Runtime Capability Authority ADR: Decentralized Universal AI Discovery Protocol (DUADP)¶
1. Capability Inventory¶
Governance must always begin with the capability inventory. Separate the Protocol/Standard from the Implementation.
Capability A: DUADP Protocol (Specification)¶
- Protocol: DUADP (Decentralized Universal AI Discovery Protocol)
- Purpose: The specification defining
duadp://OS handlers, DID identity, federation, manifests, peer discovery, and transport negotiation. - Protocol Authority: Bluefly Product (NPM Project:
duadp)
Capability B: Drupal DUADP Implementation¶
- Implementation: Drupal Contrib module (
duadp,duadp_discovery) - Purpose: Merely one reference implementation bridging the NPM-based DUADP protocol specification into the Drupal ecosystem.
- Implementation Authority: Drupal Contrib (Must be clean of proprietary IP, acting purely as the bridge to the NPM standard).
2. Authority Evaluation Order¶
Evaluate authorities in order, then record the stopping point.
Order of Evaluation: Business Capability → Open Standards (ActivityPub, DIDComm) → Existing Protocols → Drupal Core → Drupal CMS → Drupal Contrib → Composer Ecosystem → NPM Ecosystem → OSSA → Bluefly Extension → Bluefly Product
Stopped at: NPM Ecosystem (blueflyio/duadp/duadp)
Reason: The overarching authority for the protocol logic belongs to the standalone NPM project. Drupal should not reinvent the protocol algorithm; it should act as a runtime bridge to it.
3. Capability Comparison Matrix¶
Split "uses" from "owns". A capability using a core API does not own it.
| Feature / Capability | Current Implementation | Candidate Ecosystem Primitive | Owner | Gap (Delta Taxonomy) |
|---|---|---|---|---|
| DID Identity & Verification | Custom PHP | NPM DUADP Package | Bluefly Product | PRODUCT (Must rely on NPM upstream) |
| Federation Protocol/Algorithm | Custom PHP | NPM DUADP Package | Bluefly Product | PRODUCT (Must rely on NPM upstream) |
URI Scheme (duadp://) |
Custom PHP | NPM DUADP Package | Bluefly Product | PRODUCT (Must rely on NPM upstream) |
| Discovery Registry Transport | Custom Controllers | JSON:API | Drupal Core | CONFIG (Migrate to Core) |
| Registry Storage/Querying | Custom Queries | Views | Drupal Core | CONFIG (Migrate to Core) |
| Registry Serialization | Custom Normalizers | JSON:API Normalizers | Drupal Core | EXTENSION (Extend Core formats) |
| Async Task Execution | Queue API | Queue API / ECA | Drupal Core | NONE (Uses existing) |
4. Current Assessment¶
- Protocol Authority: DUADP Specification (Bluefly Product NPM package)
- Reference Implementation: Drupal (Contrib)
- Other Planned Implementations: OpenClaw, Gas Town, CLI, SDKs
- Confidence: HIGH
- Reason: Explicitly separating the Protocol (NPM) from the Implementation (Drupal) prevents Drupal from accidentally becoming the canonical source of truth for the mesh protocol. The Drupal module must be refactored to delegate data exposure to native config (Views/JSON:API) and delegate protocol execution to the NPM package / defined spec.
5. Enhancement Backlog (The Engineering Plan)¶
What ultimately reduces custom code.
Move to Core / Config (NONE / CONFIG) * Queue execution (Adopt core fully) * Config entities (Adopt core schema) * Discovery Storage (Move to Views) * Discovery Transport (Move to JSON:API) * Cache API integration
Move to Contrib (EXTENSION) * ECA integration definitions * Tool API integrations
Retain as Product / Upstream NPM (PRODUCT) * Federation algorithm * Discovery protocol logic * DID verification and generation * Mesh routing and peer negotiation (Note: These Product capabilities should ideally be handled by compiling the NPM DUADP library or adhering strictly to its spec, rather than rewriting complex algorithms in PHP).
6. Governance Outcome & Evidence Gates¶
Target Outcome: Candidate Upstream (NPM) / Candidate Package (Drupal Contrib)
Evidence Checklist: - [x] Capability inventoried (Protocol vs Implementation separated) - [x] Authority identified (NPM DUADP Package) - [x] Remaining delta defined granularly - [ ] Enhancement plan drafted (Focus on ripping out PHP-reinvented protocol logic and shifting to Views/JSON:API config) - [ ] Implementation validated - [ ] Receipt