Skip to content

13 · Version constraint on Canvas (<1.11) makes Lupus Decoupled Starter uninstallable on Drupal CMS 2.2

Project Canvas ExtJS (canvas_extjs); affects Lupus Decoupled Starter (site template)
Component Code (composer.json)
Category Bug report
Priority Major
Status Draft, not filed on drupal.org yet
Patch canvas_extjs-allow-canvas-1.11-1.12.patch

Problem/Motivation

Drupal CMS 2.2 requires drupal/canvas:^1.11. The newest release of Canvas ExtJS, 1.2.3, only allows drupal/canvas >=1.5 <1.11. Lupus Decoupled Starter 2.2.0 requires drupal/canvas_extjs:^1.2, so no version of the site template can be installed on Drupal CMS 2.2: choosing it in the installer fails, and so does adding it with Composer.

Composer output (Drupal CMS 2.2.1, Drupal core 11.4.8, Canvas 1.12.0, Composer 2.10.3):

Problem 1
  - Root composer.json requires drupal/lupus_decoupled_starter * -> satisfiable by drupal/lupus_decoupled_starter[1.1.0, 1.1.1, 2.0.0, 2.1.0, 2.1.1, 2.2.0].
  - drupal/canvas_extjs 1.2.3 requires drupal/canvas >=1.5 <1.11 || 1.x-dev -> found drupal/canvas[1.5.0, ..., 1.10.1] but it conflicts with your root composer.json require (^1.11).
  - drupal/lupus_decoupled_starter 2.2.0 requires drupal/canvas_extjs ^1.2 -> satisfiable by drupal/canvas_extjs[1.2.0, 1.2.1, 1.2.2, 1.2.3].
  - drupal/lupus_decoupled_starter[1.1.0, ..., 1.1.1] require drupal/drupal_cms_starter ^1.0 -> satisfiable by drupal/drupal_cms_starter[1.0.0, ..., 1.2.11].
  - drupal/drupal_cms_starter[1.0.5, ..., 1.2.11] require drupal/eca ^2.1.4 -> found drupal/eca[2.1.4, ..., 2.1.24] but it conflicts with your root composer.json require (^3.1.2).

(Shortened; the older releases of both projects fail on the same Canvas constraint or on the Drupal CMS 1.x dependencies.)

Steps to reproduce

  1. composer create-project drupal/cms test
  2. cd test && composer require drupal/lupus_decoupled_starter
  3. Composer cannot resolve the dependencies (see above). Choosing Lupus Decoupled Starter in the Drupal CMS installer fails the same way.

Proposed resolution

The 1.x branch is already compatible with Canvas 1.11: commit 0e54f12 (#3618329, 2026-08-20) passes the ColorResolver that Canvas 1.11 added to JsonSchemaPropsComponentSourceBase. Only composer.json still says <1.11. Since that commit, the branch actually requires Canvas 1.11 or later (ColorResolver does not exist in Canvas 1.10), so the lower bound has to move as well.

Attached patch against 1.x, following the existing "Allow installing canvas 1.x.*" issues:

-    "drupal/canvas": ">=1.5 <1.11 || 1.x-dev",
+    "drupal/canvas": ">=1.11 <1.13 || 1.x-dev",

Tested with Drupal core 11.4.8 and PHP 8.5:

  • All 50 kernel tests of Canvas ExtJS pass with Canvas 1.11.0 and with Canvas 1.12.0 (507 assertions; only deprecation notices from Canvas and Symfony).
  • With the patch, composer require drupal/lupus_decoupled_starter resolves on Drupal CMS 2.2.1, and the site template installs; its 16 external JavaScript components are registered. (The installation additionally needs the fixes from two separate issues, see below.)

A tagged release (1.2.4) would make Lupus Decoupled Starter installable again without changes, since it accepts any ^1.2 release.

So far every release has raised the upper bound by one Canvas minor version (<1.4, <1.5, … <1.11), so the template breaks again with every new Canvas minor release until Canvas ExtJS catches up. Running the tests against the latest Canvas release in CI would surface this early.

Remaining tasks

  • Review and commit the patch, tag a release.

Additional information

Checked on 2026-09-29. The site template is offered in the Drupal CMS 2.2 installer, so users run into this right away. Installing it on Drupal CMS 2.2 needs two more fixes that are not part of this issue: the recipe includes Drupal CMS recipes that are no longer installed with Drupal CMS 2.2 (report #40), and Canvas fails on its JSON-encoded component inputs (report #03).

