WAVE 0 EVIDENCE RECEIPT¶
ContextControl.ai — bluefly.io¶
Receipt Type: Wave 0 — Evidence Collection
Governing Standards:
- Engineering-Standard/standards/drupal/07-CONTRIB-FIRST.md (BluTown-Docs) — Architectural principles, allowed primitives, forbidden implementations
- Engineering-Standard/standards/drupal/12-DRUPAL-APPLICATION-GOVERNANCE.md (BluTown-Docs) — Delta Principle, Single Authority, Governance Lifecycle, Citizenship Criteria
- Engineering-Standard/standards/drupal/11-DRUPAL-BUILD-CONTRACT.md (BluTown-Docs) — Build-time validation, module classifier, CI enforcement
Wave: 0 — Evidence Collection only. Per 12 §2 Wave 0: read-only inventory. No architectural replacements. No candidate owner assignments. Opinions are forbidden at this wave. Status: FROZEN — evidence only. All EVID items are observed facts. Date collected: 2026-07-01 Collected by: Agent — read-only filesystem inspection + git tracking verification + composer.json analysis + config/sync analysis.
SECTION 1 — ROOT FOLDER INVENTORY¶
Evidence collected per 12 §2 Wave 1 Artifact Taxonomy.
1.1 Standard Drupal Composer Project Artifacts¶
| Artifact | Class | Git Tracked | Observation |
|---|---|---|---|
web/ |
SOURCE | ✅ | Drupal docroot |
vendor/ |
GENERATED | Gitignored | Composer-managed |
config/sync/ |
CONFIG | ✅ | 1,847+ config files observed |
composer.json |
SOURCE | ✅ | 148 required packages |
composer.lock |
GENERATED | ✅ | ~1MB |
patches/ |
BUILD | ✅ | 6 patch files — see §4 |
recipes/ |
INSTALL | ✅ | Mixed contrib + custom — see §6 |
private/ |
RUNTIME | ✅ (empty) | Drupal private files dir |
.ddev/ |
BUILD | ✅ | DDEV config, 30+ compose files |
.gitlab-ci.yml |
BUILD | ✅ | CI pipeline config |
Dockerfile |
BUILD | ✅ | OCI image build |
lefthook.yml |
BUILD | ✅ | Git hooks |
external/ |
BUILD | ✅ | Symlink → cloned-for-today/_DRUPAL |
1.2 Non-Standard Artifacts — Classified¶
| EVID | Artifact | Class | Git Tracked | Observation |
|---|---|---|---|---|
| EVID-001 | app/ |
RUNTIME | ✅ | Next.js application: TSX pages, API routes (/api/activity, /api/webhooks, /api/tools), TypeScript stores. Contains full npm project with @bluefly/* dependencies. |
| EVID-002 | lib/ |
RUNTIME | ✅ | TypeScript stores: activity-store.ts, webhook-store.ts, memory-store.ts, auth.ts. Part of EVID-001. |
| EVID-003 | node_modules/ |
GENERATED | Gitignored | npm dependencies for EVID-001. |
| EVID-004 | package.json |
BUILD | ✅ | Next.js + Radix UI + @bluefly/* npm packages. Script names include bluefly:validate, bluefly:workspace-status. |
| EVID-005 | package-lock.json |
GENERATED | ✅ | 430KB npm lockfile. |
| EVID-006 | agentblu-tools-mcp.mjs |
RUNTIME | ✅ | MCP stdio server. Comment: "Deploy to Oracle at /home/node/.openclaw/". Key: not a Drupal artifact; stated deployment target is Oracle/OpenClaw. |
| EVID-007 | memory/ |
RUNTIME | ✅ | AI agent dream/memory logs. Contains dreaming/deep/, dreaming/rem/, dreaming/light/ JSONL + Markdown files dating 2026-05-22 through 2026-06-02. |
| EVID-008 | _dev_scripts/ |
RECOVERY | ✅ | 11 PHP scripts tracked in git. See §2 for full inventory. |
| EVID-009 | web/fix_versions.php |
RECOVERY | ✅ | PHP script in web docroot. Manipulates canvas_page entity storage directly. Publicly accessible via HTTP. |
| EVID-010 | Plans/ |
DOCS | ✅ | 12 markdown planning files: REBUILD-MASTER.md, REDESIGN-ARCHITECTURE.md, SDC_COMPONENTS_MANIFEST.md, etc. |
| EVID-011 | debug_altcha.html |
GENERATED | ✅ | 173KB debug HTML artifact. |
| EVID-012 | debug_forms.html |
GENERATED | ✅ | 183KB debug HTML artifact. |
| EVID-013 | debug_login.html |
GENERATED | ✅ | 15KB debug HTML artifact. |
