenshots/ DOCS ✅ Contains home-mock.png. Design mockup.
EVID-021 ai.json UNKNOWN ✅ 20KB file at repo root. Content not fully parsed. Owner and class not determined. Protected Until Ownership Proven.
EVID-022 docs/ DOCS Unknown Contains 4 files: bluefly-design-system-review.html, consolidation_playbook.md, consolidation_receipt.md, drupal-2026-catalog.html.
EVID-023 public/ UNKNOWN Unknown Contents not observed. Protected Until Ownership Proven.
EVID-024 tests/ BUILD Unknown Contains e2e/ and support/ — Playwright tests.
EVID-025 introduction.mdx DOCS Unknown Mintlify page stub at repo root.

SECTION 2 — CAPABILITY INVENTORY

Per 12 §2 Wave 0: capability inventory only. No owner assignments at this wave.

2.1 Capabilities Observed in _dev_scripts/ (EVID-008)

Script Observed Capability
create_missing_components.php Creates Canvas components programmatically
create_pages.php Creates Canvas pages
create_remaining_pages.php Creates additional Canvas pages
diagnose_components.php Inspects Canvas component state
diagnose_partner.php Inspects partner content
fix_all_versions.php Corrects component version field values
fix_versions_sql.php Corrects version field values via SQL
strip_unsupported_inputs.php Removes unsupported field values from content
update_component_config.php Updates Canvas component configuration
update_hero_component.php Updates hero SDC component configuration
update_link_components.php Updates link component configuration

2.2 Capabilities Observed in app/ (EVID-001)

Route / File Observed Capability
app/api/activity/route.ts Activity event ingestion API
app/api/activity/stream/route.ts Activity event streaming (SSE)
app/api/tools/route.ts Tool listing API
app/api/tools/activity/route.ts Activity tool API
app/api/tools/gitlab/route.ts GitLab tool API
app/api/tools/memory/route.ts Memory tool API
app/api/webhooks/route.ts Inbound webhook receiver
app/api/webhooks/gitlab/route.ts GitLab webhook receiver
app/api/webhooks/stats/route.ts Webhook statistics API
app/activity/page.tsx Activity dashboard page
app/activity-stream.tsx Activity stream React component

2.3 Contrib Modules Installed for Equivalent Capabilities (observed in composer.json)

Capability Installed Contrib Module Enabled (core.extension.yml)
Webhook processing drupal/webhooks ✅ webhooks
Tool plugins drupal/tool ✅ tool, tool_ai_connector
MCP tools drupal/mcp_tools ✅ mcp_tools, mcp_tools_remote
Admin dashboard drupal/dashboard ✅ dashboard
AI provider abstraction drupal/ai ✅ ai
AI agents drupal/ai_agents ✅ ai_agents
Workflow automation drupal/eca ✅ eca

SECTION 3 — CONTRIB OWNERSHIP FINDINGS

Per 11 §Build Contract 1 — Contrib Audit patterns. Per 07 §Forbidden Implementations.

3.1 web/libraries/ — Manual Installation Observed

4 libraries installed manually (not via Composer). No composer.json path-repo or asset-packagist reference found for any.

Library Installed Contrib Module Module Enabled
friendly-challenge drupal/friendlycaptcha ✅
klaro drupal/klaro ✅
rtseo.js drupal/yoast_seo ✅ yoast_seo
vanilla-icon-picker Not determined Unknown

Observation: Three of four libraries have a corresponding installed contrib module. Whether those modules manage their library assets or require the manual installation is not determined at Wave 0.

3.2 web/libraries/studio-ui/ — Empty Directory

An empty studio-ui directory exists in web/libraries/. No files observed. Purpose not determined.

3.3 openapi.yaml (EVID-015)

drupal/openapi and drupal/openapi_jsonapi are both installed and enabled (openapi, openapi_jsonapi in core.extension.yml). A 96KB openapi.yaml exists at repo root. Relationship between the installed modules and this file not determined at Wave 0.


SECTION 4 — PATCH LEDGER

Per 07 §Contrib-First and the principle that patches against Drupal contrib must have an upstream issue on drupal.org.

