OpenFang Security Architecture
This document provides a comprehensive technical reference for every security system in the OpenFang Agent Operating System. All struct names, function signatures, constant values, and algorithm descriptions are drawn directly from the source code.
Table of Contents
- -Security Overview
- -Capability-Based Security
- -WASM Dual Metering
- -Merkle Hash Chain Audit Trail
- -Information Flow Taint Tracking
- -Ed25519 Manifest Signing
- -SSRF Protection
- -Secret Zeroization
- -OFP Mutual Authentication
- -Security Headers
- -GCRA Rate Limiter
- -Path Traversal Prevention
- -Subprocess Sandbox
- -Prompt Injection Scanner
- -Loop Guard
- -Session Repair
- -Health Endpoint Redaction
- -Security Configuration
- -Security Dependencies
1. Security Overview
OpenFang implements defense-in-depth security. No single mechanism is trusted to be the sole protector; instead, 16 independent systems form overlapping layers so that a failure in any one layer is caught by others.
| # | System | Crate | Protects Against |
|---|---|---|---|
| 1 | Capability-Based Security | openfang-types |
Unauthorized actions by agents |
| 2 | WASM Dual Metering | openfang-runtime |
Infinite loops, CPU DoS |
| 3 | Merkle Audit Trail | openfang-runtime |
Tampered audit logs |
| 4 | Taint Tracking | openfang-types |
Prompt injection, data exfiltration |
| 5 | Ed25519 Manifest Signing | openfang-types |
Supply chain attacks |
| 6 | SSRF Protection | openfang-runtime |
Server-Side Request Forgery |
| 7 | Secret Zeroization | openfang-runtime, openfang-channels |
Memory forensics, key leakage |
| 8 | OFP Mutual Auth | openfang-wire |
Unauthorized peer connections |
| 9 | Security Headers | openfang-api |
XSS, clickjacking, MIME sniffing |
| 10 | GCRA Rate Limiter | openfang-api |
API abuse, denial of service |
| 11 | Path Traversal Prevention | openfang-runtime |
Directory traversal attacks |
| 12 | Subprocess Sandbox | openfang-runtime |
Secret leakage via child processes |
| 13 | Prompt Injection Scanner | openfang-skills |
Malicious skill prompts |
| 14 | Loop Guard | openfang-runtime |
Stuck agent tool loops |
| 15 | Session Repair | openfang-runtime |
Corrupted LLM conversation history |
| 16 | Health Endpoint Redaction | openfang-api |
Information leakage |
2. Capability-Based Security
OpenFang uses capability-based security. An agent can only perform actions it has been explicitly granted permission to do. Capabilities are immutable after agent creation and are enforced at the kernel level.
2.1 Capability Variants
The Capability enum defines every permission type:
pub enum Capability {
// Filesystem
FileRead(String), // Glob pattern, e.g. "/data/*"
FileWrite(String),
// Network
NetConnect(String), // Host:port pattern, e.g. "*.openai.com:443"
NetListen(u16),
// Tools
ToolInvoke(String), // Specific tool ID
ToolAll, // All tools (dangerous)
// LLM
LlmQuery(String),
LlmMaxTokens(u64),
// Agent interaction
AgentSpawn,
AgentMessage(String),
AgentKill(String),
// Memory
MemoryRead(String),
MemoryWrite(String),
// Shell
ShellExec(String),
EnvRead(String),
// OFP Wire Protocol
OfpDiscover,
OfpConnect(String),
OfpAdvertise,
// Economic
EconSpend(f64),
EconEarn,
EconTransfer(String),
}
2.2 Pattern Matching
The capability_matches(granted, required) function implements glob-style matching:
- Exact match: `