Repository navigation
Home
Geekstrange edited this page Aug 31, 2026
·
1 revision
Deeprotection is a high-performance, fully-featured shell environment (dpshell) written in Rust. It provides a hand-written recursive-descent parser, a direct fork/execve executor (no /bin/sh wrapper), POSIX-compatible control structures, 50+ built-in commands, job control, and rich interactive features.
On top of this shell core, it layers:
- Rule-based command matching — block or replace commands via regex patterns
- Plugin extensibility — external scripts that can inspect and transform commands
- Path protection — symlink-aware auditing of operations on protected directories
- JSONL audit logging — every command logged with timestamp, user, and context
- SHA-256 password authentication — required for protected-path operations in enforcing mode
| Page | Description |
|---|---|
| User Guide | Getting started, basic usage, interactive features |
| Configuration | TOML configuration reference, rules, modes |
| Security | Protection modes, path protection, authentication |
| Plugin Development | Writing and deploying plugins |
| Architecture | Deep dive into the codebase design |
| Built-in Commands | Complete list of 50+ builtins |
| FAQ | Frequently asked questions |
| Contributing | Development setup and guidelines |
Deeprotection operates in one of three modes:
| Mode | Behavior |
|---|---|
| Disable | Commands pass through without modification. No rules, plugins, or path protection are applied. |
| Permissive | Rules and plugins are evaluated. Path protection is ignored. Ideal for testing rule logic. |
| Enforcing | Full security enforcement. Rules → plugins → path protection → password authentication. |
Warning
dpshell is under active development with unstable features. It is NOT recommended to use it as the default login shell in production environments.
Caution
Security restrictions such as fork bomb prevention cannot provide full protection. Do not execute untrusted scripts or unknown commands in risky environments.
1.