Files
attack-defense-platform/panel/compose_gen.py
T
MythEclipse d4c741926d fix: make challenge toggle actually work end-to-end (5 root-cause bugs)
Found by testing a real enable/disable cycle (art, fjb, gift-card):

1. compose_gen always swapped build->image, so a never-built challenge
   produced 'pull access denied for services-<name>'. Now it only reuses
   the image when it exists locally, otherwise keeps build: so
   'docker compose up --build' builds it.
2. Canonical templates use 'build: context: .' (written for the shared
   services/ tree). In the per-team compose that resolves to the team dir
   which has no Dockerfile -> 'failed to read dockerfile'. The renderer
   now rewrites the main service's context to ./<name>.
3. Teams created before the XVI/XVII import had no xvi/xvii subpackages
   under their local challenges/ dir, so the regenerated receiver main.py
   crash-looped on import. gen_receiver_main now mirrors ALL shared
   checkers (native + xvi + xvii) into every team receiver on each sync.
4. systemd Environment= keys can't contain hyphens, so
   CHALLENGE_PORT_GIFT-CARD was silently dropped. Keys are now
   normalized to underscores on both the writer and reader side.
5. Several checkers called 'docker exec' with no timeout; against a
   container with accumulated chall.py zombies that blocks forever and
   stalls the whole SLA loop. Added mandatory timeouts (Phew, Sheesh,
   Carbeat, Poke, Warmup).

Also: enabling a challenge now copies its source tree into each team's
services/ dir (team dirs only held challenges enabled at create_team
time), and the XVII checkers were rewritten to be protocol-aware
(gift-card/gift-voucher are socat TCP, not HTTP) with strict timeouts.
2026-09-25 15:36:09 +08:00

