fix: make challenge toggle actually work end-to-end (5 root-cause bugs)

Found by testing a real enable/disable cycle (art, fjb, gift-card):

1. compose_gen always swapped build->image, so a never-built challenge
   produced 'pull access denied for services-<name>'. Now it only reuses
   the image when it exists locally, otherwise keeps build: so
   'docker compose up --build' builds it.
2. Canonical templates use 'build: context: .' (written for the shared
   services/ tree). In the per-team compose that resolves to the team dir
   which has no Dockerfile -> 'failed to read dockerfile'. The renderer
   now rewrites the main service's context to ./<name>.
3. Teams created before the XVI/XVII import had no xvi/xvii subpackages
   under their local challenges/ dir, so the regenerated receiver main.py
   crash-looped on import. gen_receiver_main now mirrors ALL shared
   checkers (native + xvi + xvii) into every team receiver on each sync.
4. systemd Environment= keys can't contain hyphens, so
   CHALLENGE_PORT_GIFT-CARD was silently dropped. Keys are now
   normalized to underscores on both the writer and reader side.
5. Several checkers called 'docker exec' with no timeout; against a
   container with accumulated chall.py zombies that blocks forever and
   stalls the whole SLA loop. Added mandatory timeouts (Phew, Sheesh,
   Carbeat, Poke, Warmup).

Also: enabling a challenge now copies its source tree into each team's
services/ dir (team dirs only held challenges enabled at create_team
time), and the XVII checkers were rewritten to be protocol-aware
(gift-card/gift-voucher are socat TCP, not HTTP) with strict timeouts.
This commit is contained in:
MythEclipse
2026-09-25 15:36:09 +08:00
parent c6fd9ec268
commit d4c741926d
10 changed files with 176 additions and 106 deletions
+29 -5
View File
@@ -18,6 +18,7 @@ anti-alchemy, tempest-poc) keep their sidecar services.
"""
import json
import re
import subprocess
from pathlib import Path
BASE = Path("/opt/gemastik18-final")
@@ -47,6 +48,18 @@ def read_template(name: str) -> str:
raise FileNotFoundError(f"Tidak ada template compose untuk {name} di {p}")
return p.read_text()
def _image_exists(image_name: str) -> bool:
"""True if the docker image is already present locally.
The renderer only swaps a service's `build:` block for `image: services-<name>`
when that image actually exists. Otherwise compose would try to PULL a local
build artifact and fail with "pull access denied for services-<name>".
"""
r = subprocess.run(["docker", "image", "inspect", image_name],
capture_output=True, text=True, timeout=30)
return r.returncode == 0
def _parse_services(text: str):
names = []
for line in text.splitlines():
@@ -93,10 +106,12 @@ def render_team_compose(idx: int, state: dict) -> str:
text = re.sub(rf'"({org}):', f'"{tc}:', text)
text = re.sub(rf'"({org + 22}):', f'"{ts}:', text)
# --- build: -> image for MAIN only ---
# Replace the main service's build block with image: services-<name>.
# NB we process by service names, not generic removal, so sidecar
# builds survive.
# --- build: -> image for MAIN only (only when the image exists) ---
# Replace the main service's build block with image: services-<name> so
# teams share one image. If that image was never built, KEEP the build
# block so `docker compose up --build` builds it instead of trying to
# pull a nonexistent local image.
use_image = _image_exists(f"services-{name}")
lines = text.splitlines()
i = 0
in_main = False
@@ -112,7 +127,7 @@ def render_team_compose(idx: int, state: dict) -> str:
i += 1
continue
# inside a service block
if in_main and line.strip() == "build:":
if in_main and use_image and line.strip() == "build:":
# skip build block (context/args/dockerfile...) until next key at same indent
out.append(f" image: services-{name}")
i += 1
@@ -127,6 +142,15 @@ def render_team_compose(idx: int, state: dict) -> str:
text = re.sub(r"\$PASSWORD_" + str(org) + r"\b", passwords[name], text)
text = re.sub(r"PASSWORD_" + str(org) + r"\b", passwords[name], text)
