49 Commits
Author SHA1 Message Date
root 50cb782ded fix(portal): per-challenge SSH user in web terminal + credential API
The web SSH terminal and the credential API reported `ctfuser` for all 16
challenges, but only the 6 native GEMASTIK XVIII images provision ctfuser.
Every imported XVI/XVII image does `RUN echo root:${PASSWORD} | chpasswd`,
so 10 of 16 participant logins were refused with "Permission denied".

Root causes (all the same class of bug - login hardcoded in the wrong layer):
- main.py websocket ssh handler read st["ssh_user"], a single team-wide value
  defaulting to ctfuser, instead of the per-challenge registry field
- /api/credential proxied the global receiver on :18080, which only knows the
  6 native challenges, so the other 10 returned "Invalid challenge"
- team.html hardcoded the challenge picker to those same 6 challenges, making
  the other 10 unreachable from the terminal entirely
- index.html rendered `<b>ctfuser</b>` and a stale hardcoded SSH port table

Fixes:
- orch.challenge_credential()/all_teams() read the TEAM's state.json, which
  holds the same per-challenge password the panel chpasswds
- gen_receiver_services.py injects SSH_USER_<port> from the registry so the
  receiver's /credential endpoint agrees with the panel
- receiver Challenge.credentials() honours SSH_USER_<port> (ctfuser fallback)
- new /api/team/{idx}/own-challenges feeds the picker; targets now carry
  challenge + ssh_user
- UI takes user and port from the server instead of hardcoding them

Verified: 32/32 credential payloads correct across teams 1-2, and 32/32 real
paramiko SSH logins succeed with whoami confirming the expected account.

Also adds bulk team delete: POST /api/teams/bulk-delete runs one background
thread and is polled via GET /api/teams/bulk-delete/{job_id}, plus per-team
checkboxes with select-all/clear in the UI. Deletion must stay sequential
because delete_team() regenerates shared artifacts at the end.
2026-09-26 16:37:40 +08:00
Cyrene aa0bb45633 fix(sla): 100% fleet SLA (64/64) - per-challenge SSH login, phew checker, sidecar detection
Three independent root causes, all found by measuring instead of assuming:

1. SSH failed on 10/16 challenges while state.json looked perfect.
   Only the 6 native GEMASTIK XVIII images provision 'ctfuser'; every imported
   XVI/XVII image does 'echo root:${PASSWORD} | chpasswd' and logs in as root.
   set_ssh_passwords() hardcoded ctfuser, so chpasswd set a password nobody
   used -> 'Permission denied' on every team. Registry gains a per-challenge
   'ssh_user'; chpasswd targets the real login and reports failures loudly.

2. phew SLA timed out on a healthy service, four bugs stacked:
   - chall.py block-buffers stdout through the exec pipe (PYTHONUNBUFFERED now
     set) and does a fresh Pailier keygen (~12 s) before printing its menu;
   - _read_until read a TEXT pipe, so read(1) pulled 8 KB into Python's
     TextIOWrapper buffer and select() then blocked on data already in memory;
   - its buffer was per-call, so the read satisfying 'pt (hex)' also swallowed
     the '> ' the next call waited for -> a race that failed intermittently;
   - reaping killed chall.py it did not own: a blanket pkill -f, a
     snapshot-diff (concurrent sessions diff against the same pre-spawn set),
     and a class-level _children shared across uvicorn's thread pool. The child
     now prints its own pid so exactly one session is reaped.
   Also: ONE interactive session per check instead of five spawns (Paillier is
   randomized per ciphertext, not per process) - 5 keygens were the CPU load
   that starved the checks. And the 6 orphan single-node containers from the
   original deploy were removed; one held 58 leaked chall.py and drove load
   average 76 on 2 CPUs.

3. missing_sidecars() matched compose-generated names (teamN-<svc>-1) while
   every service sets an explicit container_name, so it reported all 16 running
   challenges as missing and hid the one real gap (anti-alchemy-db, which has
   no container_name). Now reads container_name when present and falls back to
   the compose default otherwise.

Verified: 64/64 SLA across 4 teams; 64/64 real SSH logins succeed with
correct <chall>_teamN hostnames; phew 3/3 sequential with no process leak.

