Skip to content

Configuration

Geekstrange edited this page Aug 31, 2026 · 1 revision

Deeprotection uses a clean, minimalist TOML configuration file located at /etc/deeprotection/config.toml.

Core Settings

[core]
# Operating mode: "disable", "permissive", or "enforcing"
mode = "enforcing"

# Enable Bash compatibility: sources ~/.bashrc, uses ~/.bash_history
bash_compat = false

# Enable live config reloading (checks file content before each prompt)
dynamic_config = true

Authentication

[auth]
# SHA-256 hex digest of admin password
# Generate with: echo -n "pass" | sha256sum
password_hash = "31fc7f00f4a0f72653d3ba5f445b8c21d922ae786da3f0a3a780f573942d00aa"

Path Protection

[paths]
# Directories that are strictly protected against modification commands
protect = ["/root/test", "/root/.ssh"]

# Commands allowed to operate on protected paths (requires authentication)
allowlist = ["rm", "rmdir", "mv", "cp", "chmod", "chown", "touch", "cat", "ls"]

Feature Toggles

[features]
syntax_highlighting = true    # Colour-code commands, builtins, strings, operators
auto_suggest        = true    # Grey ghost-text suggestions from history
enhance_completion  = true    # Fuzzy (nucleo) completion; false = bash-style prefix

Rules

Rules define command matching and actions. They are evaluated in order.

[[rules]]
name = "block_rm_rf"
pattern = "rm -rf"
action = { block = true }
enabled = true

[[rules]]
name = "block_fork_bomb"
pattern = "re:^\\s*:\\(\\)\\s*\\{.*\\|.*&.*\\}.*;"
action = { block = true }
enabled = true

[[rules]]
name = "replace_echo"
pattern = "re:^echo 111$"
action = { replace = "echo 222" }
enabled = true

Rule Pattern Types

Type Description Example
Plain string Automatically anchored with flexible whitespace "rm -rf" → ^\s*rm\s+-rf\s*$
Explicit regex Prefixed with re: "re:^echo 111$"
Command name Prefixed with cmd: "cmd:rm"
Argument regex Prefixed with arg: "arg:\.\."

Rule Actions

Action Description
block = true Block the command and log the action
replace = "new command" Replace the command with the specified string

Dynamic Config Reload

When dynamic_config = true, dpshell reads the configuration file before processing each command. If the file content has changed, it reloads all settings: mode, rules, paths, allowlist, password hash, and feature flags. A dpshell: config reloaded message is printed to stderr on successful reload.

Clone this wiki locally