From 7a6e717c28a584a3fe274d80bd7fcccf4b88c2a9 Mon Sep 17 00:00:00 2001 From: asepharyana Date: Fri, 21 Aug 2026 13:51:31 +0700 Subject: [PATCH] docs: replace dummy docs with GEMASTIK 2026 Warmup writeups (ch1-14) - Deleted all previous dummy docs (defcon-quals-2024, infra/cloudflare-525, debugging/websocket-timeout, template, docs/*, notes/*, research/*) - Added 14 Gemastik warmup writeups covering encoding, stego, web, pwn, crypto - ch13: RSA small factors; ch14: RSA special integers via paper-search (GCD with paper appendix primes) - All flags recovered and documented with solution methods --- .../references/bun-source-ssh-deploy.md | 254 ++++++++++++++++++ content/docs/bullmq/workers.md | 68 ----- content/docs/caddy/reverse-proxy.md | 85 ------ content/docs/mcp/streamable-http.md | 56 ---- content/docs/websocket/contract.md | 43 --- content/notes/postgres/full-text-search.md | 65 ----- content/notes/typescript/patterns.md | 36 --- content/research/mcp/architecture.md | 34 --- content/writeups/ctf/_index.md | 26 -- .../writeups/ctf/defcon-quals-2024/_index.md | 31 --- .../pwn/pwn-100-ret2win-alignment.md | 122 --------- .../writeups/ctf/template/writeup-template.md | 76 ------ .../writeups/debugging/websocket-timeout.md | 36 --- .../writeups/gemastik-2026-warmup/_index.md | 48 ++++ .../gemastik-2026-warmup/ch1-sixty-four.md | 43 +++ .../gemastik-2026-warmup/ch10-call-me.md | 55 ++++ .../ch11-behind-the-picture.md | 24 ++ .../gemastik-2026-warmup/ch12-layers.md | 34 +++ .../gemastik-2026-warmup/ch13-slopped.md | 59 ++++ .../ch14-slopped-wave2.md | 86 ++++++ .../gemastik-2026-warmup/ch2-julius.md | 29 ++ .../gemastik-2026-warmup/ch3-needle.md | 24 ++ .../gemastik-2026-warmup/ch4-say-cheese.md | 24 ++ .../gemastik-2026-warmup/ch5-nothing-here.md | 29 ++ .../gemastik-2026-warmup/ch6-sweet-cookie.md | 29 ++ .../gemastik-2026-warmup/ch7-open-book.md | 28 ++ .../ch8-back-and-forth.md | 29 ++ .../gemastik-2026-warmup/ch9-are-you-admin.md | 46 ++++ content/writeups/infra/cloudflare-525.md | 56 ---- 29 files changed, 841 insertions(+), 734 deletions(-) create mode 100644 .hermes/skills/devops/nix-ci-deploy/references/bun-source-ssh-deploy.md delete mode 100644 content/docs/bullmq/workers.md delete mode 100644 content/docs/caddy/reverse-proxy.md delete mode 100644 content/docs/mcp/streamable-http.md delete mode 100644 content/docs/websocket/contract.md delete mode 100644 content/notes/postgres/full-text-search.md delete mode 100644 content/notes/typescript/patterns.md delete mode 100644 content/research/mcp/architecture.md delete mode 100644 content/writeups/ctf/_index.md delete mode 100644 content/writeups/ctf/defcon-quals-2024/_index.md delete mode 100644 content/writeups/ctf/defcon-quals-2024/pwn/pwn-100-ret2win-alignment.md delete mode 100644 content/writeups/ctf/template/writeup-template.md delete mode 100644 content/writeups/debugging/websocket-timeout.md create mode 100644 content/writeups/gemastik-2026-warmup/_index.md create mode 100644 content/writeups/gemastik-2026-warmup/ch1-sixty-four.md create mode 100644 content/writeups/gemastik-2026-warmup/ch10-call-me.md create mode 100644 content/writeups/gemastik-2026-warmup/ch11-behind-the-picture.md create mode 100644 content/writeups/gemastik-2026-warmup/ch12-layers.md create mode 100644 content/writeups/gemastik-2026-warmup/ch13-slopped.md create mode 100644 content/writeups/gemastik-2026-warmup/ch14-slopped-wave2.md create mode 100644 content/writeups/gemastik-2026-warmup/ch2-julius.md create mode 100644 content/writeups/gemastik-2026-warmup/ch3-needle.md create mode 100644 content/writeups/gemastik-2026-warmup/ch4-say-cheese.md create mode 100644 content/writeups/gemastik-2026-warmup/ch5-nothing-here.md create mode 100644 content/writeups/gemastik-2026-warmup/ch6-sweet-cookie.md create mode 100644 content/writeups/gemastik-2026-warmup/ch7-open-book.md create mode 100644 