Repository navigation
FAQ
Deeprotection is a secure shell wrapper (dpshell) written in Rust that provides command interception, rule-based matching, plugin extensibility, path protection, audit logging, and password authentication.
Warning
dpshell is under active development with unstable features. It is NOT recommended to use it as the default login shell in production environments.
- Disable — commands pass through without modification
- Permissive — rules and plugins are evaluated, path protection is ignored
- Enforcing — full security enforcement with path protection and authentication
/etc/deeprotection/config.toml
echo -n "your_password" | sha256sumYes. Set dynamic_config = true in the [core] section. The configuration is reloaded before each command prompt.
Protected paths are defined in the [paths] section with the protect key. These are absolute directory prefixes.
Commands listed in the allowlist can operate on protected paths, but require password authentication in enforcing mode.
Built-in protections include a rate limiter (64 forks/s), a child limit (256 processes), and a call depth limit (128).
/etc/deeprotection/plugins/<plugin-name>/
Plugins have a 5-second timeout. If a plugin does not exit within this window, it is terminated with SIGKILL, and the original command is allowed (fail-open) with a warning.
Yes. A plugin can exit with code 2 and output the new command string to stdout.
Toggle syntax_highlighting in the [features] section of the configuration file.
-
Enhanced (default) — fuzzy matching powered by
nucleo - Bash-style — traditional prefix-based completion
Toggle via enhance_completion.
Yes. Set bash_compat = true to use ~/.bash_history. Otherwise, history is stored in /tmp and is not persistent across reboots.
Only when bash_compat = true is set in the configuration.
No. dpshell does not source these files during login.