| EVID-014 | auth.json |
RUNTIME | ✅ | Content: {}. Empty Composer auth file tracked in source control. |
| EVID-015 | openapi.yaml |
GENERATED | ✅ | 96KB OpenAPI specification at repo root. Authorship method (hand-written vs. generated) not determined at Wave 0. |
| EVID-016 | data/ |
— | ✅ | Contains only .gitkeep. No other files observed. |
| EVID-017 | deployment/ |
UNKNOWN | ✅ | Contains only index.html. Purpose not determined. Protected Until Ownership Proven. |
| EVID-018 | api-reference/ |
DOCS | Unknown | Contains only introduction.mdx. Mintlify stub. |
| EVID-019 | mint.json |
BUILD | Unknown | Mintlify documentation configuration. |
| EVID-020 | screenshots/ |
DOCS | ✅ | Contains home-mock.png. Design mockup. |
| EVID-021 | ai.json |
UNKNOWN | ✅ | 20KB file at repo root. Content not fully parsed. Owner and class not determined. Protected Until Ownership Proven. |
| EVID-022 | docs/ |
DOCS | Unknown | Contains 4 files: bluefly-design-system-review.html, consolidation_playbook.md, consolidation_receipt.md, drupal-2026-catalog.html. |
| EVID-023 | public/ |
UNKNOWN | Unknown | Contents not observed. Protected Until Ownership Proven. |
| EVID-024 | tests/ |
BUILD | Unknown | Contains e2e/ and support/ — Playwright tests. |
| EVID-025 | introduction.mdx |
DOCS | Unknown | Mintlify page stub at repo root. |
SECTION 2 — CAPABILITY INVENTORY¶
Per 12 §2 Wave 0: capability inventory only. No owner assignments at this wave.
2.1 Capabilities Observed in _dev_scripts/ (EVID-008)¶
| Script | Observed Capability |
|---|---|
create_missing_components.php |
Creates Canvas components programmatically |
create_pages.php |
Creates Canvas pages |
create_remaining_pages.php |
Creates additional Canvas pages |
diagnose_components.php |
Inspects Canvas component state |
diagnose_partner.php |
Inspects partner content |
fix_all_versions.php |
Corrects component version field values |
fix_versions_sql.php |
Corrects version field values via SQL |
strip_unsupported_inputs.php |
Removes unsupported field values from content |
update_component_config.php |
Updates Canvas component configuration |
update_hero_component.php |
Updates hero SDC component configuration |
update_link_components.php |
Updates link component configuration |
2.2 Capabilities Observed in app/ (EVID-001)¶
| Route / File | Observed Capability |
|---|---|
app/api/activity/route.ts |
Activity event ingestion API |
app/api/activity/stream/route.ts |
Activity event streaming (SSE) |
app/api/tools/route.ts |
Tool listing API |
app/api/tools/activity/route.ts |
Activity tool API |
app/api/tools/gitlab/route.ts |
GitLab tool API |
app/api/tools/memory/route.ts |
Memory tool API |
app/api/webhooks/route.ts |
Inbound webhook receiver |
app/api/webhooks/gitlab/route.ts |
GitLab webhook receiver |
app/api/webhooks/stats/route.ts |
Webhook statistics API |
app/activity/page.tsx |
Activity dashboard page |
app/activity-stream.tsx |
Activity stream React component |
2.3 Contrib Modules Installed for Equivalent Capabilities (observed in composer.json)¶
| Capability | Installed Contrib | Module Enabled (core.extension.yml) |
|---|---|---|
| Webhook processing | drupal/webhooks |
✅ webhooks |
| Tool plugins | drupal/tool |
✅ tool, tool_ai_connector |
| MCP tools | drupal/mcp_tools |
✅ mcp_tools, mcp_tools_remote |
| Admin dashboard | drupal/dashboard |
✅ dashboard |
| AI provider abstraction | drupal/ai |
✅ ai |
| AI agents | drupal/ai_agents |
✅ ai_agents |
| Workflow automation | drupal/eca |
✅ eca |
SECTION 3 — CONTRIB OWNERSHIP FINDINGS¶
Per 11 §Build Contract 1 — Contrib Audit patterns. Per 07 §Forbidden Implementations.