# --- build context -> per-team challenge subdir ---
# Canonical templates are written for the SHARED services/ tree where a
# challenge's files sit in services/<name>/. The per-team compose lives in
# teamN/services/, so a bare `context: .` would resolve to the team dir
# (no Dockerfile). Point the MAIN service's build at ./<name>.
if re.search(r"^ build:$", text, re.M):
text = re.sub(r"^ build:\n context: \.$",
f" build:\n context: ./{name}", text, count=1, flags=re.M)
# --- flag volume normalization ---
# Replace any ./flag.txt / ../receiver/flags/<name>.txt with the per-team flag mount
text = re.sub(r"\./flag\.txt(:\w+)?", f"../receiver/flags/{name}.txt", text)
+39 -4
View File
@@ -11,6 +11,7 @@ from three packages:
from __future__ import annotations
import json
import shutil
from pathlib import Path
from teams import TEAMS_DIR, load_registry
@@ -98,26 +99,33 @@ app = FastAPI()
security = HTTPBasic()
settings = get_settings()
def _envkey(name: str) -> str:
# systemd Environment= keys can't contain hyphens; gen_receiver_services
# writes CHALLENGE_PORT_GIFT_CARD for the challenge "gift-card".
return name.upper().replace("-", "_")
def _ch_port(name: str, default: int) -> int:
# read from .env manually (pydantic settings has fixed fields)
val = os.environ.get(f"CHALLENGE_PORT_{{name.upper()}}")
key = _envkey(name)
val = os.environ.get(f"CHALLENGE_PORT_{{key}}")
if not val:
try:
with open(os.path.join(os.path.dirname(__file__), ".env")) as f:
for line in f:
if line.startswith(f"CHALLENGE_PORT_{{name.upper()}}="):
if line.startswith(f"CHALLENGE_PORT_{{key}}="):
val = line.strip().split("=", 1)[1]
except Exception:
pass
return int(val) if val else default
def _ch_container(name: str, default: str) -> str:
val = os.environ.get(f"CHALLENGE_CONTAINER_{{name.upper()}}")
key = _envkey(name)
val = os.environ.get(f"CHALLENGE_CONTAINER_{{key}}")
if not val:
try:
with open(os.path.join(os.path.dirname(__file__), ".env")) as f:
for line in f:
if line.startswith(f"CHALLENGE_CONTAINER_{{name.upper()}}="):
if line.startswith(f"CHALLENGE_CONTAINER_{{key}}="):
val = line.strip().split("=", 1)[1]
except Exception:
pass
@@ -253,6 +261,32 @@ def validate(credentials, challenge):
"""
def _sync_checker_packages(recv_dir) -> None:
"""Mirror the shared receiver's challenge checkers into a team receiver.
Two reasons this must run on every sync, not just at create_team time:
1. Teams created before the XVI/XVII import have no xvi/xvii subpackages,
so a regenerated main.py that imports them would crash-loop the receiver.
2. Native checkers (Blogpost/Phew/...) get bug fixes (e.g. mandatory
subprocess timeouts); a team copy made earlier keeps the stale version.
"""
shared_challenges = Path("/opt/gemastik18-final/receiver/challenges")
dst_root = recv_dir / "challenges"
dst_root.mkdir(parents=True, exist_ok=True)
for src_file in sorted(shared_challenges.glob("*.py")):
if src_file.name == "__init__.py":
continue
shutil.copy2(src_file, dst_root / src_file.name)
for pkg in ("xvi", "xvii"):
src = shared_challenges / pkg
if not src.exists():
continue
dst = dst_root / pkg
if dst.exists():
shutil.rmtree(dst)
shutil.copytree(src, dst, ignore=shutil.ignore_patterns("__pycache__", "*.pyc"))
def sync_team_receivers() -> None:
"""Regenerate main.py for every existing team from its state + registry."""
for d in sorted(TEAMS_DIR.glob("team*")):
@@ -262,6 +296,7 @@ def sync_team_receivers() -> None:
st = json.loads(sf.read_text())
idx = st["index"]
enabled = [c for c in load_registry()["challenges"] if c.get("enabled")]
_sync_checker_packages(d / "receiver")
text = render_receiver_main(enabled, {c["name"]: st["ports"][c["name"]]["chall"] for c in enabled})
(d / "receiver" / "main.py").write_text(text)
print(f"team{idx}: receiver main.py regenerated ({len(enabled)} challenges)")
+7 -3
View File
@@ -19,12 +19,16 @@ def write_unit(idx: int, st: dict):
port = st["ports"]["receiver"]
recv_dir = TEAMS_DIR / f"team{idx}" / "receiver"