169 lines
6.8 KiB
Python

#!/usr/bin/env python3
"""
compose_gen — render a team's docker-compose.yml from the challenge registry.
For every ENABLED challenge, a canonical per-challenge compose template lives
at services/<name>/docker-compose.yml (see gen_canonical_composes.py). The
renderer:
- replaces `build:` blocks with `image: services-<name>` for the MAIN
service (sidecars keep their images/builds),
- rewrites container_name / hostname to the per-team suffix,
- rewrites host ports (<ORG>:<INT>, <ORG+22>:22) to the team's ports,
- replaces PASSWORD_<ORG> placeholders with the team's challenge password,
- normalizes flag volume to ../receiver/flags/<name>.txt.
Multi-container challenges (gemas-notes, gemas-fetcher, kode-viewer,
anti-alchemy, tempest-poc) keep their sidecar services.
"""
import json
import re
import subprocess
from pathlib import Path
BASE = Path("/opt/gemastik18-final")
TEAMS_DIR = BASE / "teams"
SERVICES_SRC = BASE / "services"
# Challenges whose compose has multiple top-level services; the FIRST service
# listed is the MAIN challenge service (gets image: reuse + challenge ports),
# the rest are sidecars.
SIDECAR_NAMES = {
"anti-alchemy": ["anti-alchemy-db"],
"gemas-fetcher": ["mongodb"],
"gemas-notes": ["database", "validation-service"],
"kode-viewer": ["redis"],
"tempest-poc": ["backend"],
}
def _load_registry() -> dict:
try:
return json.loads((TEAMS_DIR / "challenge_registry.json").read_text())
except Exception:
return {"sets": {}, "challenges": []}
def read_template(name: str) -> str:
p = SERVICES_SRC / name / "docker-compose.yml"
if not p.exists():
raise FileNotFoundError(f"Tidak ada template compose untuk {name} di {p}")
return p.read_text()
def _image_exists(image_name: str) -> bool:
"""True if the docker image is already present locally.
The renderer only swaps a service's `build:` block for `image: services-<name>`
when that image actually exists. Otherwise compose would try to PULL a local
build artifact and fail with "pull access denied for services-<name>".
"""
r = subprocess.run(["docker", "image", "inspect", image_name],
capture_output=True, text=True, timeout=30)
return r.returncode == 0
def _parse_services(text: str):
names = []
for line in text.splitlines():
m = re.match(r"^ ([A-Za-z0-9_-]+):\s*$", line)
if m and not line.startswith(" "):
names.append(m.group(1))
return names
def render_team_compose(idx: int, state: dict) -> str:
ports = state["ports"]
passwords = state["chall_passwords"]
blocks = []
for ch in enabled_challenges():
name = ch["name"]
text = read_template(name)
main = _parse_services(text)
main = main[0] if main else name
sidecars = set(SIDECAR_NAMES.get(name, []))
org = int(ch.get("org_port", 10000))
tc = ports[name]["chall"]
ts = ports[name]["ssh"]
# --- rewrite container_name / hostname per team ---
out_lines = []
for line in text.splitlines():
s = line.strip()
if s.startswith("container_name:"):
cname = s.split(":", 1)[1].strip()
line = f" container_name: {cname}_team{idx}"
elif s.startswith("hostname:"):
hname = s.split(":", 1)[1].strip()
if hname == name:
line = f" hostname: {name}_team{idx}"
else:
# sidecar hostname also suffixed to keep per-team network unique
line = f" hostname: {hname}_team{idx}"
out_lines.append(line)
text = "\n".join(out_lines)
# --- ports: rewrite ONLY the main challenge service's ports ---
# The main service is the one whose ports map to org/org+22.
# (sidecar "ports_chall" cases: gemas-notes validation-service exposes
# 12000:80 — handled by rewriting ANY "<org>:" / "<org+22>:" occurrence.)
text = re.sub(rf'"({org}):', f'"{tc}:', text)
text = re.sub(rf'"({org + 22}):', f'"{ts}:', text)
# --- build: -> image for MAIN only (only when the image exists) ---
# Replace the main service's build block with image: services-<name> so
# teams share one image. If that image was never built, KEEP the build
# block so `docker compose up --build` builds it instead of trying to
# pull a nonexistent local image.
use_image = _image_exists(f"services-{name}")
lines = text.splitlines()
i = 0
in_main = False
cur = None
out = []
while i < len(lines):
line = lines[i]
m = re.match(r"^ ([A-Za-z0-9_-]+):\s*$", line)
if m and not line.startswith(" "):
cur = m.group(1)
in_main = (cur == main)
out.append(line)
i += 1
continue
# inside a service block
if in_main and use_image and line.strip() == "build:":
# skip build block (context/args/dockerfile...) until next key at same indent
out.append(f" image: services-{name}")
i += 1
while i < len(lines) and (lines[i].startswith(" ") or lines[i].strip() == ""):
i += 1
continue
out.append(line)
i += 1
text = "\n".join(out)
# --- PASSWORD placeholder -> team password ---
text = re.sub(r"\$PASSWORD_" + str(org) + r"\b", passwords[name], text)
text = re.sub(r"PASSWORD_" + str(org) + r"\b", passwords[name], text)
# --- build context -> per-team challenge subdir ---
# Canonical templates are written for the SHARED services/ tree where a
# challenge's files sit in services/<name>/. The per-team compose lives in
# teamN/services/, so a bare `context: .` would resolve to the team dir
# (no Dockerfile). Point the MAIN service's build at ./<name>.
if re.search(r"^ build:$", text, re.M):
text = re.sub(r"^ build:\n context: \.$",
f" build:\n context: ./{name}", text, count=1, flags=re.M)
# --- flag volume normalization ---
# Replace any ./flag.txt / ../receiver/flags/<name>.txt with the per-team flag mount
text = re.sub(r"\./flag\.txt(:\w+)?", f"../receiver/flags/{name}.txt", text)
blocks.append(text)
header = "version: '3.8'\nservices:\n"
body = []
for b in blocks:
if not b.strip():
continue
# strip a leading "services:" header from each block (they are fragments)
b = re.sub(r"^services:\n", "", b)
body.append(b)
return header + "\n".join(body) + "\n"
def enabled_challenges() -> list:
return [c for c in _load_registry().get("challenges", []) if c.get("enabled")]