3.1 web/libraries/ — Manual Installation Observed¶
4 libraries installed manually (not via Composer). No composer.json path-repo or asset-packagist reference found for any.
| Library | Installed Contrib Module | Module Enabled |
|---|---|---|
friendly-challenge |
drupal/friendlycaptcha |
✅ |
klaro |
drupal/klaro |
✅ |
rtseo.js |
drupal/yoast_seo |
✅ yoast_seo |
vanilla-icon-picker |
Not determined | Unknown |
Observation: Three of four libraries have a corresponding installed contrib module. Whether those modules manage their library assets or require the manual installation is not determined at Wave 0.
3.2 web/libraries/studio-ui/ — Empty Directory¶
An empty studio-ui directory exists in web/libraries/. No files observed. Purpose not determined.
3.3 openapi.yaml (EVID-015)¶
drupal/openapi and drupal/openapi_jsonapi are both installed and enabled (openapi, openapi_jsonapi in core.extension.yml). A 96KB openapi.yaml exists at repo root. Relationship between the installed modules and this file not determined at Wave 0.
SECTION 4 — PATCH LEDGER¶
Per 07 §Contrib-First and the principle that patches against Drupal contrib must have an upstream issue on drupal.org.
Applied Patches (in composer.json)¶
PATCH-01: patches/drupal-tfa-reset-pass-login-signature-drupal11.patch
| Field | Observation |
|---|---|
| Target | drupal/tfa ^1.0 |
| Applied | Yes — composer.json |
| What it changes | Adds Request $request parameter to TfaUserControllerDeprecated::resetPassLogin() |
| Drupal.org issue | Confirmed active — "Drupal 11 resetPassLogin signature compatibility" in TFA issue queue |
| Issue URL in composer key | No — missing |
PATCH-02: patches/media_library-base-field-id-fix.patch
| Field | Observation |
|---|---|
| Target | drupal/core — media_library submodule |
| Applied | Yes — composer.json |
| What it changes | Guards MediaLibraryWidget against calling id() on BaseFieldDefinition |
| Drupal.org issue | Confirmed — issue #3563487: "Media library widget cannot be used with base fields" |
| Issue URL in composer key | No — missing |
Patches On Disk But NOT Applied in composer.json¶
PATCH-03: patches/api_normalization-eca-action-type-mismatch.patch
| Field | Observation |
|---|---|
| Target | drupal/api_normalization |
| Applied | No |
| What it changes | Renames service class references: ApiNormalizationService → NormalizationService; ApiNormalizerService → NormalizationService (3 files) |
| Drupal.org issue | None — api_normalization is a Bluefly private module, not on drupal.org |
| Governance note | A service class rename applied to a private module via Composer patch is not an upstream patch. 12 §0.1 requires ownership to rest with the module source. Wave 1.5 must determine owner. |
PATCH-04: patches/api_normalization-eca-subscriber-container-init.patch
| Field | Observation |
|---|---|
| Target | drupal/api_normalization |
| Applied | No |
| What it changes | Replaces conditional ECA module-exists check in EcaAgentEventSubscriber::getSubscribedEvents() with return [] |
| Drupal.org issue | None |
| Governance note | Same as PATCH-03 — private module, no upstream path. |
PATCH-05: patches/api_normalization-missing-services.patch
| Field | Observation |
|---|---|
| Target | drupal/api_normalization |
| Applied | No |
| What it changes | Adds a new PHP class (CircuitBreakerService) to the module. Patch comment states: "This class was missing from api_normalization 1.0.0-alpha4." |
| Drupal.org issue | None |
