OpenFang Security Architecture

This document provides a comprehensive technical reference for every security system in the OpenFang Agent Operating System. All struct names, function signatures, constant values, and algorithm descriptions are drawn directly from the source code.


Table of Contents

  1. -Security Overview
  2. -Capability-Based Security
  3. -WASM Dual Metering
  4. -Merkle Hash Chain Audit Trail
  5. -Information Flow Taint Tracking
  6. -Ed25519 Manifest Signing
  7. -SSRF Protection
  8. -Secret Zeroization
  9. -OFP Mutual Authentication
  10. -Security Headers
  11. -GCRA Rate Limiter
  12. -Path Traversal Prevention
  13. -Subprocess Sandbox
  14. -Prompt Injection Scanner
  15. -Loop Guard
  16. -Session Repair
  17. -Health Endpoint Redaction
  18. -Security Configuration
  19. -Security Dependencies

1. Security Overview

OpenFang implements defense-in-depth security. No single mechanism is trusted to be the sole protector; instead, 16 independent systems form overlapping layers so that a failure in any one layer is caught by others.

# System Crate Protects Against
1 Capability-Based Security openfang-types Unauthorized actions by agents
2 WASM Dual Metering openfang-runtime Infinite loops, CPU DoS
3 Merkle Audit Trail openfang-runtime Tampered audit logs
4 Taint Tracking openfang-types Prompt injection, data exfiltration
5 Ed25519 Manifest Signing openfang-types Supply chain attacks
6 SSRF Protection openfang-runtime Server-Side Request Forgery
7 Secret Zeroization openfang-runtime, openfang-channels Memory forensics, key leakage
8 OFP Mutual Auth openfang-wire Unauthorized peer connections
9 Security Headers openfang-api XSS, clickjacking, MIME sniffing
10 GCRA Rate Limiter openfang-api API abuse, denial of service
11 Path Traversal Prevention openfang-runtime Directory traversal attacks
12 Subprocess Sandbox openfang-runtime Secret leakage via child processes
13 Prompt Injection Scanner openfang-skills Malicious skill prompts
14 Loop Guard openfang-runtime Stuck agent tool loops
15 Session Repair openfang-runtime Corrupted LLM conversation history
16 Health Endpoint Redaction openfang-api Information leakage

2. Capability-Based Security

OpenFang uses capability-based security. An agent can only perform actions it has been explicitly granted permission to do. Capabilities are immutable after agent creation and are enforced at the kernel level.

2.1 Capability Variants

The Capability enum defines every permission type:

pub enum Capability {
    // Filesystem
    FileRead(String),       // Glob pattern, e.g. "/data/*"
    FileWrite(String),

// Network
    NetConnect(String),     // Host:port pattern, e.g. "*.openai.com:443"
    NetListen(u16),

// Tools
    ToolInvoke(String),     // Specific tool ID
    ToolAll,                // All tools (dangerous)

// LLM
    LlmQuery(String),
    LlmMaxTokens(u64),

// Agent interaction
    AgentSpawn,
    AgentMessage(String),
    AgentKill(String),

// Memory
    MemoryRead(String),
    MemoryWrite(String),

// Shell
    ShellExec(String),
    EnvRead(String),

// OFP Wire Protocol
    OfpDiscover,
    OfpConnect(String),
    OfpAdvertise,

// Economic
    EconSpend(f64),
    EconEarn,
    EconTransfer(String),
}

2.2 Pattern Matching

The capability_matches(granted, required) function implements glob-style matching:

  • Exact match: `