Found by testing a real enable/disable cycle (art, fjb, gift-card): 1. compose_gen always swapped build->image, so a never-built challenge produced 'pull access denied for services-<name>'. Now it only reuses the image when it exists locally, otherwise keeps build: so 'docker compose up --build' builds it. 2. Canonical templates use 'build: context: .' (written for the shared services/ tree). In the per-team compose that resolves to the team dir which has no Dockerfile -> 'failed to read dockerfile'. The renderer now rewrites the main service's context to ./<name>. 3. Teams created before the XVI/XVII import had no xvi/xvii subpackages under their local challenges/ dir, so the regenerated receiver main.py crash-looped on import. gen_receiver_main now mirrors ALL shared checkers (native + xvi + xvii) into every team receiver on each sync. 4. systemd Environment= keys can't contain hyphens, so CHALLENGE_PORT_GIFT-CARD was silently dropped. Keys are now normalized to underscores on both the writer and reader side. 5. Several checkers called 'docker exec' with no timeout; against a container with accumulated chall.py zombies that blocks forever and stalls the whole SLA loop. Added mandatory timeouts (Phew, Sheesh, Carbeat, Poke, Warmup). Also: enabling a challenge now copies its source tree into each team's services/ dir (team dirs only held challenges enabled at create_team time), and the XVII checkers were rewritten to be protocol-aware (gift-card/gift-voucher are socat TCP, not HTTP) with strict timeouts.
42 lines
1.5 KiB
Python
42 lines
1.5 KiB
Python
from .Challenge import Challenge
|
|
|
|
import os
|
|
import io
|
|
import requests
|
|
import random
|
|
import subprocess
|
|
|
|
class Warmup(Challenge):
|
|
flag_location = 'flags/warmup.txt'
|
|
history_location = 'history/warmup.txt'
|
|
|
|
def distribute(self, flag):
|
|
try:
|
|
with open(self.flag_location, 'w') as f:
|
|
f.write(flag)
|
|
with open(self.history_location, 'a') as f:
|
|
f.write(flag + '\n')
|
|
self.logger.info(f'Flag {flag} written to {self.flag_location}')
|
|
return True
|
|
except Exception as e:
|
|
self.logger.error(f'Could not write flag to {self.flag_location}: {e}')
|
|
return False
|
|
|
|
def check(self):
|
|
try:
|
|
url = f'http://localhost:{self.port}/'
|
|
r = requests.get(url, timeout=5)
|
|
assert "Simple file viewing application" in r.text, 'Warmup app not available'
|
|
|
|
with open(self.flag_location, 'r') as f:
|
|
host_flag = f.read().strip()
|
|
container_flag = subprocess.run([
|
|
"docker", "exec", os.environ.get("CHALLENGE_CONTAINER_WARMUP", "warmup_container"), "cat", "/flag.txt"
|
|
], capture_output=True, text=True, timeout=30).stdout.strip()
|
|
assert host_flag == container_flag, 'Flag mismatch between host and container'
|
|
|
|
self.logger.info('Check passed for warmup')
|
|
return True
|
|
except Exception as e:
|
|
self.logger.error(f'Could not check warmup: {e}')
|
|
return False |