| Governance note | This patch adds a new class to a module via diff. This is the observed fact. Wave 1.5 must determine where CircuitBreakerService ownership belongs per 07's Architectural Taxonomy. |
PATCH-06: patches/drupal-tool-legacy-typed-data-normalizer-return-type.patch
| Field | Observation |
|---|---|
| Target | drupal/tool 1.0.x-dev |
| Applied | No |
| What it changes | Narrows return types on LegacyTypedDataNormalizer, ContextDefinitionNormalizer, MapDefinitionNormalizer to : array to resolve PHP 8.4 LSP violations |
| Drupal.org issue | Not verified. Requires search at drupal.org/project/tool/issues. |
| Governance note | Target is contrib on drupal.org. If an upstream issue exists, this is a candidate for Type A (upstream patch). If fixed in a newer release, version constraint update supersedes the patch. Not determinable at Wave 0. |
Patch Ledger Summary¶
| Patch | Applied | Drupal.org Issue Confirmed | Observation |
|---|---|---|---|
drupal-tfa-reset-pass-login-signature-drupal11.patch |
✅ | ✅ Active | Missing issue URL in composer key |
media_library-base-field-id-fix.patch |
✅ | ✅ #3563487 | Missing issue URL in composer key |
api_normalization-eca-action-type-mismatch.patch |
❌ | ❌ Private module | Not applied; Wave 1.5 required |
api_normalization-eca-subscriber-container-init.patch |
❌ | ❌ Private module | Not applied; Wave 1.5 required |
api_normalization-missing-services.patch |
❌ | ❌ Private module | Not applied; adds new class; Wave 1.5 required |
drupal-tool-legacy-typed-data-normalizer-return-type.patch |
❌ | ⚠️ Not verified | Not applied; drupal.org issue search required |
SECTION 5 — SDC / THEME FINDINGS¶
5.1 Theme Structure¶
| Theme | Location | Base Theme | Observation |
|---|---|---|---|
agentic_canvas |
web/themes/custom/agentic_canvas/ |
false |
Engine theme. name: 'LLM Platform Manager' in .info.yml. Also exists as empty directory in web/themes/contrib/agentic_canvas/. |
bluefly_theme |
web/themes/custom/bluefly_theme/ |
agentic_canvas |
Marketing sub-theme. name: Bluefly Theme. |
Observation: agentic_canvas appears in both custom/ and contrib/. The contrib/ copy is empty. The custom/ copy is the active installation. Both .gitignore and Composer path repos reference external/_DRUPAL/THEMES/agentic_canvas_theme. Relationship between these three locations not fully determined at Wave 0.
5.2 SDC Component Duplication¶
bluefly_theme/components/ contains 46 SDC components. 22 exist in two versions simultaneously:
| Bare Name | Prefixed Name |
|---|---|
accordion |
bluefly-accordion |
agent-card |
bluefly-agent-card |
agent-service-grid |
bluefly-agent-service-grid |
arch-diagram |
bluefly-arch-diagram |
card |
bluefly-card |
case-study-card |
bluefly-case-study-card |
certification-badge |
bluefly-certification-badge |
comparison-table |
bluefly-comparison-table |
cta-cluster |
bluefly-cta-cluster |
evidence-panel |
bluefly-evidence-panel |
feature-grid |
bluefly-feature-grid |
flow-drop-embed |
bluefly-flow-drop-embed |
hero |
bluefly-hero |
logo-strip |
bluefly-logo-strip |
profile-card |
bluefly-profile-card |
resource-card |
bluefly-resource-card |
section |
bluefly-section |
service-card |
bluefly-service-card |
sod-table |
bluefly-sod-table |
stats-block |
bluefly-stats-block |
timeline |
bluefly-timeline |
trust-tier-badge |
bluefly-trust-tier-badge |
Unique to bare (no prefixed version): partner-card, tab-group
Unique to prefixed (no bare version): none beyond the 22 pairs.