Adds panel/verify_ssh_creds.py, audit_ssh_users.sh, reset_runtime.sh,
sla_sweep.sh, fix_sidecars.sh, phew_concurrency_test.sh, exec_probe_i.py.
2026-09-26 15:37:31 +08:00
Cyrene ae50acfe40 fix(ssh): per-challenge SSH login + phew buffering/leak/timeout
Passwords failed on 10/16 challenges while state.json looked correct:
- only the 6 native GEMASTIK XVIII images provision 'ctfuser'; every imported
  XVI/XVII image does 'echo root:${PASSWORD} | chpasswd' and logs in as root.
  set_ssh_passwords() hardcoded ctfuser, so chpasswd set a password on an
  account nobody uses -> 'Permission denied' everywhere.
  Registry gains a per-challenge 'ssh_user'; chpasswd now targets the real
  login (and ctfuser/ctf when present) and reports failures loudly.
- phew checker: chall.py block-buffers stdout through the docker exec pipe
  (PYTHONUNBUFFERED now set) and leaks chall.py inside the container on
  timeout (26 orphans, container saturated) -> reaps the whole exec process
  group. Startup does a fresh Pailier keygen (~12 s) so crypto reads need
  _CRYPTO_TIMEOUT, not the 5 s prompt default.

Adds panel/verify_ssh_creds.py (proves the state->container binding from
inside via a real login), audit_ssh_users.sh, reset_runtime.sh.
2026-09-26 14:40:10 +08:00
MythEclipse d4c741926d fix: make challenge toggle actually work end-to-end (5 root-cause bugs)
Found by testing a real enable/disable cycle (art, fjb, gift-card):

1. compose_gen always swapped build->image, so a never-built challenge
   produced 'pull access denied for services-<name>'. Now it only reuses
   the image when it exists locally, otherwise keeps build: so
   'docker compose up --build' builds it.
2. Canonical templates use 'build: context: .' (written for the shared
   services/ tree). In the per-team compose that resolves to the team dir
   which has no Dockerfile -> 'failed to read dockerfile'. The renderer
   now rewrites the main service's context to ./<name>.
3. Teams created before the XVI/XVII import had no xvi/xvii subpackages
   under their local challenges/ dir, so the regenerated receiver main.py
   crash-looped on import. gen_receiver_main now mirrors ALL shared
   checkers (native + xvi + xvii) into every team receiver on each sync.
4. systemd Environment= keys can't contain hyphens, so
   CHALLENGE_PORT_GIFT-CARD was silently dropped. Keys are now
   normalized to underscores on both the writer and reader side.
5. Several checkers called 'docker exec' with no timeout; against a
   container with accumulated chall.py zombies that blocks forever and
   stalls the whole SLA loop. Added mandatory timeouts (Phew, Sheesh,
   Carbeat, Poke, Warmup).

