From d4c741926d91f625d91bd32d757b56214b939ab0 Mon Sep 17 00:00:00 2001 From: MythEclipse Date: Fri, 25 Sep 2026 15:36:09 +0800 Subject: [PATCH] fix: make challenge toggle actually work end-to-end (5 root-cause bugs) Found by testing a real enable/disable cycle (art, fjb, gift-card): 1. compose_gen always swapped build->image, so a never-built challenge produced 'pull access denied for services-'. Now it only reuses the image when it exists locally, otherwise keeps build: so 'docker compose up --build' builds it. 2. Canonical templates use 'build: context: .' (written for the shared services/ tree). In the per-team compose that resolves to the team dir which has no Dockerfile -> 'failed to read dockerfile'. The renderer now rewrites the main service's context to ./. 3. Teams created before the XVI/XVII import had no xvi/xvii subpackages under their local challenges/ dir, so the regenerated receiver main.py crash-looped on import. gen_receiver_main now mirrors ALL shared checkers (native + xvi + xvii) into every team receiver on each sync. 4. systemd Environment= keys can't contain hyphens, so CHALLENGE_PORT_GIFT-CARD was silently dropped. Keys are now normalized to underscores on both the writer and reader side. 5. Several checkers called 'docker exec' with no timeout; against a container with accumulated chall.py zombies that blocks forever and stalls the whole SLA loop. Added mandatory timeouts (Phew, Sheesh, Carbeat, Poke, Warmup). Also: enabling a challenge now copies its source tree into each team's services/ dir (team dirs only held challenges enabled at create_team time), and the XVII checkers were rewritten to be protocol-aware (gift-card/gift-voucher are socat TCP, not HTTP) with strict timeouts. --- panel/compose_gen.py | 34 +++++- panel/gen_receiver_main.py | 43 ++++++- panel/gen_receiver_services.py | 10 +- panel/teams.py | 14 +++ receiver/challenges/Carbeat.py | 3 +- receiver/challenges/Phew.py | 10 +- receiver/challenges/Poke.py | 3 +- receiver/challenges/Sheesh.py | 3 +- receiver/challenges/Warmup.py | 2 +- receiver/challenges/xvii/checkers.py | 160 ++++++++++++--------------- 10 files changed, 176 insertions(+), 106 deletions(-) diff --git a/panel/compose_gen.py b/panel/compose_gen.py index 1ed1594..fb5d8e1 100644 --- a/panel/compose_gen.py +++ b/panel/compose_gen.py @@ -18,6 +18,7 @@ anti-alchemy, tempest-poc) keep their sidecar services. """ import json import re +import subprocess from pathlib import Path BASE = Path("/opt/gemastik18-final") @@ -47,6 +48,18 @@ def read_template(name: str) -> str: raise FileNotFoundError(f"Tidak ada template compose untuk {name} di {p}") return p.read_text() +def _image_exists(image_name: str) -> bool: + """True if the docker image is already present locally. + + The renderer only swaps a service's `build:` block for `image: services-` + when that image actually exists. Otherwise compose would try to PULL a local + build artifact and fail with "pull access denied for services-". + """ + r = subprocess.run(["docker", "image", "inspect", image_name], + capture_output=True, text=True, timeout=30) + return r.returncode == 0 + + def _parse_services(text: str): names = [] for line in text.splitlines(): @@ -93,10 +106,12 @@ def render_team_compose(idx: int, state: dict) -> str: text = re.sub(rf'"({org}):', f'"{tc}:', text) text = re.sub(rf'"({org + 22}):', f'"{ts}:', text) - # --- build: -> image for MAIN only --- - # Replace the main service's build block with image: services-. - # NB we process by service names, not generic removal, so sidecar - # builds survive. + # --- build: -> image for MAIN only (only when the image exists) --- + # Replace the main service's build block with image: services- so + # teams share one image. If that image was never built, KEEP the build + # block so `docker compose up --build` builds it instead of trying to + # pull a nonexistent local image. + use_image = _image_exists(f"services-{name}") lines = text.splitlines() i = 0 in_main = False @@ -112,7 +127,7 @@ def render_team_compose(idx: int, state: dict) -> str: i += 1 continue # inside a service block - if in_main and line.strip() == "build:": + if in_main and use_image and line.strip() == "build:": # skip build block (context/args/dockerfile...) until next key at same indent out.append(f" image: services-{name}") i += 1 @@ -127,6 +142,15 @@ def render_team_compose(idx: int, state: dict) -> str: text = re.sub(r"\$PASSWORD_" + str(org) + r"\b", passwords[name], text) text = re.sub(r"PASSWORD_" + str(org) + r"\b", passwords[name], text) + # --- build context -> per-team challenge subdir --- + # Canonical templates are written for the SHARED services/ tree where a + # challenge's files sit in services//. The per-team compose lives in + # teamN/services/, so a bare `context: .` would resolve to the team dir + # (no Dockerfile). Point the MAIN service's build at ./. + if re.search(r"^ build:$", text, re.M): + text = re.sub(r"^ build:\n context: \.$", + f" build:\n context: ./{name}", text, count=1, flags=re.M) + # --- flag volume normalization --- # Replace any ./flag.txt / ../receiver/flags/.txt with the per-team flag mount text = re.sub(r"\./flag\.txt(:\w+)?", f"../receiver/flags/{name}.txt", text) diff --git a/panel/gen_receiver_main.py b/panel/gen_receiver_main.py index d1bf5f4..28a28e6 100644 --- a/panel/gen_receiver_main.py +++ b/panel/gen_receiver_main.py @@ -11,6 +11,7 @@ from three packages: from __future__ import annotations import json +import shutil from pathlib import Path from teams import TEAMS_DIR, load_registry @@ -98,26 +99,33 @@ app = FastAPI() security = HTTPBasic() settings = get_settings() +def _envkey(name: str) -> str: + # systemd Environment= keys can't contain hyphens; gen_receiver_services + # writes CHALLENGE_PORT_GIFT_CARD for the challenge "gift-card". + return name.upper().replace("-", "_") + def _ch_port(name: str, default: int) -> int: # read from .env manually (pydantic settings has fixed fields) - val = os.environ.get(f"CHALLENGE_PORT_{{name.upper()}}") + key = _envkey(name) + val = os.environ.get(f"CHALLENGE_PORT_{{key}}") if not val: try: with open(os.path.join(os.path.dirname(__file__), ".env")) as f: for line in f: - if line.startswith(f"CHALLENGE_PORT_{{name.upper()}}="): + if line.startswith(f"CHALLENGE_PORT_{{key}}="): val = line.strip().split("=", 1)[1] except Exception: pass return int(val) if val else default def _ch_container(name: str, default: str) -> str: - val = os.environ.get(f"CHALLENGE_CONTAINER_{{name.upper()}}") + key = _envkey(name) + val = os.environ.get(f"CHALLENGE_CONTAINER_{{key}}") if not val: try: with open(os.path.join(os.path.dirname(__file__), ".env")) as f: for line in f: - if line.startswith(f"CHALLENGE_CONTAINER_{{name.upper()}}="): + if line.startswith(f"CHALLENGE_CONTAINER_{{key}}="): val = line.strip().split("=", 1)[1] except Exception: pass @@ -253,6 +261,32 @@ def validate(credentials, challenge): """ +def _sync_checker_packages(recv_dir) -> None: + """Mirror the shared receiver's challenge checkers into a team receiver. + + Two reasons this must run on every sync, not just at create_team time: + 1. Teams created before the XVI/XVII import have no xvi/xvii subpackages, + so a regenerated main.py that imports them would crash-loop the receiver. + 2. Native checkers (Blogpost/Phew/...) get bug fixes (e.g. mandatory + subprocess timeouts); a team copy made earlier keeps the stale version. + """ + shared_challenges = Path("/opt/gemastik18-final/receiver/challenges") + dst_root = recv_dir / "challenges" + dst_root.mkdir(parents=True, exist_ok=True) + for src_file in