Applied Patches (in composer.json)

PATCH-01: patches/drupal-tfa-reset-pass-login-signature-drupal11.patch

Field Observation
Target drupal/tfa ^1.0
Applied Yes — composer.json
What it changes Adds Request $request parameter to TfaUserControllerDeprecated::resetPassLogin()
Drupal.org issue Confirmed active — "Drupal 11 resetPassLogin signature compatibility" in TFA issue queue
Issue URL in composer key No — missing

PATCH-02: patches/media_library-base-field-id-fix.patch

Field Observation
Target drupal/core — media_library submodule
Applied Yes — composer.json
What it changes Guards MediaLibraryWidget against calling id() on BaseFieldDefinition
Drupal.org issue Confirmed — issue #3563487: "Media library widget cannot be used with base fields"
Issue URL in composer key No — missing

Patches On Disk But NOT Applied in composer.json

PATCH-03: patches/api_normalization-eca-action-type-mismatch.patch

Field Observation
Target drupal/api_normalization
Applied No
What it changes Renames service class references: ApiNormalizationService → NormalizationService; ApiNormalizerService → NormalizationService (3 files)
Drupal.org issue None — api_normalization is a Bluefly private module, not on drupal.org
Governance note A service class rename applied to a private module via Composer patch is not an upstream patch. 12 §0.1 requires ownership to rest with the module source. Wave 1.5 must determine owner.

PATCH-04: patches/api_normalization-eca-subscriber-container-init.patch

Field Observation
Target drupal/api_normalization
Applied No
What it changes Replaces conditional ECA module-exists check in EcaAgentEventSubscriber::getSubscribedEvents() with return []
Drupal.org issue None
Governance note Same as PATCH-03 — private module, no upstream path.

PATCH-05: patches/api_normalization-missing-services.patch

Field Observation
Target drupal/api_normalization
Applied No
What it changes Adds a new PHP class (CircuitBreakerService) to the module. Patch comment states: "This class was missing from api_normalization 1.0.0-alpha4."
Drupal.org issue None
Governance note This patch adds a new class to a module via diff. This is the observed fact. Wave 1.5 must determine where CircuitBreakerService ownership belongs per 07's Architectural Taxonomy.

PATCH-06: patches/drupal-tool-legacy-typed-data-normalizer-return-type.patch

Field Observation
Target drupal/tool 1.0.x-dev
Applied No
What it changes Narrows return types on LegacyTypedDataNormalizer, ContextDefinitionNormalizer, MapDefinitionNormalizer to : array to resolve PHP 8.4 LSP violations
Drupal.org issue Not verified. Requires search at drupal.org/project/tool/issues.
Governance note Target is contrib on drupal.org. If an upstream issue exists, this is a candidate for Type A (upstream patch). If fixed in a newer release, version constraint update supersedes the patch. Not determinable at Wave 0.

Patch Ledger Summary

Patch Applied Drupal.org Issue Confirmed Observation
drupal-tfa-reset-pass-login-signature-drupal11.patch ✅ ✅ Active Missing issue URL in composer key
media_library-base-field-id-fix.patch ✅ ✅ #3563487 Missing issue URL in composer key
api_normalization-eca-action-type-mismatch.patch ❌ ❌ Private module Not applied; Wave 1.5 required
api_normalization-eca-subscriber-container-init.patch ❌ ❌ Private module Not applied; Wave 1.5 required
api_normalization-missing-services.patch ❌ ❌ Private module Not applied; adds new class; Wave 1.5 required
drupal-tool-legacy-typed-data-normalizer-return-type.patch ❌ ⚠️ Not verified Not applied; drupal.org issue search required

SECTION 5 — SDC / THEME FINDINGS

5.1 Theme Structure

Theme Location Base Theme Observation
agentic_canvas web/themes/custom/agentic_canvas/ false Engine theme. name: 'LLM Platform Manager' in .info.yml. Also exists as empty directory in web/themes/contrib/agentic_canvas/.
bluefly_theme web/themes/custom/bluefly_theme/ agentic_canvas Marketing sub-theme. name: Bluefly Theme.

