Repository navigation
Security
Deeprotection implements a multi-layer security architecture that applies uniformly to every command.
Commands pass through without modification or blocking. No rules, plugins, or path protection are applied. Activity is logged to the audit file only for security-relevant events.
Commands are evaluated against your defined rules and any active plugins. Path protection is ignored. This is excellent for testing rule logic.
Strict security. Commands are evaluated against:
- Rules — regex-based blocking or replacement
- Plugins — external scripts for inspection and transformation
- Path protection — symlink-aware auditing of protected directories
Operations involving commands in the allowlist targeting protected directories require password authentication. Commands not in the allowlist are blocked immediately.
dpshell(1)# ls test/
[!] Protected path operation requires authorization.
Admin password:
The raw command string is matched against regex patterns before any parsing or expansion occurs. This catches dangerous patterns at the earliest stage.
After parsing, the command AST is evaluated against rules. Plugins are executed synchronously in discovery order. A plugin can:
- Allow (exit 0) — command proceeds
- Block (exit 1) — command is blocked
- Replace (exit 2) — stdout contains the new command string
The executor performs a post-expansion, symlink-aware audit of all file paths. If a command attempts to operate on a protected path:
- The command must be in the
allowlist - Password authentication is required (max 3 attempts)
In enforcing mode, when operating on protected paths with allowlisted commands, you are prompted for password authentication. The password is verified using SHA-256 against the hash stored in the configuration file.
Built-in protections include:
- Rate limiter: 64 forks/second
- Child limit: 256 processes
- Call depth limit: 128
dpshell strips dangerous environment variables from all child processes, including:
LD_PRELOADLD_LIBRARY_PATHPYTHONPATHIFS- And 7 others
All operations are logged in JSONL format to /var/log/audit.log. Each log entry includes:
- Timestamp (ISO 8601 UTC)
- Log level (INFO / WARN)
- Username
- Operation mode
- Original command
- Working directory
- Process ID
- Exit code
- Additional message