Observation: Both versions exist simultaneously. Which Canvas page configs reference which version is not determined at Wave 0. This requires a grep -r "bluefly_theme:" config/sync/ audit before any Wave 3 action.
SECTION 6 — RECIPE AND CONFIGURATION FINDINGS¶
6.1 Config/Sync Scale¶
| Config Type | Count |
|---|---|
canvas.component.* |
166 |
field.field.* |
426 |
field.storage.* |
257 |
views.view.* |
42 |
block.block.* |
69 |
eca.eca.* |
13 |
node.type.* |
33 |
image.style.* |
65 |
core.entity_view_display.* |
102 |
taxonomy.vocabulary.* |
17 |
6.2 Recipe Integrity Findings¶
| Recipe | Location | Observation |
|---|---|---|
recipe_ai_marketplace |
__DRUPAL/Recipes/recipe_ai_marketplace/ |
Contains both recipe.yml AND module code: agent_marketplace.info.yml, agent_marketplace.routing.yml, agent_marketplace.services.yml, src/. Whether this is intentional packaging is not determined at Wave 0. Protected Until Ownership Proven. |
recipe_secure_drupal |
__DRUPAL/Recipes/recipe_secure_drupal/ |
Contains both recipe.yml AND module code: secure_drupal.module, secure_drupal.services.yml, src/, templates/. Also contains test_field_api.php and validate_implementation.php at recipe root. Protected Until Ownership Proven. |
recipe_agent_platform |
__DRUPAL/Recipes/recipe_agent_platform/ |
Contains recipe.yml, config/, content/ (YAML content files), assets/, scripts/, Playwright tests. |
drupal_cms_starter |
recipes/drupal_cms_starter/ |
Contrib recipe — recipe.yml + content/ YAML files + screenshot.webp. |
easy_email_* |
recipes/easy_email_*/ |
4 contrib recipes — standard recipe shape. |
6.3 external/_DRUPAL Symlink Chain¶
| Path | Resolves To |
|---|---|
external/_DRUPAL |
cloned-for-today/_DRUPAL (symlink) |
cloned-for-today/_DRUPAL/PRIVATE |
<workspace>/PROJECTS/__DRUPAL/Module |
cloned-for-today/_DRUPAL/CUSTOM-CONTRIB |
<workspace>/PROJECTS/__DRUPAL/Module |
cloned-for-today/_DRUPAL/RECIPES |
<workspace>/PROJECTS/__DRUPAL/Recipes |
cloned-for-today/_DRUPAL/THEMES |
<workspace>/PROJECTS/__DRUPAL/Themes |
Observation: PRIVATE and CUSTOM-CONTRIB both resolve to the same filesystem path (__DRUPAL/Module). The namespace distinction exists in the Composer path-repo declarations but not on disk. Whether this is intentional is not determined at Wave 0.
6.4 __DRUPAL/Module Contents — 52 Modules Observed¶
_quarantine/ agent_bootstrap_authority agent_registry_consumer
agentdash_platform agentic_canvas_blocks ai_agents_agui
ai_agents_blu_ops ai_agents_claude ai_agents_client
ai_agents_communication ai_agents_crewai ai_agents_cursor
ai_agents_dashboard ai_agents_huggingface ai_agents_kagent
ai_agents_marketplace ai_agents_ossa ai_agents_tunnel
ai_provider_apple ai_provider_langchain ai_provider_routing_eca
alternative_services api_normalization apidog_integration
apidog_integration_v1 blockchain_manager blu-fleet
cedar_policy charts_ai_analytics code_executor
contractplane_client copaw_bridge dita_ccms
dragonfly_client drupal_audit drupal_patch_framework
duadp duadp_client external_migration
kb_cache layout_system_converter mcp_gateway
openclaw playbook_engine recipe_onboarding
skills_browser source_connect source_connector
source_connector_compliance source_connector_mcp
Observation: _quarantine/ exists. Contents include a full Drupal web installation (demo_agent_marketplace_misplaced_site/web/...). Purpose not determined. Protected Until Ownership Proven.