sorted(shared_challenges.glob("*.py")): + if src_file.name == "__init__.py": + continue + shutil.copy2(src_file, dst_root / src_file.name) + for pkg in ("xvi", "xvii"): + src = shared_challenges / pkg + if not src.exists(): + continue + dst = dst_root / pkg + if dst.exists(): + shutil.rmtree(dst) + shutil.copytree(src, dst, ignore=shutil.ignore_patterns("__pycache__", "*.pyc")) + + def sync_team_receivers() -> None: """Regenerate main.py for every existing team from its state + registry.""" for d in sorted(TEAMS_DIR.glob("team*")): @@ -262,6 +296,7 @@ def sync_team_receivers() -> None: st = json.loads(sf.read_text()) idx = st["index"] enabled = [c for c in load_registry()["challenges"] if c.get("enabled")] + _sync_checker_packages(d / "receiver") text = render_receiver_main(enabled, {c["name"]: st["ports"][c["name"]]["chall"] for c in enabled}) (d / "receiver" / "main.py").write_text(text) print(f"team{idx}: receiver main.py regenerated ({len(enabled)} challenges)") diff --git a/panel/gen_receiver_services.py b/panel/gen_receiver_services.py index 59f4e22..a006aaf 100644 --- a/panel/gen_receiver_services.py +++ b/panel/gen_receiver_services.py @@ -19,12 +19,16 @@ def write_unit(idx: int, st: dict): port = st["ports"]["receiver"] recv_dir = TEAMS_DIR / f"team{idx}" / "receiver" env = {} - # ports/containers for challenge classes + # ports/containers for challenge classes. + # NOTE: systemd Environment= keys must be [A-Za-z0-9_]+ — a hyphen in the + # challenge name (gift-card) would make systemd silently drop the line, so + # normalize the name to underscores here. main.py looks up the same key. for ch in st["ports"]: if ch in ("receiver", "panel"): continue - env[f"CHALLENGE_PORT_{ch.upper()}"] = str(st["ports"][ch]["chall"]) - env[f"CHALLENGE_CONTAINER_{ch.upper()}"] = f"{ch}_container_team{idx}" + key = ch.upper().replace("-", "_") + env[f"CHALLENGE_PORT_{key}"] = str(st["ports"][ch]["chall"]) + env[f"CHALLENGE_CONTAINER_{key}"] = f"{ch}_container_team{idx}" # SSH passwords: checker Challenge.credentials() reads PASSWORD_ # where self.port is the team challenge port. pwd = st.get("chall_passwords", {}).get(ch) diff --git a/panel/teams.py b/panel/teams.py index 5740c6c..4a12402 100644 --- a/panel/teams.py +++ b/panel/teams.py @@ -116,6 +116,20 @@ def sync_challenge_runtime(name: str, enabled: bool) -> dict: name) or f"chall{idx}_{name}_{secrets.token_hex(4)}" # write state BEFORE rendering (render needs ports[name]) (sf).write_text(json.dumps(st, indent=2)) + # Copy the challenge source into the team's services tree so a + # `build: context: .` resolves (team dirs only hold challenges + # that were enabled at create_team time). + team_svc_src = svc_dir / name + if not team_svc_src.exists(): + src = SERVICES_SRC / name + if not src.exists(): + raise FileNotFoundError(f"sumber service tidak ada: {src}") + shutil.copytree(src, team_svc_src, + ignore=shutil.ignore_patterns("__pycache__", "*.pyc", ".git")) + # apt-insecure.conf is needed by every challenge build + shared_apt = SERVICES_SRC / "apt-insecure.conf" + if shared_apt.exists() and not (team_svc_src / "apt-insecure.conf").exists(): + shutil.copy2(shared_apt, team_svc_src / "apt-insecure.conf") # regenerate whole compose (so enabled challenge included), # then bring up just this service new_text = compose_gen.render_team_compose(idx, st) diff --git a/receiver/challenges/Carbeat.py b/receiver/challenges/Carbeat.py index fe8685d..5f39d8b 100644 --- a/receiver/challenges/Carbeat.py +++ b/receiver/challenges/Carbeat.py @@ -26,8 +26,9 @@ class Carbeat(Challenge): def _read_container_flag(self) -> str: + # timeout is mandatory: docker exec can block forever on a saturated container out = subprocess.run(["docker", "exec", self._CONTAINER, "cat", "/flag.txt"], - capture_output=True, text=True) + capture_output=True, text=True, timeout=30) if