Observation: agentic_canvas appears in both custom/ and contrib/. The contrib/ copy is empty. The custom/ copy is the active installation. Both .gitignore and Composer path repos reference external/_DRUPAL/THEMES/agentic_canvas_theme. Relationship between these three locations not fully determined at Wave 0.

5.2 SDC Component Duplication

bluefly_theme/components/ contains 46 SDC components. 22 exist in two versions simultaneously:

Bare Name Prefixed Name
accordion bluefly-accordion
agent-card bluefly-agent-card
agent-service-grid bluefly-agent-service-grid
arch-diagram bluefly-arch-diagram
card bluefly-card
case-study-card bluefly-case-study-card
certification-badge bluefly-certification-badge
comparison-table bluefly-comparison-table
cta-cluster bluefly-cta-cluster
evidence-panel bluefly-evidence-panel
feature-grid bluefly-feature-grid
flow-drop-embed bluefly-flow-drop-embed
hero bluefly-hero
logo-strip bluefly-logo-strip
profile-card bluefly-profile-card
resource-card bluefly-resource-card
section bluefly-section
service-card bluefly-service-card
sod-table bluefly-sod-table
stats-block bluefly-stats-block
timeline bluefly-timeline
trust-tier-badge bluefly-trust-tier-badge

Unique to bare (no prefixed version): partner-card, tab-group Unique to prefixed (no bare version): none beyond the 22 pairs.

Observation: Both versions exist simultaneously. Which Canvas page configs reference which version is not determined at Wave 0. This requires a grep -r "bluefly_theme:" config/sync/ audit before any Wave 3 action.


SECTION 6 — RECIPE AND CONFIGURATION FINDINGS

6.1 Config/Sync Scale

Config Type Count
canvas.component.* 166
field.field.* 426
field.storage.* 257
views.view.* 42
block.block.* 69
eca.eca.* 13
node.type.* 33
image.style.* 65
core.entity_view_display.* 102
taxonomy.vocabulary.* 17

6.2 Recipe Integrity Findings

Recipe Location Observation
recipe_ai_marketplace __DRUPAL/Recipes/recipe_ai_marketplace/ Contains both recipe.yml AND module code: agent_marketplace.info.yml, agent_marketplace.routing.yml, agent_marketplace.services.yml, src/. Whether this is intentional packaging is not determined at Wave 0. Protected Until Ownership Proven.
recipe_secure_drupal __DRUPAL/Recipes/recipe_secure_drupal/ Contains both recipe.yml AND module code: secure_drupal.module, secure_drupal.services.yml, src/, templates/. Also contains test_field_api.php and validate_implementation.php at recipe root. Protected Until Ownership Proven.
recipe_agent_platform __DRUPAL/Recipes/recipe_agent_platform/ Contains recipe.yml, config/, content/ (YAML content files), assets/, scripts/, Playwright tests.
drupal_cms_starter recipes/drupal_cms_starter/ Contrib recipe — recipe.yml + content/ YAML files + screenshot.webp.
easy_email_* recipes/easy_email_*/ 4 contrib recipes — standard recipe shape.
Path Resolves To
external/_DRUPAL cloned-for-today/_DRUPAL (symlink)
cloned-for-today/_DRUPAL/PRIVATE <workspace>/PROJECTS/__DRUPAL/Module
cloned-for-today/_DRUPAL/CUSTOM-CONTRIB <workspace>/PROJECTS/__DRUPAL/Module
cloned-for-today/_DRUPAL/RECIPES <workspace>/PROJECTS/__DRUPAL/Recipes
cloned-for-today/_DRUPAL/THEMES <workspace>/PROJECTS/__DRUPAL/Themes

Observation: PRIVATE and CUSTOM-CONTRIB both resolve to the same filesystem path (__DRUPAL/Module). The namespace distinction exists in the Composer path-repo declarations but not on disk. Whether this is intentional is not determined at Wave 0.

