Repository navigation
Configuration
Geekstrange edited this page Aug 31, 2026
·
1 revision
Deeprotection uses a clean, minimalist TOML configuration file located at /etc/deeprotection/config.toml.
[core]
# Operating mode: "disable", "permissive", or "enforcing"
mode = "enforcing"
# Enable Bash compatibility: sources ~/.bashrc, uses ~/.bash_history
bash_compat = false
# Enable live config reloading (checks file content before each prompt)
dynamic_config = true[auth]
# SHA-256 hex digest of admin password
# Generate with: echo -n "pass" | sha256sum
password_hash = "31fc7f00f4a0f72653d3ba5f445b8c21d922ae786da3f0a3a780f573942d00aa"[paths]
# Directories that are strictly protected against modification commands
protect = ["/root/test", "/root/.ssh"]
# Commands allowed to operate on protected paths (requires authentication)
allowlist = ["rm", "rmdir", "mv", "cp", "chmod", "chown", "touch", "cat", "ls"][features]
syntax_highlighting = true # Colour-code commands, builtins, strings, operators
auto_suggest = true # Grey ghost-text suggestions from history
enhance_completion = true # Fuzzy (nucleo) completion; false = bash-style prefixRules define command matching and actions. They are evaluated in order.
[[rules]]
name = "block_rm_rf"
pattern = "rm -rf"
action = { block = true }
enabled = true
[[rules]]
name = "block_fork_bomb"
pattern = "re:^\\s*:\\(\\)\\s*\\{.*\\|.*&.*\\}.*;"
action = { block = true }
enabled = true
[[rules]]
name = "replace_echo"
pattern = "re:^echo 111$"
action = { replace = "echo 222" }
enabled = true| Type | Description | Example |
|---|---|---|
| Plain string | Automatically anchored with flexible whitespace |
"rm -rf" → ^\s*rm\s+-rf\s*$
|
| Explicit regex | Prefixed with re:
|
"re:^echo 111$" |
| Command name | Prefixed with cmd:
|
"cmd:rm" |
| Argument regex | Prefixed with arg:
|
"arg:\.\." |
| Action | Description |
|---|---|
block = true |
Block the command and log the action |
replace = "new command" |
Replace the command with the specified string |
When dynamic_config = true, dpshell reads the configuration file before processing each command. If the file content has changed, it reloads all settings: mode, rules, paths, allowlist, password hash, and feature flags. A dpshell: config reloaded message is printed to stderr on successful reload.