SECTION 7 — IN-REPO CUSTOM MODULES (web/modules/custom/)¶
Per 11 §Build Contract 3 — Module Classifier. Classification at Wave 0 is observation only.
| Module | In Repo or Symlink | Observation |
|---|---|---|
mcp_registry |
In-repo (not symlink) | Has own AGENTS.md, CLAUDE.md, CODEOWNERS, openapi.yaml, mkdocs.yml, scripts/, tools/. Complex. |
blu_fleet |
In-repo | Has composer.json, drush.services.yml, modules/ sub-directory. |
ai_agents_marketplace |
In-repo | Has drupal.org submission documents (CHANGES_FOR_DRUPAL_ORG.md, DRUPAL_ORG_SUBMISSION.md). Also exists in __DRUPAL/Module. Duplicate locations observed. |
cedar_policy |
In-repo | Has composer.json, CSS, JS. |
recipe_onboarding |
Symlink → __DRUPAL/Module |
|
drupal_patch_framework |
Symlink → __DRUPAL/Module |
|
source_connector |
Symlink → __DRUPAL/Module |
Involved in drush status failure (previous session context: LegacyServiceInstantiator missing parameter source_connector_mcp.client) |
dita_ccms |
Symlink → __DRUPAL/Module |
|
alternative_services |
Symlink → __DRUPAL/Module |
|
skills_browser |
Symlink → __DRUPAL/Module |
Observation: .gitignore declares /web/modules/custom/ as gitignored. All content in this directory is managed by Composer path repos. The in-repo modules (mcp_registry, blu_fleet, ai_agents_marketplace, cedar_policy) are not directly in git — they are symlinked or installed by Composer from external/_DRUPAL/.
SECTION 8 — DELTA CLASSIFICATIONS¶
Per 12 §0.1 (Delta Principle): classifications at Wave 0 are evidence-based only. Final delta decisions belong to Wave 2.
| EVID | Artifact | Observed Parallel Capability in Contrib | Classification Candidate |
|---|---|---|---|
| EVID-001 | app/api/webhooks/ |
drupal/webhooks installed and enabled |
Candidate: no delta |
| EVID-001 | app/api/tools/ |
drupal/tool + drupal/mcp_tools installed and enabled |
Candidate: no delta |
| EVID-001 | app/api/activity/ |
drupal/dashboard installed and enabled; Views available |
Candidate: no delta |
| EVID-009 | web/fix_versions.php |
drush/drush DrushCommand plugin type available |
Candidate: no delta |
| EVID-008 | _dev_scripts/*.php |
Drupal Migrate API + Drush available | Candidate: no delta |
| EVID-015 | openapi.yaml (root) |
drupal/openapi + drupal/openapi_jsonapi installed |
Authorship method not determined; candidate if hand-maintained |
Note: These are candidates only. Per 12 §2 Wave 1.5, owner assignments remain UNDECIDED until Wave 2.
SECTION 9 — PROTECTED UNTIL OWNERSHIP PROVEN¶
Per 12 §0.3 (Capability Ownership Principle): no artifact is retired until the six-step sequence is complete.
| EVID | Artifact | Reason |
|---|---|---|
| EVID-021 | ai.json (root, 20KB) |
Owner not determined. Class not determined. |
| EVID-017 | deployment/ |
Single index.html. Purpose not determined. |
| EVID-023 | public/ |
Contents not observed. |
| — | __DRUPAL/Module/_quarantine/ |
Full Drupal site embedded. Origin and purpose not determined. |
| — | config/sync/canvas.component.* (166) |
Active site structure. Canvas reference audit not complete. |
| — | config/sync/field.* (683) |
Live content fields. Content audit not complete. |
| — | bluefly_theme/components/ bare-name SDC |
Canvas reference audit (grep -r "bluefly_theme:" config/sync/) not complete. |
| — | mcp_registry module |
Active MCP dependency. Client dependency graph not mapped. |
| — | source_connector module |
Active; involved in known drush status error. Root cause not resolved. |
| — | alternative_services module |
Service container dependency. Container health not verified. |
| — | All 13 ECA models | Automation running. Trigger/action inventory not complete. |
| — | recipe_ai_marketplace |
Module code inside recipe. Intentional vs. accidental not determined. |
| — | recipe_secure_drupal |
Module code inside recipe. Intentional vs. accidental not determined. |
| — | 33 node types | Live content audit not complete. |
SECTION 10 — HUMAN DECISIONS REQUIRED¶
These items cannot be resolved by evidence collection alone.