out.returncode != 0 or not out.stdout.strip(): raise FileNotFoundError("Flag not found in container (/flag.txt)") return out.stdout.strip() diff --git a/receiver/challenges/Phew.py b/receiver/challenges/Phew.py index 444d036..d4f9e7b 100644 --- a/receiver/challenges/Phew.py +++ b/receiver/challenges/Phew.py @@ -14,8 +14,14 @@ class Phew(Challenge): _HEX_RE = re.compile(r'^[0-9a-fA-F]+$') def _read_container_flag(self) -> str: - out = subprocess.run(["docker", "exec", self._CONTAINER, "cat", "/flag.txt"], - capture_output=True, text=True) + # NB: a timeout is mandatory here. `docker exec` against a container + # whose process table is saturated (accumulated chall.py zombies) can + # block forever and take the whole SLA check loop down with it. + try: + out = subprocess.run(["docker", "exec", self._CONTAINER, "cat", "/flag.txt"], + capture_output=True, text=True, timeout=30) + except subprocess.TimeoutExpired: + raise TimeoutError("docker exec cat /flag.txt timed out (container overloaded?)") if out.returncode != 0 or not out.stdout.strip(): raise FileNotFoundError("Flag not found in container (/flag.txt)") return out.stdout.strip() diff --git a/receiver/challenges/Poke.py b/receiver/challenges/Poke.py index ab9a699..077d686 100644 --- a/receiver/challenges/Poke.py +++ b/receiver/challenges/Poke.py @@ -52,7 +52,8 @@ class Poke(Challenge): container_flag = subprocess.run( ["docker", "exec", "poke_container", "cat", "/flag.txt"], capture_output=True, - text=True + text=True, + timeout=30 ).stdout.strip() assert host_flag == container_flag, 'Flag mismatch between host and container' diff --git a/receiver/challenges/Sheesh.py b/receiver/challenges/Sheesh.py index 37ccdb2..4f1e920 100644 --- a/receiver/challenges/Sheesh.py +++ b/receiver/challenges/Sheesh.py @@ -15,9 +15,10 @@ class Sheesh(Challenge): _HEX_RE = re.compile(r'^[0-9a-fA-F]+$') def _read_container_flag(self) -> str: + # timeout is mandatory: docker exec can block forever on a saturated container out = subprocess.run( ["docker", "exec", self._CONTAINER, "cat", "/flag.txt"], - capture_output=True, text=True + capture_output=True, text=True, timeout=30 ) if out.returncode != 0 or not out.stdout.strip(): raise FileNotFoundError("Flag not found in container (/flag.txt)") diff --git a/receiver/challenges/Warmup.py b/receiver/challenges/Warmup.py index 33bf3b9..43ef6aa 100644 --- a/receiver/challenges/Warmup.py +++ b/receiver/challenges/Warmup.py @@ -32,7 +32,7 @@ class Warmup(Challenge): host_flag = f.read().strip() container_flag = subprocess.run([ "docker", "exec", os.environ.get("CHALLENGE_CONTAINER_WARMUP", "warmup_container"), "cat", "/flag.txt" - ], capture_output=True, text=True).stdout.strip() + ], capture_output=True, text=True, timeout=30).stdout.strip() assert host_flag == container_flag, 'Flag mismatch between host and container' self.logger.info('Check passed for warmup') diff --git a/receiver/challenges/xvii/checkers.py b/receiver/challenges/xvii/checkers.py index 540ad73..06f652b 100644 --- a/receiver/challenges/xvii/checkers.py +++ b/receiver/challenges/xvii/checkers.py @@ -1,10 +1,17 @@ """SLA checkers for GEMASTIK XVII challenges (imported from github.com/vidner/gemastik-xvii-final — no upstream receiver was provided). -Each checker validates liveness + flag presence in the container. Protocols: - - TCP/netcat : asmr, bit-canvas, go-green (xinetd banner) & ticketer (socat) - - HTTP GET : anti-alchemy, fjb, gift-card, gift-voucher, gleam-drive, - kode-viewer, more-less, tempest-poc +Each checker validates liveness (+ flag presence where the flag is a file) with +STRICT timeouts so a wedged service can never hang the receiver's check loop. + +Protocol classes: + - WEB : HTTP GET on the challenge port + - TCP : socat/xinetd line service — connect and expect a prompt/banner + - WEB+FLAG: WEB plus the flag must be mounted inside the container + +Env-var convention: systemd Environment= keys are normalized to underscores +(CHALLENGE_PORT_GIFT_CARD for the challenge "gift-card"), so the lookup helper +does the same normalization. """ import os import socket @@ -15,6 +22,16 @@ import requests from .Challenge import Challenge +def _key(name: str) -> str: + return name.upper().replace("-", "_") + + +def _container(challenge: str) -> str: + return os.environ.get( + f"CHALLENGE_CONTAINER_{_key(challenge)}", f"{challenge}_container" + ) + + def _docker_exec(container: str, *args, timeout: int = 10): try: return subprocess.run(["docker", "exec", container, *args], @@ -24,35 +41,54 @@ def _docker_exec(container: str, *args, timeout: int = 10): def _flag_in_container(container: str, path: str = "/flag.txt") -> bool: - r = _docker_exec(container, "sh", "-c", f"test -f {path} && cat {path} || echo MISSING") - return bool(r and "MISSING" not in (r.stdout or "") and r.returncode == 0) + r = _docker_exec(container, "sh", "-c", f"test -s {path} && echo FLAG_OK || echo MISSING") + return bool(r and "FLAG_OK" in (r.stdout or "")) -def _tcp_banner(port: int, timeout: float = 4.0, expect: bytes = None) -> bool: +def _web_alive(port: int, timeout: float = 5.0) -> bool: + """Any HTTP response (even 4xx/5xx) proves the listener is up.""" try: - s = socket.create_connection(("127.0.0.1", port), timeout=timeout) - s.settimeout(timeout) - data = s.recv(256) - s.close() - if expect: - return expect.lower() in data.lower() - return len(data) > 0 + r = requests.get(f"http://127.0.0.1:{port}/", timeout=timeout, allow_redirects=False) + return r.status_code < 600 + except requests.exceptions.RequestException: + return False except Exception: return False +def _tcp_alive(port: int, timeout: float = 5.0, send: bytes = None) -> bool: + """Connect to a line service and read a prompt/banner (or survive silence). + + Some socat services wait for input before greeting, so a successful connect + with no data is also treated as alive; a refused connection is not. + """ + try: + s = socket.create_connection(("127.0.0.1", port), timeout=timeout) + except Exception: + return False + try: + s.settimeout(timeout) + if send: + s.sendall(send) + try: + data = s.recv(256) + except socket.timeout: + # connected but silent — service is accepting connections + return True + return True if data is not None else True + finally: + try: + s.close() + except Exception: + pass + + class AntiAlchemy(Challenge): flag_location = "flags/anti-alchemy.txt" history_location = "history/anti-alchemy.txt" def check(self): - try: - url = f"http://localhost:{self.port}/" - r = requests.get(url, timeout=6) - assert r.status_code in (200, 302, 500) or len(r.text) > 0 - return _flag_in_container(os.environ.get("CHALLENGE_CONTAINER_ANTI_ALCHEMY", "anti-alchemy_container")) - except Exception: - return False + return _web_alive(self.port) and _flag_in_container(_container("anti-alchemy")) class Asmr(Challenge): @@ -60,10 +96,7 @@ class Asmr(Challenge): history_location = "history/asmr.txt" def check(self): - try: - return _tcp_banner(self.port, expect=None) - except Exception: - return False + return _tcp_alive(self.port) class BitCanvas(Challenge): @@ -71,10 +104,7 @@ class BitCanvas(Challenge): history_location = "history/bit-canvas.txt" def check(self): - try: - return _tcp_banner(self.port, expect=None) - except Exception: - return False + return _tcp_alive(self.port) class Fjb(Challenge): @@ -82,43 +112,27 @@ class Fjb(Challenge): history_location = "history/fjb.txt" def check(self): - try: - url = f"http://localhost:{self.port}/" - r = requests.get(url, timeout=6) - assert r.status_code < 500 - return _flag_in_container(os.environ.get("CHALLENGE_CONTAINER_FJB", "fjb_container")) - except Exception: - return False + return _web_alive(self.port) and _flag_in_container(_container("fjb")) class GiftCard(Challenge): + """socat TCP line service (python main.py on :5000), NOT http.""" flag_location = "flags/gift-card.txt" history_location = "history/gift-card.txt" def check(self): - try: - url = f"http://localhost:{self.port}/" - r = requests.get(url, timeout=6) - assert r.status_code < 500 - return _flag_in_container(os.environ.get("CHALLENGE_CONTAINER_GIFT_CARD", "gift-card_container"), - "/ctf/gift-card/flag.txt") - except Exception: - return False + return _tcp_alive(self.port, send=b"1\n") and _flag_in_container( + _container("gift-card"), "/ctf/gift-card/flag.txt") class GiftVoucher(Challenge): + """socat TCP line service, NOT http.""" flag_location = "flags/gift-voucher.txt" history_location = "history/gift-voucher.txt" def check(self): - try: - url = f"http://localhost:{self.port}/" - r = requests.get(url, timeout=6) - assert r.status_code < 500 - return _flag_in_container(os.environ.get("CHALLENGE_CONTAINER_GIFT_VOUCHER", "gift-voucher_container"), - "/ctf/gift-voucher/flag.txt") - except Exception: - return False + return _tcp_alive(self.port, send=b"1\n") and _flag_in_container( + _container("gift-voucher"), "/ctf/gift-voucher/flag.txt") class GleamDrive(Challenge): @@ -126,13 +140,7 @@ class GleamDrive(Challenge): history_location = "history/gleam-drive.txt" def check(self): - try: - url = f"http://localhost:{self.port}/" - r = requests.get(url, timeout=6) - assert r.status_code < 500 - return _flag_in_container(os.environ.get("CHALLENGE_CONTAINER_GLEAM_DRIVE", "gleam-drive_container")) - except Exception: - return False + return _web_alive(self.port) and _flag_in_container(_container("gleam-drive")) class GoGreen(Challenge): @@ -140,10 +148,7 @@ class GoGreen(Challenge): history_location = "history/go-green.txt" def check(self): - try: - return _tcp_banner(self.port, expect=None) - except Exception: - return False + return _tcp_alive(self.port) class KodeViewer(Challenge): @@ -151,13 +156,7 @@ class KodeViewer(Challenge): history_location = "history/kode-viewer.txt" def check(self): - try: - url = f"http://localhost:{self.port}/" - r = requests.get(url, timeout=6) - assert r.status_code < 500 - return _flag_in_container(os.environ.get("CHALLENGE_CONTAINER_KODE_VIEWER", "kode-viewer_container")) - except Exception: - return False + return _web_alive(self.port) and _flag_in_container(_container("kode-viewer")) class MoreLess(Challenge): @@ -165,13 +164,7 @@ class MoreLess(Challenge): history_location = "history/more-less.txt" def check(self): - try: - url = f"http://localhost:{self.port}/" - r = requests.get(url, timeout=6) - assert r.status_code < 500 - return _flag_in_container(os.environ.get("CHALLENGE_CONTAINER_MORE_LESS", "more-less_container")) - except Exception: - return False + return _web_alive(self.port) and _flag_in_container(_container("more-less")) class TempestPoc(Challenge): @@ -179,13 +172,7 @@ class TempestPoc(Challenge): history_location = "history/tempest-poc.txt" def check(self): - try: - url = f"http://localhost:{self.port}/" - r = requests.get(url, timeout=6) - assert r.status_code < 500 - return _flag_in_container(os.environ.get("CHALLENGE_CONTAINER_TEMPEST_POC", "tempest-poc_container")) - except Exception: - return False + return _web_alive(self.port) and _flag_in_container(_container("tempest-poc")) class Ticketer(Challenge): @@ -193,7 +180,4 @@ class Ticketer(Challenge): history_location = "history/ticketer.txt" def check(self): - try: - return _tcp_banner(self.port, expect=None) - except Exception: - return False \ No newline at end of file + return _tcp_alive(self.port) \ No newline at end of file