Skip to content

Delta Discovery Plan: OSSA Capabilities

Engineering Rule: Every investigation must be falsifiable. An investigation is successful when it conclusively determines whether a capability can be satisfied by an existing authority or whether a measurable remaining delta exists. The goal is accurate classification (NONE, CONFIG, EXTENSION, PACKAGE, PRODUCT), not the elimination of custom code.


1. Discovery Transport

Current Evidence

  • Evidence Sources: Existing Implementation, CGR (cgr-001-ossa), Drupal documentation.
  • Confidence: LOW
  • Known Unknowns:
    • JSON:API feature parity with OSSA .well-known schemas.
    • Number of custom Normalizers required.
    • Caching behavior of dynamic transport layers.

Incremental Delta Discovery

  • Confirmed: Async Task Execution → NONE (Core Queue/ECA)
  • Tentative: Registry Queries → CONFIG (Views)
  • Unknown: Discovery Transport (.well-known endpoints)

Experiment

Can JSON:API natively express the required OSSA .well-known schema formats securely and performantly?

Prototype & Benchmark

  • Prototype: Build one minimal JSON:API endpoint exposing a single OSSA entity type.
  • Benchmark: Measure query latency, cache invalidation reliability, and JSON payload size against the custom REST controller baseline.

Criteria

  • Success Criteria: 100% compliance with OSSA discovery schema; core cacheability maintained.
  • Failure Criteria: Investigation fails if:
    • More than one custom Normalizer is required.
    • Core caching cannot be preserved for public payloads.
    • Required metadata cannot be accurately mapped to the spec.

Exit Conditions

Investigation is complete when: - [ ] Feature Matrix complete - [ ] Prototype complete - [ ] Benchmark complete - [ ] Remaining delta classified - [ ] CGR updated - [ ] Evidence receipt issued


2. Manifest Validation

Current Evidence

  • Evidence Sources: Existing Implementation (PhpManifestValidator.php), NPM @blueflyio/openstandardagents source.
  • Confidence: LOW
  • Known Unknowns:
    • Latency of invoking Node locally from PHP.
    • Authentication model for a remote validator microservice.
    • Feasibility of pure CI/CD validation.

Incremental Delta Discovery

  • Unknown: Operational Boundary for NPM execution.

Experiment

What is the lowest-latency, highest-security method for the Drupal runtime to invoke the canonical NPM validation logic without rewriting the mathematical schema in PHP?

Prototype & Benchmark

  • Prototype: Build three invocation proofs: Local Node child-process, Remote A2A Service, Offline CI/CD pipeline.
  • Benchmark: Measure blocking latency for local and remote executions, and measure the integration complexity of offline validation.

Criteria

  • Success Criteria: ≤100ms local/remote validation; zero schema divergence; single specification authority maintained.
  • Failure Criteria: Investigation fails if:
    • Local execution blocks PHP threads for >500ms.
    • Remote service requires introducing a complex new secrets broker.
    • Offline validation prevents dynamic agent onboarding via the UI.

Exit Conditions

Investigation is complete when: - [ ] Feature Matrix complete - [ ] Prototype complete - [ ] Benchmark complete - [ ] Remaining delta classified - [ ] CGR updated - [ ] Evidence receipt issued


3. Registry UI (Catalog)

Current Evidence

  • Evidence Sources: Existing Implementation (AgentPluginListController.php), Core Views documentation.
  • Confidence: MEDIUM
  • Known Unknowns:
    • Capacity of Views to support arbitrary inline execution links (e.g., Quick Launch).

Incremental Delta Discovery

  • Unknown: Administrative UI Capabilities.

Experiment

Can Drupal Views support all required administrative behaviors (inline validation, quick-launch execution) without falling back to custom routing controllers?

Prototype & Benchmark

  • Prototype: Construct views.view.ossa_agent_catalog.yml simulating the current Controller output.
  • Benchmark: Measure the rendering performance and batch operation limits.

Criteria

  • Success Criteria: Full feature parity with the custom Controller UI; no custom PHP routing required for rendering the list.
  • Failure Criteria: Investigation fails if:
    • Custom Views Field plugins must be written to support basic execution links.
    • Row-level access checks bypass the standard entity API.

Exit Conditions

Investigation is complete when: - [ ] Feature Matrix complete - [ ] Prototype complete - [ ] Benchmark complete - [ ] Remaining delta classified - [ ] CGR updated - [ ] Evidence receipt issued