Skip to content

v2.0.0 (Harrier)

Choose a tag to compare

@Geekstrange Geekstrange released this 28 Apr 06:16
· 9 commits to main since this release
v2.0.0

🚀 Full refactor of the Deeprotection Shell,
introducing a plugin system, TOML configuration, job control, enhanced path protection, and three runtime operation modes.


🧬 New Architecture

  • Code restructured into seven well-defined modules:
    cmd, config, executor, logger, plugins, protection, rules, utils
  • Modern error handling powered by anyhow + thiserror
  • Unified management of command completion, syntax highlighting, and command history via rustyline

🔌 Plugin System

  • Load plugins from /etc/deeprotection/plugins/
  • Each plugin is declared through plugin.json, receiving commands via standard input and environment variables with a 5‑second timeout
  • Plugins are able to allow, block, or rewrite executed commands
  • The plugin directory is automatically added to $PATH, enabling direct invocation of plugin-provided binaries (e.g. enls)

⚙️ TOML-Based Configuration

  • New primary config path: /etc/deeprotection/config.toml
  • Clearly segmented sections: [core], [auth], [paths], and repeated [[rules]] blocks
  • Automatic parsing and adaptation for regex rules (prefixed with re:) and plain-text matching rules
  • Fine-grained path protection: whitelisted commands + optional administrator password verification

🛡️ Three Runtime Modes

Mode Behavior
disable Execute commands directly; only record audit logs
permissive Apply rules and plugins; bypass strict path protection
enforcing Full security enforcement: rules → plugins → path protection; admin password required for restricted operations

🧵 Process & Signal Management

  • Proper Ctrl+Z handling: child processes run in independent process groups with correct terminal handoff, preventing shell freezing
  • Ctrl+C interrupts only the active child command and will not terminate the shell
  • exit command requires administrator password authentication under enforcing mode

📜 Logging & Auditing

  • Structured JSON Lines audit logs output to /var/log/audit.log
  • Each entry includes timestamp, user context, runtime mode, raw command, working directory, PID and more
  • Thread-safe log writer with manual flush support

🧭 Other Improvements

  • Retained and enhanced interactive directory navigation: cd ? and recursive cd ??
  • Safe default flags -i -v automatically applied to rm (overridable via custom rules)
  • All built-in security behaviors are rule/plugin-driven with no hardcoded command interception
  • Startup banner color varies by mode: green for permissive, red for enforcing

💥 Breaking Changes

  • Configuration migrated from legacy key=value format to TOML; legacy configs require manual migration
  • Removed i18n multi-language support; all terminal messages standardized to English for easier maintenance
  • /etc/deeprotection/plugins/ is now a required directory (must exist, even if empty)
  • Log file path changed to /var/log/audit.log; legacy log path /var/log/deeprotection.log is no longer written