env = {}
# ports/containers for challenge classes
# ports/containers for challenge classes.
# NOTE: systemd Environment= keys must be [A-Za-z0-9_]+ — a hyphen in the
# challenge name (gift-card) would make systemd silently drop the line, so
# normalize the name to underscores here. main.py looks up the same key.
for ch in st["ports"]:
if ch in ("receiver", "panel"):
continue
env[f"CHALLENGE_PORT_{ch.upper()}"] = str(st["ports"][ch]["chall"])
env[f"CHALLENGE_CONTAINER_{ch.upper()}"] = f"{ch}_container_team{idx}"
key = ch.upper().replace("-", "_")
env[f"CHALLENGE_PORT_{key}"] = str(st["ports"][ch]["chall"])
env[f"CHALLENGE_CONTAINER_{key}"] = f"{ch}_container_team{idx}"
# SSH passwords: checker Challenge.credentials() reads PASSWORD_<self.port>
# where self.port is the team challenge port.
pwd = st.get("chall_passwords", {}).get(ch)
+14
View File
@@ -116,6 +116,20 @@ def sync_challenge_runtime(name: str, enabled: bool) -> dict:
name) or f"chall{idx}_{name}_{secrets.token_hex(4)}"
# write state BEFORE rendering (render needs ports[name])
(sf).write_text(json.dumps(st, indent=2))
# Copy the challenge source into the team's services tree so a
# `build: context: .` resolves (team dirs only hold challenges
# that were enabled at create_team time).
team_svc_src = svc_dir / name
if not team_svc_src.exists():
src = SERVICES_SRC / name
if not src.exists():
raise FileNotFoundError(f"sumber service tidak ada: {src}")
shutil.copytree(src, team_svc_src,
ignore=shutil.ignore_patterns("__pycache__", "*.pyc", ".git"))
# apt-insecure.conf is needed by every challenge build
shared_apt = SERVICES_SRC / "apt-insecure.conf"
if shared_apt.exists() and not (team_svc_src / "apt-insecure.conf").exists():
shutil.copy2(shared_apt, team_svc_src / "apt-insecure.conf")
# regenerate whole compose (so enabled challenge included),
# then bring up just this service
new_text = compose_gen.render_team_compose(idx, st)
+2 -1
View File
@@ -26,8 +26,9 @@ class Carbeat(Challenge):
def _read_container_flag(self) -> str:
# timeout is mandatory: docker exec can block forever on a saturated container
out = subprocess.run(["docker", "exec", self._CONTAINER, "cat", "/flag.txt"],
capture_output=True, text=True)
capture_output=True, text=True, timeout=30)
if out.returncode != 0 or not out.stdout.strip():
raise FileNotFoundError("Flag not found in container (/flag.txt)")
return out.stdout.strip()
+7 -1
View File
@@ -14,8 +14,14 @@ class Phew(Challenge):
_HEX_RE = re.compile(r'^[0-9a-fA-F]+$')
def _read_container_flag(self) -> str:
# NB: a timeout is mandatory here. `docker exec` against a container
# whose process table is saturated (accumulated chall.py zombies) can
# block forever and take the whole SLA check loop down with it.
try:
out = subprocess.run(["docker", "exec", self._CONTAINER, "cat", "/flag.txt"],
capture_output=True, text=True)
capture_output=True, text=True, timeout=30)
except subprocess.TimeoutExpired:
raise TimeoutError("docker exec cat /flag.txt timed out (container overloaded?)")
if out.returncode != 0 or not out.stdout.strip():
raise FileNotFoundError("Flag not found in container (/flag.txt)")
return out.stdout.strip()
+2 -1
View File
@@ -52,7 +52,8 @@ class Poke(Challenge):
container_flag = subprocess.run(
["docker", "exec", "poke_container", "cat", "/flag.txt"],
capture_output=True,
text=True
text=True,
timeout=30
).stdout.strip()
assert host_flag == container_flag, 'Flag mismatch between host and container'
+2 -1
View File
@@ -15,9 +15,10 @@ class Sheesh(Challenge):
_HEX_RE = re.compile(r'^[0-9a-fA-F]+$')
def _read_container_flag(self) -> str:
# timeout is mandatory: docker exec can block forever on a saturated container
out = subprocess.run(
["docker", "exec", self._CONTAINER, "cat", "/flag.txt"],
capture_output=True, text=True
capture_output=True, text=True, timeout=30
)
if out.returncode != 0 or not out.stdout.strip():
raise FileNotFoundError("Flag not found in container (/flag.txt)")
+1 -1
View File
@@ -32,7 +32,7 @@ class Warmup(Challenge):
host_flag = f.read().strip()
container_flag = subprocess.run([
"docker", "exec", os.environ.get("CHALLENGE_CONTAINER_WARMUP", "warmup_container"), "cat", "/flag.txt"
], capture_output=True, text=True).stdout.strip()
], capture_output=True, text=True, timeout=30).stdout.strip()
assert host_flag == container_flag, 'Flag mismatch between host and container'
self.logger.info('Check passed for warmup')
+72 -88
View File
@@ -1,10 +1,17 @@
"""SLA checkers for GEMASTIK XVII challenges (imported from
github.com/vidner/gemastik-xvii-final — no upstream receiver was provided).