| # | Item | Decision Required |
|---|---|---|
| H-01 | app/ (Next.js) |
Replace capabilities with Drupal Dashboard + Canvas + Webhooks, or move to a separate deployment repo? |
| H-02 | ai.json (EVID-021) |
Who owns this? What is it? |
| H-03 | __DRUPAL/Module/_quarantine/ |
What is demo_agent_marketplace_misplaced_site? Origin and purpose? |
| H-04 | deployment/index.html |
What is this? |
| H-05 | public/ (EVID-023) |
What is in this directory? |
| H-06 | PRIVATE + CUSTOM-CONTRIB → same folder |
Intentional? Should CUSTOM-CONTRIB be a separate path for drupal.org submission candidates? |
| H-07 | recipe_ai_marketplace + recipe_secure_drupal |
Module code inside recipe directories — intentional bundle or accident? |
| H-08 | ai_agents_marketplace duplication |
Exists in both web/modules/custom/ (in-repo) and __DRUPAL/Module/. Has DRUPAL_ORG_SUBMISSION.md. Active submission in progress? Which copy is canonical? |
| H-09 | PATCH-06 (drupal-tool return types) |
Search drupal.org/project/tool/issues. Wire with issue URL, or update version constraint? |
| H-10 | PATCH-03/04/05 (private module patches) | Confirm with api_normalization module owner: are these fixes committed to module source? If yes, delete patch files. |
SECTION 11 — RECOMMENDED WAVE 1 WORK¶
Per 12 §2 Wave 1: artifact classification and governance status assignment. No owner assignments yet.
- Assign governance status (
Known,Unknown,Protected,Needs Review) to every EVID in §1.2. - Complete the
grep -r "bluefly_theme:" config/sync/audit to determine which SDC component version is referenced by Canvas configs. - Resolve H-09 and H-10 (patch decisions) before the next Composer operation.
- Map ECA model triggers and actions (all 13) as a capability inventory.
- Map the
mcp_registryservice dependency graph to understand downstream clients. - Classify PATCH-03, 04, 05 formally per 12 §2 Wave 1 before next
composer install. - Determine authorship method of
openapi.yaml(generated vs. hand-maintained).
STANDARDS IMPROVEMENT RECOMMENDATIONS¶
Per the governing directive: if a genuine deficiency is found in 07, 11, or 12, produce a recommendation here rather than creating a repository-specific variant.
REC-01 — 12 does not define a Patch Policy Standards 07 and 12 forbid custom contrib patches but do not define a formal patch lifecycle (expiration conditions, issue URL requirements, private-module patch prohibition). Recommendation: add a §5 Patch Governance section to 12 defining: upstream patches require drupal.org issue URL + expiration condition; patches against private modules require the fix to land in module source; no patch may add new PHP classes.
REC-02 — 12 is Drupal-centric; platform authority table is absent Standard 12 §0 references "authority" without defining the full platform authority map (OSSA, OpenClaw, ContractPlane, GitLab, 1Password, OCI). A single platform capability ownership table would allow Wave 1.5 to propose non-Drupal authorities where appropriate. Recommendation: add a §Platform Capability Ownership section to 12 (or a new standard 13) defining authority for installation, governance, secrets, runtime, deployment, monitoring, and receipts.
REC-03 — Authority Receipt format is not defined in any standard Wave 4 of 12 requires "Evidence → Validation → Retire" but does not define the artifact format for the audit trail. Recommendation: add an Authority Receipt template to 12 §2 Wave 4 defining required fields (capability, current owner, new owner, evidence, validation method, retirement approval, retirement date).