feat: set per-team SSH passwords at runtime (chpasswd in shared images)
This commit is contained in:
@@ -186,8 +186,25 @@ def start_team(idx: int):
|
||||
st = json.loads((team_dir / "state.json").read_text())
|
||||
st["status"] = "running"
|
||||
(team_dir / "state.json").write_text(json.dumps(st, indent=2))
|
||||
# Set per-team SSH passwords at runtime (images are shared across teams,
|
||||
# so chpasswd ensures each team's containers have the team's own password).
|
||||
set_ssh_passwords(idx)
|
||||
return st
|
||||
|
||||
|
||||
def set_ssh_passwords(idx: int):
|
||||
"""Set SSH password for ctfuser in each challenge container of a team."""
|
||||
team_dir = TEAMS_DIR / f"team{idx}"
|
||||
st = json.loads((team_dir / "state.json").read_text())
|
||||
for name, coff, soff in CHALLENGES:
|
||||
cont = f"{name}_container_team{idx}"
|
||||
pw = st["chall_passwords"][name]
|
||||
cmd = f"echo 'ctfuser:{pw}' | chpasswd"
|
||||
r = subprocess.run(["docker", "exec", cont, "sh", "-c", cmd],
|
||||
capture_output=True, text=True, timeout=30)
|
||||
if r.returncode != 0:
|
||||
print(f"[set_ssh_passwords] {cont}: FAILED ({r.stderr.strip()[:100]})")
|
||||
|
||||
def stop_team(idx: int):
|
||||
team_dir = TEAMS_DIR / f"team{idx}"
|
||||
svc_dir = team_dir / "services"
|
||||
|
||||
Reference in New Issue
Block a user