Skip to content
Geekstrange edited this page Aug 31, 2026 · 1 revision

General

What is Deeprotection?

Deeprotection is a secure shell wrapper (dpshell) written in Rust that provides command interception, rule-based matching, plugin extensibility, path protection, audit logging, and password authentication.

Is it production-ready?

Warning

dpshell is under active development with unstable features. It is NOT recommended to use it as the default login shell in production environments.

What are the three operation modes?

  • Disable — commands pass through without modification
  • Permissive — rules and plugins are evaluated, path protection is ignored
  • Enforcing — full security enforcement with path protection and authentication

Configuration

Where is the configuration file?

/etc/deeprotection/config.toml

How do I generate a password hash?

echo -n "your_password" | sha256sum

Can I reload configuration without restarting?

Yes. Set dynamic_config = true in the [core] section. The configuration is reloaded before each command prompt.

Security

What paths are protected?

Protected paths are defined in the [paths] section with the protect key. These are absolute directory prefixes.

What commands are allowed on protected paths?

Commands listed in the allowlist can operate on protected paths, but require password authentication in enforcing mode.

How does fork-bomb protection work?

Built-in protections include a rate limiter (64 forks/s), a child limit (256 processes), and a call depth limit (128).

Plugins

Where do I install plugins?

/etc/deeprotection/plugins/<plugin-name>/

What happens if a plugin times out?

Plugins have a 5-second timeout. If a plugin does not exit within this window, it is terminated with SIGKILL, and the original command is allowed (fail-open) with a warning.

Can plugins transform commands?

Yes. A plugin can exit with code 2 and output the new command string to stdout.

Interactive Features

How do I enable/disable syntax highlighting?

Toggle syntax_highlighting in the [features] section of the configuration file.

What completion modes are available?

  • Enhanced (default) — fuzzy matching powered by nucleo
  • Bash-style — traditional prefix-based completion

Toggle via enhance_completion.

Does dpshell support persistent history?

Yes. Set bash_compat = true to use ~/.bash_history. Otherwise, history is stored in /tmp and is not persistent across reboots.

Bash Compatibility

Does dpshell source ~/.bashrc?

Only when bash_compat = true is set in the configuration.

Does dpshell source /etc/profile or ~/.bash_profile?

No. dpshell does not source these files during login.