Copy to drupal.org

Issue title:

Version constraint on Canvas (<1.11) makes Lupus Decoupled Starter uninstallable on Drupal CMS 2.2

Issue summary (paste it into the "Issue summary" field; project, component, category and priority are in the table above):

<h3 id="summary-problem-motivation">Problem/Motivation</h3>
<p>Drupal CMS 2.2 requires <code>drupal/canvas:^1.11</code>. The newest release of Canvas ExtJS, 1.2.3, only allows <code>drupal/canvas >=1.5 <1.11</code>. Lupus Decoupled Starter 2.2.0 requires <code>drupal/canvas_extjs:^1.2</code>, so no version of the site template can be installed on Drupal CMS 2.2: choosing it in the installer fails, and so does adding it with Composer.</p>
<p>Composer output (Drupal CMS 2.2.1, Drupal core 11.4.8, Canvas 1.12.0, Composer 2.10.3):</p>
<code>Problem 1
  - Root composer.json requires drupal/lupus_decoupled_starter * -> satisfiable by drupal/lupus_decoupled_starter[1.1.0, 1.1.1, 2.0.0, 2.1.0, 2.1.1, 2.2.0].
  - drupal/canvas_extjs 1.2.3 requires drupal/canvas >=1.5 <1.11 || 1.x-dev -> found drupal/canvas[1.5.0, ..., 1.10.1] but it conflicts with your root composer.json require (^1.11).
  - drupal/lupus_decoupled_starter 2.2.0 requires drupal/canvas_extjs ^1.2 -> satisfiable by drupal/canvas_extjs[1.2.0, 1.2.1, 1.2.2, 1.2.3].
  - drupal/lupus_decoupled_starter[1.1.0, ..., 1.1.1] require drupal/drupal_cms_starter ^1.0 -> satisfiable by drupal/drupal_cms_starter[1.0.0, ..., 1.2.11].
  - drupal/drupal_cms_starter[1.0.5, ..., 1.2.11] require drupal/eca ^2.1.4 -> found drupal/eca[2.1.4, ..., 2.1.24] but it conflicts with your root composer.json require (^3.1.2).</code>
<p>(Shortened; the older releases of both projects fail on the same Canvas constraint or on the Drupal CMS 1.x dependencies.)</p>
<h3 id="summary-steps-reproduce">Steps to reproduce</h3>
<ol>
<li><code>composer create-project drupal/cms test</code></li>
<li><code>cd test && composer require drupal/lupus_decoupled_starter</code></li>
<li>Composer cannot resolve the dependencies (see above). Choosing Lupus Decoupled Starter in the Drupal CMS installer fails the same way.</li>
</ol>
<h3 id="summary-proposed-resolution">Proposed resolution</h3>
<p>The <code>1.x</code> branch is already compatible with Canvas 1.11: commit 0e54f12 (#3618329, 2026-08-20) passes the <code>ColorResolver</code> that Canvas 1.11 added to <code>JsonSchemaPropsComponentSourceBase</code>. Only <code>composer.json</code> still says <code><1.11</code>. Since that commit, the branch actually requires Canvas 1.11 or later (<code>ColorResolver</code> does not exist in Canvas 1.10), so the lower bound has to move as well.</p>
<p>Attached patch against <code>1.x</code>, following the existing "Allow installing canvas 1.x.*" issues:</p>
<code>-    "drupal/canvas": ">=1.5 <1.11 || 1.x-dev",
+    "drupal/canvas": ">=1.11 <1.13 || 1.x-dev",</code>
<p>Tested with Drupal core 11.4.8 and PHP 8.5:</p>
<ul>
<li>All 50 kernel tests of Canvas ExtJS pass with Canvas <strong>1.11.0</strong> and with Canvas <strong>1.12.0</strong> (507 assertions; only deprecation notices from Canvas and Symfony).</li>
<li>With the patch, <code>composer require drupal/lupus_decoupled_starter</code> resolves on Drupal CMS 2.2.1, and the site template installs; its 16 external JavaScript components are registered. (The installation additionally needs the fixes from two separate issues, see below.)</li>
</ul>
<p>A tagged release (1.2.4) would make Lupus Decoupled Starter installable again without changes, since it accepts any <code>^1.2</code> release.</p>
<p>So far every release has raised the upper bound by one Canvas minor version (<code><1.4</code>, <code><1.5</code>, … <code><1.11</code>), so the template breaks again with every new Canvas minor release until Canvas ExtJS catches up. Running the tests against the latest Canvas release in CI would surface this early.</p>
<h3 id="summary-remaining-tasks">Remaining tasks</h3>
<ul>
<li>Review and commit the patch, tag a release.</li>
</ul>
<h3>Additional information</h3>
<p>Checked on 2026-09-29. The site template is offered in the Drupal CMS 2.2 installer, so users run into this right away. Installing it on Drupal CMS 2.2 needs two more fixes that are not part of this issue: the recipe includes Drupal CMS recipes that are no longer installed with Drupal CMS 2.2 (report #40), and Canvas fails on its JSON-encoded component inputs (report #03).</p>