Skip to content

Security

Geekstrange edited this page Aug 31, 2026 · 1 revision

Deeprotection implements a multi-layer security architecture that applies uniformly to every command.

Protection Modes

Disable Mode

Commands pass through without modification or blocking. No rules, plugins, or path protection are applied. Activity is logged to the audit file only for security-relevant events.

Permissive Mode

Commands are evaluated against your defined rules and any active plugins. Path protection is ignored. This is excellent for testing rule logic.

Enforcing Mode

Strict security. Commands are evaluated against:

  1. Rules — regex-based blocking or replacement
  2. Plugins — external scripts for inspection and transformation
  3. Path protection — symlink-aware auditing of protected directories

Operations involving commands in the allowlist targeting protected directories require password authentication. Commands not in the allowlist are blocked immediately.

dpshell(1)# ls test/
[!] Protected path operation requires authorization.
Admin password:

Three-Layer Security Pipeline

Layer 1: Raw Input Rules

The raw command string is matched against regex patterns before any parsing or expansion occurs. This catches dangerous patterns at the earliest stage.

Layer 2: AST Rules & Plugins

After parsing, the command AST is evaluated against rules. Plugins are executed synchronously in discovery order. A plugin can:

  • Allow (exit 0) — command proceeds
  • Block (exit 1) — command is blocked
  • Replace (exit 2) — stdout contains the new command string

Layer 3: Path Protection (Enforcing Mode)

The executor performs a post-expansion, symlink-aware audit of all file paths. If a command attempts to operate on a protected path:

  1. The command must be in the allowlist
  2. Password authentication is required (max 3 attempts)

Password Authentication

In enforcing mode, when operating on protected paths with allowlisted commands, you are prompted for password authentication. The password is verified using SHA-256 against the hash stored in the configuration file.

Fork-Bomb Protection

Built-in protections include:

  • Rate limiter: 64 forks/second
  • Child limit: 256 processes
  • Call depth limit: 128

Environment Sanitization

dpshell strips dangerous environment variables from all child processes, including:

  • LD_PRELOAD
  • LD_LIBRARY_PATH
  • PYTHONPATH
  • IFS
  • And 7 others

Audit Logging

All operations are logged in JSONL format to /var/log/audit.log. Each log entry includes:

  • Timestamp (ISO 8601 UTC)
  • Log level (INFO / WARN)
  • Username
  • Operation mode
  • Original command
  • Working directory
  • Process ID
  • Exit code
  • Additional message

Clone this wiki locally