6.4 __DRUPAL/Module Contents — 52 Modules Observed

_quarantine/  agent_bootstrap_authority  agent_registry_consumer
agentdash_platform  agentic_canvas_blocks  ai_agents_agui
ai_agents_blu_ops  ai_agents_claude  ai_agents_client
ai_agents_communication  ai_agents_crewai  ai_agents_cursor
ai_agents_dashboard  ai_agents_huggingface  ai_agents_kagent
ai_agents_marketplace  ai_agents_ossa  ai_agents_tunnel
ai_provider_apple  ai_provider_langchain  ai_provider_routing_eca
alternative_services  api_normalization  apidog_integration
apidog_integration_v1  blockchain_manager  blu-fleet
cedar_policy  charts_ai_analytics  code_executor
contractplane_client  copaw_bridge  dita_ccms
dragonfly_client  drupal_audit  drupal_patch_framework
duadp  duadp_client  external_migration
kb_cache  layout_system_converter  mcp_gateway
openclaw  playbook_engine  recipe_onboarding
skills_browser  source_connect  source_connector
source_connector_compliance  source_connector_mcp

Observation: _quarantine/ exists. Contents include a full Drupal web installation (demo_agent_marketplace_misplaced_site/web/...). Purpose not determined. Protected Until Ownership Proven.


SECTION 7 — IN-REPO CUSTOM MODULES (web/modules/custom/)

Per 11 §Build Contract 3 — Module Classifier. Classification at Wave 0 is observation only.

Module In Repo or Symlink Observation
mcp_registry In-repo (not symlink) Has own AGENTS.md, CLAUDE.md, CODEOWNERS, openapi.yaml, mkdocs.yml, scripts/, tools/. Complex.
blu_fleet In-repo Has composer.json, drush.services.yml, modules/ sub-directory.
ai_agents_marketplace In-repo Has drupal.org submission documents (CHANGES_FOR_DRUPAL_ORG.md, DRUPAL_ORG_SUBMISSION.md). Also exists in __DRUPAL/Module. Duplicate locations observed.
cedar_policy In-repo Has composer.json, CSS, JS.
recipe_onboarding Symlink → __DRUPAL/Module
drupal_patch_framework Symlink → __DRUPAL/Module
source_connector Symlink → __DRUPAL/Module Involved in drush status failure (previous session context: LegacyServiceInstantiator missing parameter source_connector_mcp.client)
dita_ccms Symlink → __DRUPAL/Module
alternative_services Symlink → __DRUPAL/Module
skills_browser Symlink → __DRUPAL/Module

Observation: .gitignore declares /web/modules/custom/ as gitignored. All content in this directory is managed by Composer path repos. The in-repo modules (mcp_registry, blu_fleet, ai_agents_marketplace, cedar_policy) are not directly in git — they are symlinked or installed by Composer from external/_DRUPAL/.


SECTION 8 — DELTA CLASSIFICATIONS

Per 12 §0.1 (Delta Principle): classifications at Wave 0 are evidence-based only. Final delta decisions belong to Wave 2.

EVID Artifact Observed Parallel Capability in Contrib Classification Candidate
EVID-001 app/api/webhooks/ drupal/webhooks installed and enabled Candidate: no delta
EVID-001 app/api/tools/ drupal/tool + drupal/mcp_tools installed and enabled Candidate: no delta
EVID-001 app/api/activity/ drupal/dashboard installed and enabled; Views available Candidate: no delta
EVID-009 web/fix_versions.php drush/drush DrushCommand plugin type available Candidate: no delta
EVID-008 _dev_scripts/*.php Drupal Migrate API + Drush available Candidate: no delta
EVID-015 openapi.yaml (root) drupal/openapi + drupal/openapi_jsonapi installed Authorship method not determined; candidate if hand-maintained

Note: These are candidates only. Per 12 §2 Wave 1.5, owner assignments remain UNDECIDED until Wave 2.


SECTION 9 — PROTECTED UNTIL OWNERSHIP PROVEN

Per 12 §0.3 (Capability Ownership Principle): no artifact is retired until the six-step sequence is complete.