Also: enabling a challenge now copies its source tree into each team's
services/ dir (team dirs only held challenges enabled at create_team
time), and the XVII checkers were rewritten to be protocol-aware
(gift-card/gift-voucher are socat TCP, not HTTP) with strict timeouts.
2026-09-25 15:36:09 +08:00
MythEclipse c6fd9ec268 feat: challenge registry-driven platform + XVI/XVII imports + admin toggle + domain rename
- Rename repo/domain: attack-defense-platform / attackdefense.imrnes.team (all refs replaced)
- challenge_registry.json: single source of truth (28 challs across gemastik18/xvi/xvii)
- teams.py: registry-driven CHALLENGES, set_challenge_enabled, sync_challenge_runtime
  (apply enable/disable to live teams: build/up or stop/remove + receiver restart)
- compose_gen.py: render per-team compose from canonical per-challenge templates
  (image reuse, per-team ports 30xxx, flag mounts, passwords)
- gen_canonical_composes.py: canonical docker-compose.yml for all services
- import_new_challenges.py: import XVI/XVII services + EOL base image fixes
  (debian:buster→bookworm, node:14→20, python:3.7-slim→3.11)
- receiver: xvi package (10 checkers) + xvii package (12 generic checkers),
  Challenge base reads PASSWORD_<team_port> from env; gen_receiver_main.py
  generates per-team main.py from registry
- main.py: /api/challenges returns full registry; PATCH /api/challenges/<name>
  toggles enabled + applies to live teams
- index.html: 🏗️ Challenge Manager tab (toggle per challenge, grouped by set)
- SLA bonus now dynamic (all enabled challenges, not hardcoded 6)
2026-09-25 14:04:33 +08:00
root 4a65f24af3 chore: gitignore runtime flags + leaderboard 2026-09-23 16:18:59 +08:00
root 8c061ba1b7 fix: port scheme 30000 (avoid syncthing 22000), reuse base images (no per-team rebuild), recover corrupted receiver/main.py, compose -p project isolation
- PORT_BASE 20000->30000: team1=31xxx team2=32xxx; syncthing owns 22000
- create_team replaces build: with image: services-<name> so teams reuse base images (was rebuilding 6 images per team, disk 100%)
- recovery: receiver/main.py was corrupted by bad patch (write_file with read_file format); restored from team1 copy + original GitHub
- docker compose -p teamN: project isolation so team compose doesn't overlap (was showing team1 containers for team2)
2026-09-23 15:44:53 +08:00
root 1ca963b2b7 feat: multi-team orchestrator - topology UI, team management, flag randomizer, public submit + leaderboard
- panel/teams.py: create/start/stop teams with isolated ports+creds, per-team receivers with CHALLENGE_PORT/CONTAINER env, flag randomization, submit validation + leaderboard
- panel/main.py: /api/teams, /api/teams/{idx}/randomize, /api/flag/submit, /api/leaderboard, /api/public/teams, /submit page
- panel/static/submit.html: public flag submission UI for teams
- receiver: _ch_port/_ch_container read .env per team, container name overrides
- .gitignore: exclude teams/, .venv, __pycache__
2026-09-23 15:14:52 +08:00
Rayhan Hanaputra 615f8aa130 fix chall itoid 2025-10-28 09:08:35 +07:00
Rayhan Hanaputra 35b4b74cbb patch sla 2025-10-28 09:04:17 +07:00
lightningitoid bbeb22211e updated sheesh 2025-10-27 08:25:45 +07:00
lightningitoid fddf357524 updated sla for sheesh 2025-10-27 08:10:22 +07:00
lightningitoid f61a42fa59 updated sheesh 2025-10-27 07:46:35 +07:00
lightningitoid e7cfcbdf59 updated sheesh 2025-10-27 00:53:16 +07:00
lightningitoid 1a49e5888f fixed phew 2025-10-26 22:30:05 +07:00
lightningitoid e0d2de93f2 fixed phew 2025-10-26 22:25:05 +07:00
Rayhan Hanaputra 6b96a097c3 phew kocak 2025-10-26 20:56:37 +07:00
lightningitoid 1307deb34e little changes 2025-10-26 15:24:04 +07:00
Rayhan Hanaputra fda1e6b4cd fix sla itoid 2025-10-26 14:09:44 +07:00
lightningitoid 200d63ef74 updated sigalarm time 2025-10-26 10:12:17 +07:00
Rayhan Hanaputra 41781f721d Merge branch 'main' of https://github.com/rayhanhanaputra/gemastik18-final 2025-10-26 09:29:26 +07:00
Rayhan Hanaputra 720941ee63 updated sla jon 2025-10-26 09:29:22 +07:00
Jonathan ab4451539c update cdn checker 2025-10-26 01:44:44 +07:00
Jonathan 8688861372 cdn checker update view post 2025-10-26 01:21:30 +07:00
Rayhan Hanaputra 4dbafc3d9e added timeout scam 2025-10-25 23:33:50 +07:00
Rayhan Hanaputra 89b0bb4077 adjusted amazon-linux 2025-10-25 23:29:44 +07:00
Rayhan Hanaputra de319f6e16 test fix sla rui n itoid 2025-10-25 23:26:35 +07:00
Rayhan Hanaputra c475c63518 remove line @ pyenv.cfg 2025-10-25 23:18:12 +07:00
Rayhan Hanaputra 7e98bcc243 fix sla bini 2025-10-25 23:16:50 +07:00
itoid c9a2792481 Add files via upload 2025-10-25 17:39:54 +07:00
itoid fb5d972d20 Delete receiver/challenges/Phew.py 2025-10-25 17:39:27 +07:00
adzkyyy 59b0ffd951 test sla 2025-10-25 15:34:23 +07:00
rafliher 910f345c08 checker bugfix 2025-10-25 15:11:03 +07:00
rafliher 92ef1336ea blogpost typo 2025-10-25 15:08:07 +07:00
rafliher 110a54f510 checker fixes 2025-10-25 15:07:24 +07:00
rafliher 0f09642e91 fix warmup checker 2025-10-25 14:57:55 +07:00
rafliher 5afe75907e debug warmup 2025-10-25 14:56:34 +07:00
rafliher 3d21421c49 update req 2025-10-25 14:51:38 +07:00
rafliher 7df02812b1 update core engine 2025-10-25 14:50:40 +07:00
rafliher 0d216d77eb try checker 2025-10-25 14:48:20 +07:00
rafliher 41a170543b docker compose bugfix 2025-10-25 14:18:49 +07:00
rafliher 6ea6f54150 docker reintegrate 2025-10-25 14:10:59 +07:00
adzkyyy 0d8f10bb11 add sla 2025-10-25 12:29:18 +07:00
Rayhan Hanaputra 604bd24b04 added warmup chall 2025-10-25 04:56:33 +07:00
itoid 4552bcb0fe Add files via upload 2025-10-21 21:20:25 +07:00
itoid edab268592 Add files via upload 2025-10-13 23:38:37 +07:00
itoid a76de14086 Create sheesh.txt 2025-10-13 23:32:09 +07:00
Rayhan Hanaputra d42b472b3e removed old files 2025-10-11 11:59:21 +07:00
Rayhan Hanaputra ea02892f14 Initial commit 2025-10-10 22:18:06 +07:00