Delta Discovery Plan: OSSA Capabilities¶
Engineering Rule: Every investigation must be falsifiable. An investigation is successful when it conclusively determines whether a capability can be satisfied by an existing authority or whether a measurable remaining delta exists. The goal is accurate classification (NONE, CONFIG, EXTENSION, PACKAGE, PRODUCT), not the elimination of custom code.
1. Discovery Transport¶
Current Evidence¶
- Evidence Sources: Existing Implementation, CGR (
cgr-001-ossa), Drupal documentation. - Confidence: LOW
- Known Unknowns:
- JSON:API feature parity with OSSA
.well-knownschemas. - Number of custom Normalizers required.
- Caching behavior of dynamic transport layers.
- JSON:API feature parity with OSSA
Incremental Delta Discovery¶
- Confirmed: Async Task Execution → NONE (Core Queue/ECA)
- Tentative: Registry Queries → CONFIG (Views)
- Unknown: Discovery Transport (
.well-knownendpoints)
Experiment¶
Can JSON:API natively express the required OSSA .well-known schema formats securely and performantly?
Prototype & Benchmark¶
- Prototype: Build one minimal JSON:API endpoint exposing a single OSSA entity type.
- Benchmark: Measure query latency, cache invalidation reliability, and JSON payload size against the custom REST controller baseline.
Criteria¶
- Success Criteria: 100% compliance with OSSA discovery schema; core cacheability maintained.
- Failure Criteria: Investigation fails if:
- More than one custom Normalizer is required.
- Core caching cannot be preserved for public payloads.
- Required metadata cannot be accurately mapped to the spec.
Exit Conditions¶
Investigation is complete when: - [ ] Feature Matrix complete - [ ] Prototype complete - [ ] Benchmark complete - [ ] Remaining delta classified - [ ] CGR updated - [ ] Evidence receipt issued
2. Manifest Validation¶
Current Evidence¶
- Evidence Sources: Existing Implementation (
PhpManifestValidator.php), NPM@blueflyio/openstandardagentssource. - Confidence: LOW
- Known Unknowns:
- Latency of invoking Node locally from PHP.
- Authentication model for a remote validator microservice.
- Feasibility of pure CI/CD validation.
Incremental Delta Discovery¶
- Unknown: Operational Boundary for NPM execution.
Experiment¶
What is the lowest-latency, highest-security method for the Drupal runtime to invoke the canonical NPM validation logic without rewriting the mathematical schema in PHP?
Prototype & Benchmark¶
- Prototype: Build three invocation proofs: Local Node child-process, Remote A2A Service, Offline CI/CD pipeline.
- Benchmark: Measure blocking latency for local and remote executions, and measure the integration complexity of offline validation.
Criteria¶
- Success Criteria: ≤100ms local/remote validation; zero schema divergence; single specification authority maintained.
- Failure Criteria: Investigation fails if:
- Local execution blocks PHP threads for >500ms.
- Remote service requires introducing a complex new secrets broker.
- Offline validation prevents dynamic agent onboarding via the UI.
Exit Conditions¶
Investigation is complete when: - [ ] Feature Matrix complete - [ ] Prototype complete - [ ] Benchmark complete - [ ] Remaining delta classified - [ ] CGR updated - [ ] Evidence receipt issued
3. Registry UI (Catalog)¶
Current Evidence¶
- Evidence Sources: Existing Implementation (
AgentPluginListController.php), Core Views documentation. - Confidence: MEDIUM
- Known Unknowns:
- Capacity of Views to support arbitrary inline execution links (e.g., Quick Launch).
Incremental Delta Discovery¶
- Unknown: Administrative UI Capabilities.
Experiment¶
Can Drupal Views support all required administrative behaviors (inline validation, quick-launch execution) without falling back to custom routing controllers?
Prototype & Benchmark¶
- Prototype: Construct
views.view.ossa_agent_catalog.ymlsimulating the current Controller output. - Benchmark: Measure the rendering performance and batch operation limits.
Criteria¶
- Success Criteria: Full feature parity with the custom Controller UI; no custom PHP routing required for rendering the list.
- Failure Criteria: Investigation fails if:
- Custom Views Field plugins must be written to support basic execution links.
- Row-level access checks bypass the standard entity API.
Exit Conditions¶
Investigation is complete when: - [ ] Feature Matrix complete - [ ] Prototype complete - [ ] Benchmark complete - [ ] Remaining delta classified - [ ] CGR updated - [ ] Evidence receipt issued