Passwords failed on 10/16 challenges while state.json looked correct:
- only the 6 native GEMASTIK XVIII images provision 'ctfuser'; every imported
XVI/XVII image does 'echo root:${PASSWORD} | chpasswd' and logs in as root.
set_ssh_passwords() hardcoded ctfuser, so chpasswd set a password on an
account nobody uses -> 'Permission denied' everywhere.
Registry gains a per-challenge 'ssh_user'; chpasswd now targets the real
login (and ctfuser/ctf when present) and reports failures loudly.
- phew checker: chall.py block-buffers stdout through the docker exec pipe
(PYTHONUNBUFFERED now set) and leaks chall.py inside the container on
timeout (26 orphans, container saturated) -> reaps the whole exec process
group. Startup does a fresh Pailier keygen (~12 s) so crypto reads need
_CRYPTO_TIMEOUT, not the 5 s prompt default.
Adds panel/verify_ssh_creds.py (proves the state->container binding from
inside via a real login), audit_ssh_users.sh, reset_runtime.sh.
33 lines
1.3 KiB
Bash
33 lines
1.3 KiB
Bash
#!/usr/bin/env bash
|
|
# Start one team's full stack in the BACKGROUND (safe for a 16-challenge team:
|
|
# `compose up` for 16 services takes minutes and would blow a foreground timeout).
|
|
# Usage: start_team_bg.sh <teamIdx>
|
|
set -uo pipefail
|
|
IDX="${1:?usage: start_team_bg.sh <teamIdx>}"
|
|
LOG="/tmp/start-team${IDX}.log"
|
|
TEAMDIR="/opt/gemastik18-final/teams/team${IDX}"
|
|
cd "${TEAMDIR}/services" || exit 1
|
|
{
|
|
echo "=== $(date -Is) start team${IDX} ==="
|
|
docker compose -p "team${IDX}" up -d --remove-orphans 2>&1
|
|
echo "compose rc=$?"
|
|
# independent systemd receiver (never a child of the panel)
|
|
python3 /opt/gemastik18-final/panel/gen_receiver_services.py start 2>&1
|
|
systemctl restart "gemastik-receiver-team${IDX}.service" 2>&1
|
|
echo "receiver: $(systemctl is-active gemastik-receiver-team${IDX}.service)"
|
|
python3 - "$IDX" <<'PY'
|
|
import sys, json, time
|
|
sys.path.insert(0, '/opt/gemastik18-final/panel')
|
|
import teams
|
|
idx = int(sys.argv[1])
|
|
sf = f"/opt/gemastik18-final/teams/team{idx}/state.json"
|
|
st = json.loads(open(sf).read()); st["status"] = "running"
|
|
open(sf, "w").write(json.dumps(st, indent=2))
|
|
# retry loop: chpasswd races container boot
|
|
teams.set_ssh_passwords(idx)
|
|
print("=== done team", idx, "===")
|
|
PY
|
|
df -h / | tail -1
|
|
} >"${LOG}" 2>&1
|
|
echo "started team${IDX} -> ${LOG}"
|