EVID Artifact Reason
EVID-021 ai.json (root, 20KB) Owner not determined. Class not determined.
EVID-017 deployment/ Single index.html. Purpose not determined.
EVID-023 public/ Contents not observed.
— __DRUPAL/Module/_quarantine/ Full Drupal site embedded. Origin and purpose not determined.
— config/sync/canvas.component.* (166) Active site structure. Canvas reference audit not complete.
— config/sync/field.* (683) Live content fields. Content audit not complete.
— bluefly_theme/components/ bare-name SDC Canvas reference audit (grep -r "bluefly_theme:" config/sync/) not complete.
— mcp_registry module Active MCP dependency. Client dependency graph not mapped.
— source_connector module Active; involved in known drush status error. Root cause not resolved.
— alternative_services module Service container dependency. Container health not verified.
— All 13 ECA models Automation running. Trigger/action inventory not complete.
— recipe_ai_marketplace Module code inside recipe. Intentional vs. accidental not determined.
— recipe_secure_drupal Module code inside recipe. Intentional vs. accidental not determined.
— 33 node types Live content audit not complete.

SECTION 10 — HUMAN DECISIONS REQUIRED

These items cannot be resolved by evidence collection alone.

# Item Decision Required
H-01 app/ (Next.js) Replace capabilities with Drupal Dashboard + Canvas + Webhooks, or move to a separate deployment repo?
H-02 ai.json (EVID-021) Who owns this? What is it?
H-03 __DRUPAL/Module/_quarantine/ What is demo_agent_marketplace_misplaced_site? Origin and purpose?
H-04 deployment/index.html What is this?
H-05 public/ (EVID-023) What is in this directory?
H-06 PRIVATE + CUSTOM-CONTRIB → same folder Intentional? Should CUSTOM-CONTRIB be a separate path for drupal.org submission candidates?
H-07 recipe_ai_marketplace + recipe_secure_drupal Module code inside recipe directories — intentional bundle or accident?
H-08 ai_agents_marketplace duplication Exists in both web/modules/custom/ (in-repo) and __DRUPAL/Module/. Has DRUPAL_ORG_SUBMISSION.md. Active submission in progress? Which copy is canonical?
H-09 PATCH-06 (drupal-tool return types) Search drupal.org/project/tool/issues. Wire with issue URL, or update version constraint?
H-10 PATCH-03/04/05 (private module patches) Confirm with api_normalization module owner: are these fixes committed to module source? If yes, delete patch files.

Per 12 §2 Wave 1: artifact classification and governance status assignment. No owner assignments yet.

  1. Assign governance status (Known, Unknown, Protected, Needs Review) to every EVID in §1.2.
  2. Complete the grep -r "bluefly_theme:" config/sync/ audit to determine which SDC component version is referenced by Canvas configs.
  3. Resolve H-09 and H-10 (patch decisions) before the next Composer operation.
  4. Map ECA model triggers and actions (all 13) as a capability inventory.
  5. Map the mcp_registry service dependency graph to understand downstream clients.
  6. Classify PATCH-03, 04, 05 formally per 12 §2 Wave 1 before next composer install.
  7. Determine authorship method of openapi.yaml (generated vs. hand-maintained).

STANDARDS IMPROVEMENT RECOMMENDATIONS

Per the governing directive: if a genuine deficiency is found in 07, 11, or 12, produce a recommendation here rather than creating a repository-specific variant.

REC-01 — 12 does not define a Patch Policy Standards 07 and 12 forbid custom contrib patches but do not define a formal patch lifecycle (expiration conditions, issue URL requirements, private-module patch prohibition). Recommendation: add a §5 Patch Governance section to 12 defining: upstream patches require drupal.org issue URL + expiration condition; patches against private modules require the fix to land in module source; no patch may add new PHP classes.

REC-02 — 12 is Drupal-centric; platform authority table is absent Standard 12 §0 references "authority" without defining the full platform authority map (OSSA, OpenClaw, ContractPlane, GitLab, 1Password, OCI). A single platform capability ownership table would allow Wave 1.5 to propose non-Drupal authorities where appropriate. Recommendation: add a §Platform Capability Ownership section to 12 (or a new standard 13) defining authority for installation, governance, secrets, runtime, deployment, monitoring, and receipts.

REC-03 — Authority Receipt format is not defined in any standard Wave 4 of 12 requires "Evidence → Validation → Retire" but does not define the artifact format for the audit trail. Recommendation: add an Authority Receipt template to 12 §2 Wave 4 defining required fields (capability, current owner, new owner, evidence, validation method, retirement approval, retirement date).