Files
Cyrene ae50acfe40 fix(ssh): per-challenge SSH login + phew buffering/leak/timeout
Passwords failed on 10/16 challenges while state.json looked correct:
- only the 6 native GEMASTIK XVIII images provision 'ctfuser'; every imported
  XVI/XVII image does 'echo root:${PASSWORD} | chpasswd' and logs in as root.
  set_ssh_passwords() hardcoded ctfuser, so chpasswd set a password on an
  account nobody uses -> 'Permission denied' everywhere.
  Registry gains a per-challenge 'ssh_user'; chpasswd now targets the real
  login (and ctfuser/ctf when present) and reports failures loudly.
- phew checker: chall.py block-buffers stdout through the docker exec pipe
  (PYTHONUNBUFFERED now set) and leaks chall.py inside the container on
  timeout (26 orphans, container saturated) -> reaps the whole exec process
  group. Startup does a fresh Pailier keygen (~12 s) so crypto reads need
  _CRYPTO_TIMEOUT, not the 5 s prompt default.

Adds panel/verify_ssh_creds.py (proves the state->container binding from
inside via a real login), audit_ssh_users.sh, reset_runtime.sh.
2026-09-26 14:40:10 +08:00

33 lines
1.3 KiB
Bash

#!/usr/bin/env bash
# Start one team's full stack in the BACKGROUND (safe for a 16-challenge team:
# `compose up` for 16 services takes minutes and would blow a foreground timeout).
# Usage: start_team_bg.sh <teamIdx>
set -uo pipefail
IDX="${1:?usage: start_team_bg.sh <teamIdx>}"
LOG="/tmp/start-team${IDX}.log"
TEAMDIR="/opt/gemastik18-final/teams/team${IDX}"
cd "${TEAMDIR}/services" || exit 1
{
echo "=== $(date -Is) start team${IDX} ==="
docker compose -p "team${IDX}" up -d --remove-orphans 2>&1
echo "compose rc=$?"
# independent systemd receiver (never a child of the panel)
python3 /opt/gemastik18-final/panel/gen_receiver_services.py start 2>&1
systemctl restart "gemastik-receiver-team${IDX}.service" 2>&1
echo "receiver: $(systemctl is-active gemastik-receiver-team${IDX}.service)"
python3 - "$IDX" <<'PY'
import sys, json, time
sys.path.insert(0, '/opt/gemastik18-final/panel')
import teams
idx = int(sys.argv[1])
sf = f"/opt/gemastik18-final/teams/team{idx}/state.json"
st = json.loads(open(sf).read()); st["status"] = "running"
open(sf, "w").write(json.dumps(st, indent=2))
# retry loop: chpasswd races container boot
teams.set_ssh_passwords(idx)
print("=== done team", idx, "===")
PY
df -h / | tail -1
} >"${LOG}" 2>&1
echo "started team${IDX} -> ${LOG}"