content/writeups/gemastik-2026-warmup/ch8-back-and-forth.md create mode 100644 content/writeups/gemastik-2026-warmup/ch9-are-you-admin.md delete mode 100644 content/writeups/infra/cloudflare-525.md diff --git a/.hermes/skills/devops/nix-ci-deploy/references/bun-source-ssh-deploy.md b/.hermes/skills/devops/nix-ci-deploy/references/bun-source-ssh-deploy.md new file mode 100644 index 0000000..a904165 --- /dev/null +++ b/.hermes/skills/devops/nix-ci-deploy/references/bun-source-ssh-deploy.md @@ -0,0 +1,254 @@ +# SSH deploy to bun-source services (not Nix): gotchas + +This repo (`asepharyana/mcpedia`) deploys **bun source** via systemd — NOT via +Nix like GMW. The pattern is: CI builds in GitHub Actions → upload artifact → +deploy job downloads artifact → SCP tarball to VPS → SSH → git pull + unpack + +index + `systemctl restart`. The VPS does NOT build. + +## Gotchas (learned during mcpedia deploy setup, 2026-08-20/21) + +### 1. SSH host = public IP, NOT Tailscale IP + +The VPS appears in `~/.ssh/config` as `Host orange → HostName 100.79.111.61`. +That IP is a **Tailscale `tailscale0` interface address** in the CGNAT range +(`100.64.0.0/10`). GitHub Actions runners are NOT on the Tailscale network, so +they get `Connection timed out` (dropped at the network layer, not refused). + +**Fix:** Use the VPS's real public IP (`45.127.35.244`, discovered via +`curl https://api.ipify.org` from the VPS). Port 22 is open in iptables +(`ACCEPT tcp dpt:22` from `0.0.0.0/0`). + +### 2. SSH key MUST be stored directly from file (not shell variable) + +Storing the deploy key via a shell variable corrupts it: + +```bash +# ❌ WRONG — newlines get mangled by the shell → "ssh: no key found" +PRIV_KEY=$(cat keyfile) +gh secret set SSH_DEPLOY_KEY --body "$PRIV_KEY" + +# ✅ CORRECT — pipe the file directly so GitHub preserves all bytes +cat keyfile | gh secret set SSH_DEPLOY_KEY --repo asepharyana/mcpedia +``` + +Symptom: `appleboy/ssh-action` fails with +`ssh.ParsePrivateKey: ssh: no key found`. + +### 3. Use `appleboy/ssh-action@v1` (not `@v1.1.0`) + +- `@v1.1.0` (very old) has a key-parsing bug that rejects valid keys + (`ssh.ParsePrivateKey: ssh: no key found`). +- `@v1` (latest) handles OpenSSH ed25519 keys correctly. + +### 4. `appleboy/ssh-action` needs explicit `envs` to pass through secret-derived vars + +The `envs` parameter passes environment variables to the remote script. +Include any secret you reference in the script: +```yaml +envs: SSH_DEPLOY_HOST # passes SSH_DEPLOY_HOST into the remote script +``` +Without it, `echo $SSH_DEPLOY_HOST` on the VPS returns empty even though the +action connected. + +### 5. Always pass `-o IdentitiesOnly=yes` + +Without it, SSH offers ALL loaded identities (deploy key + default keys) and the +server may reject after "Too many authentication failures". `appleboy/ssh-action` +handles this internally via the `key` input, but if you use raw `ssh` add +`-o IdentitiesOnly=yes`. + +### 6. GitHub `workflow_run` does NOT carry the push commit SHA + +`workflow_run` events fire after CI completes, but `actions/checkout` checks out +the **default branch tip**, not the specific commit. This is fine for deploy +(the script does `git pull origin main` anyway), but verify the checkout ref +matches what CI built if you rely on it. + +### 7. DB migrations: `db:push` prompt is non-interactive-unfriendly in SSH deploy + +When the schema includes a new column (e.g. adding `extra_fields JSONB`), +`drizzle-kit push` in the SSH deploy script needs to be run. Two issues: + +- **`--strict` mode (config default)**: `drizzle.config.ts` has `strict: true`, + which makes `drizzle-kit push` prompt `No, abort / Yes, I want to execute all + statements`. In a non-interactive SSH script (no TTY), the prompt never receives + input and the command times out → SIGTERM → exit code 124 → deploy fails. + `set -e` then kills the whole deploy. +- **`bun run