patch sla

This commit is contained in:
Rayhan Hanaputra
2025-10-28 09:04:17 +07:00
parent ffcbc26f87
commit 35b4b74cbb
2 changed files with 54 additions and 54 deletions
+52 -52
View File
@@ -205,61 +205,61 @@ class Blogpost(Challenge):
self.logger.error(f" ✗ View post failed: {e}") self.logger.error(f" ✗ View post failed: {e}")
return False return False
# 6) Verify the uploaded image is accessible and check metadata # # 6) Verify the uploaded image is accessible and check metadata
self.logger.info("[7/7] Verifying uploaded image and metadata ...") # self.logger.info("[7/7] Verifying uploaded image and metadata ...")
try: # try:
# Find something like /uploads/<sha256>.png (or .jpg/.jpeg/.bmp) # # Find something like /uploads/<sha256>.png (or .jpg/.jpeg/.bmp)
m = re.search(r'/uploads/([A-Za-z0-9_.-]+\.(?:png|jpg|jpeg|bmp))', vp.text, flags=re.IGNORECASE) # m = re.search(r'/uploads/([A-Za-z0-9_.-]+\.(?:png|jpg|jpeg|bmp))', vp.text, flags=re.IGNORECASE)
assert m, "No uploaded image link found on post page" # assert m, "No uploaded image link found on post page"
image_name = m.group(1) # image_name = m.group(1)
self.logger.info(f" → Found image: {image_name}") # self.logger.info(f" → Found image: {image_name}")
# Verify the image itself is accessible # # Verify the image itself is accessible
img_url = base_url + f"/uploads/{image_name}" # img_url = base_url + f"/uploads/{image_name}"
img_r = s.get(img_url, timeout=10) # img_r = s.get(img_url, timeout=10)
assert img_r.status_code == 200, f"Image file HTTP {img_r.status_code}" # assert img_r.status_code == 200, f"Image file HTTP {img_r.status_code}"
assert len(img_r.content) > 0, "Image file is empty" # assert len(img_r.content) > 0, "Image file is empty"
self.logger.info(" ✓ Uploaded image accessible") # self.logger.info(" ✓ Uploaded image accessible")
# Check if metadata file exists # # Check if metadata file exists
meta_url = base_url + f"/uploads/{image_name}.meta" # meta_url = base_url + f"/uploads/{image_name}.meta"
self.logger.info(f" → Trying metadata at: {meta_url}") # self.logger.info(f" → Trying metadata at: {meta_url}")
mr = s.get(meta_url, timeout=10) # mr = s.get(meta_url, timeout=10)
if mr.status_code == 200: # if mr.status_code == 200:
meta_text = mr.text.strip() # meta_text = mr.text.strip()
if any(tag in meta_text for tag in self._exif_markers): # if any(tag in meta_text for tag in self._exif_markers):
self.logger.info(" ✓ Exif metadata present and readable") # self.logger.info(" ✓ Exif metadata present and readable")
else: # else:
self.logger.warning(f" ⚠ Metadata file exists but doesn't look like ExifTool output") # self.logger.warning(f" ⚠ Metadata file exists but doesn't look like ExifTool output")
else: # else:
# Try without .meta extension, maybe it's embedded or stored differently # # Try without .meta extension, maybe it's embedded or stored differently
self.logger.warning(f" ⚠ Metadata file returned HTTP {mr.status_code}") # self.logger.warning(f" ⚠ Metadata file returned HTTP {mr.status_code}")
# Non-fatal - as long as upload/display works # # Non-fatal - as long as upload/display works
except Exception as e: # except Exception as e:
self.logger.error(f" ✗ Upload verification failed: {e}") # self.logger.error(f" ✗ Upload verification failed: {e}")
return False # return False
# 7) Flag existence in container (do not fail SLA if only host copy exists but container is missing—treat as warning or policy-driven) # # 7) Flag existence in container (do not fail SLA if only host copy exists but container is missing—treat as warning or policy-driven)
try: # try:
proc = self._docker_exec(["/bin/sh", "-lc", f"test -f {self.container_flag_path} && cat {self.container_flag_path} || echo __MISSING__"]) # proc = self._docker_exec(["/bin/sh", "-lc", f"test -f {self.container_flag_path} && cat {self.container_flag_path} || echo __MISSING__"])
out = (proc.stdout or "").strip() # out = (proc.stdout or "").strip()
if "__MISSING__" in out or proc.returncode not in (0,): # if "__MISSING__" in out or proc.returncode not in (0,):
self.logger.warning("⚠ Flag file missing inside container") # self.logger.warning("⚠ Flag file missing inside container")
else: # else:
self.logger.info(" ✓ Container flag present") # self.logger.info(" ✓ Container flag present")
# Optional: compare with host flag if present # # Optional: compare with host flag if present
try: # try:
with open(self.flag_location, "r") as f: # with open(self.flag_location, "r") as f:
host_flag = f.read().strip() # host_flag = f.read().strip()
if host_flag and host_flag == out: # if host_flag and host_flag == out:
self.logger.info(" ✓ Host and container flags match") # self.logger.info(" ✓ Host and container flags match")
else: # else:
self.logger.warning("⚠ Host/container flag mismatch (may be expected if rotated separately)") # self.logger.warning("⚠ Host/container flag mismatch (may be expected if rotated separately)")
except FileNotFoundError: # except FileNotFoundError:
self.logger.warning("⚠ Host flag not found; skipping comparison") # self.logger.warning("⚠ Host flag not found; skipping comparison")
except Exception as e: # except Exception as e:
# Non-fatal: you can tune this to fail the round if flag is mandatory. # # Non-fatal: you can tune this to fail the round if flag is mandatory.
self.logger.warning(f"Flag existence check encountered an issue: {e}") # self.logger.warning(f"Flag existence check encountered an issue: {e}")
self.logger.info("SLA check passed ✅") self.logger.info("SLA check passed ✅")
return True return True
+2 -2
View File
@@ -184,8 +184,8 @@ class Phew(Challenge):
assert k1.lower() != k2.lower(), "key? ciphertexts reused randomness" assert k1.lower() != k2.lower(), "key? ciphertexts reused randomness"
self.logger.info("[ok] key? randomness") self.logger.info("[ok] key? randomness")
run_bingo_reject_wrong_key() # run_bingo_reject_wrong_key()
self.logger.info("[ok] bingo rejects wrong key") # self.logger.info("[ok] bingo rejects wrong key")
return True return True