Each checker validates liveness + flag presence in the container. Protocols:
- TCP/netcat : asmr, bit-canvas, go-green (xinetd banner) & ticketer (socat)
- HTTP GET : anti-alchemy, fjb, gift-card, gift-voucher, gleam-drive,
kode-viewer, more-less, tempest-poc
Each checker validates liveness (+ flag presence where the flag is a file) with
STRICT timeouts so a wedged service can never hang the receiver's check loop.
Protocol classes:
- WEB : HTTP GET on the challenge port
- TCP : socat/xinetd line service — connect and expect a prompt/banner
- WEB+FLAG: WEB plus the flag must be mounted inside the container
Env-var convention: systemd Environment= keys are normalized to underscores
(CHALLENGE_PORT_GIFT_CARD for the challenge "gift-card"), so the lookup helper
does the same normalization.
"""
import os
import socket
@@ -15,6 +22,16 @@ import requests
from .Challenge import Challenge
def _key(name: str) -> str:
return name.upper().replace("-", "_")
def _container(challenge: str) -> str:
return os.environ.get(
f"CHALLENGE_CONTAINER_{_key(challenge)}", f"{challenge}_container"
)
def _docker_exec(container: str, *args, timeout: int = 10):
try:
return subprocess.run(["docker", "exec", container, *args],
@@ -24,35 +41,54 @@ def _docker_exec(container: str, *args, timeout: int = 10):
def _flag_in_container(container: str, path: str = "/flag.txt") -> bool:
r = _docker_exec(container, "sh", "-c", f"test -f {path} && cat {path} || echo MISSING")
return bool(r and "MISSING" not in (r.stdout or "") and r.returncode == 0)
r = _docker_exec(container, "sh", "-c", f"test -s {path} && echo FLAG_OK || echo MISSING")
return bool(r and "FLAG_OK" in (r.stdout or ""))
def _tcp_banner(port: int, timeout: float = 4.0, expect: bytes = None) -> bool:
def _web_alive(port: int, timeout: float = 5.0) -> bool:
"""Any HTTP response (even 4xx/5xx) proves the listener is up."""
try:
s = socket.create_connection(("127.0.0.1", port), timeout=timeout)
s.settimeout(timeout)
data = s.recv(256)
s.close()
if expect:
return expect.lower() in data.lower()
return len(data) > 0
r = requests.get(f"http://127.0.0.1:{port}/", timeout=timeout, allow_redirects=False)
return r.status_code < 600
except requests.exceptions.RequestException:
return False
except Exception:
return False
def _tcp_alive(port: int, timeout: float = 5.0, send: bytes = None) -> bool:
"""Connect to a line service and read a prompt/banner (or survive silence).
Some socat services wait for input before greeting, so a successful connect
with no data is also treated as alive; a refused connection is not.
"""
try:
s = socket.create_connection(("127.0.0.1", port), timeout=timeout)
except Exception:
return False
try:
s.settimeout(timeout)
if send:
s.sendall(send)
try:
data = s.recv(256)
except socket.timeout:
# connected but silent — service is accepting connections
return True
return True if data is not None else True
finally:
try:
s.close()
except Exception:
pass
class AntiAlchemy(Challenge):
flag_location = "flags/anti-alchemy.txt"
history_location = "history/anti-alchemy.txt"
def check(self):
try:
url = f"http://localhost:{self.port}/"
r = requests.get(url, timeout=6)
assert r.status_code in (200, 302, 500) or len(r.text) > 0
return _flag_in_container(os.environ.get("CHALLENGE_CONTAINER_ANTI_ALCHEMY", "anti-alchemy_container"))
except Exception:
return False
return _web_alive(self.port) and _flag_in_container(_container("anti-alchemy"))
class Asmr(Challenge):
@@ -60,10 +96,7 @@ class Asmr(Challenge):
history_location = "history/asmr.txt"
def check(self):
try:
return _tcp_banner(self.port, expect=None)
except Exception:
return False
return _tcp_alive(self.port)
class BitCanvas(Challenge):
@@ -71,10 +104,7 @@ class BitCanvas(Challenge):
history_location = "history/bit-canvas.txt"
def check(self):
try:
return _tcp_banner(self.port, expect=None)
except Exception:
return False
return _tcp_alive(self.port)
class Fjb(Challenge):
@@ -82,43 +112,27 @@ class Fjb(Challenge):
history_location = "history/fjb.txt"
def check(self):
try:
url = f"http://localhost:{self.port}/"
r = requests.get(url, timeout=6)
assert r.status_code < 500
return _flag_in_container(os.environ.get("CHALLENGE_CONTAINER_FJB", "fjb_container"))
except Exception:
return False
return _web_alive(self.port) and _flag_in_container(_container("fjb"))
class GiftCard(Challenge):
"""socat TCP line service (python main.py on :5000), NOT http."""
flag_location = "flags/gift-card.txt"
history_location = "history/gift-card.txt"
def check(self):
try:
url = f"http://localhost:{self.port}/"
r = requests.get(url, timeout=6)
assert r.status_code < 500
return _flag_in_container(os.environ.get("CHALLENGE_CONTAINER_GIFT_CARD", "gift-card_container"),
"/ctf/gift-card/flag.txt")
except Exception:
return False
return _tcp_alive(self.port, send=b"1\n") and _flag_in_container(
_container("gift-card"), "/ctf/gift-card/flag.txt")
class GiftVoucher(Challenge):
"""socat TCP line service, NOT http."""
flag_location = "flags/gift-voucher.txt"
history_location = "history/gift-voucher.txt"
def check(self):
try:
url = f"http://localhost:{self.port}/"
r = requests.get(url, timeout=6)
assert r.status_code < 500
return _flag_in_container(os.environ.get("CHALLENGE_CONTAINER_GIFT_VOUCHER", "gift-voucher_container"),
"/ctf/gift-voucher/flag.txt")
except Exception:
return False
return _tcp_alive(self.port, send=b"1\n") and _flag_in_container(
_container("gift-voucher"), "/ctf/gift-voucher/flag.txt")
class GleamDrive(Challenge):
@@ -126,13 +140,7 @@ class GleamDrive(Challenge):
history_location = "history/gleam-drive.txt"
def check(self):
try:
url = f"http://localhost:{self.port}/"
r = requests.get(url, timeout=6)
assert r.status_code < 500
return _flag_in_container(os.environ.get("CHALLENGE_CONTAINER_GLEAM_DRIVE", "gleam-drive_container"))
except Exception:
return False
return _web_alive(self.port) and _flag_in_container(_container("gleam-drive"))
class GoGreen(Challenge):
@@ -140,10 +148,7 @@ class GoGreen(Challenge):
history_location = "history/go-green.txt"
def check(self):
try:
return _tcp_banner(self.port, expect=None)
except Exception:
return False
return _tcp_alive(self.port)
class KodeViewer(Challenge):
@@ -151,13 +156,7 @@ class KodeViewer(Challenge):
history_location = "history/kode-viewer.txt"
def check(self):
try:
url = f"http://localhost:{self.port}/"
r = requests.get(url, timeout=6)
assert r.status_code < 500
return _flag_in_container(os.environ.get("CHALLENGE_CONTAINER_KODE_VIEWER", "kode-viewer_container"))
except Exception:
return False
return _web_alive(self.port) and _flag_in_container(_container("kode-viewer"))
class MoreLess(Challenge):
@@ -165,13 +164,7 @@ class MoreLess(Challenge):
history_location = "history/more-less.txt"
def check(self):
try:
url = f"http://localhost:{self.port}/"
r = requests.get(url, timeout=6)
assert r.status_code < 500
return _flag_in_container(os.environ.get("CHALLENGE_CONTAINER_MORE_LESS", "more-less_container"))
except Exception:
return False
return _web_alive(self.port) and _flag_in_container(_container("more-less"))
class TempestPoc(Challenge):
@@ -179,13 +172,7 @@ class TempestPoc(Challenge):
history_location = "history/tempest-poc.txt"
def check(self):
try:
url = f"http://localhost:{self.port}/"
r = requests.get(url, timeout=6)
assert r.status_code < 500
return _flag_in_container(os.environ.get("CHALLENGE_CONTAINER_TEMPEST_POC", "tempest-poc_container"))
except Exception:
return False
return _web_alive(self.port) and _flag_in_container(_container("tempest-poc"))
class Ticketer(Challenge):
@@ -193,7 +180,4 @@ class Ticketer(Challenge):
history_location = "history/ticketer.txt"
def check(self):
try:
return _tcp_banner(self.port, expect=None)
except Exception:
return False
return _tcp_alive(self.port)