forked from jokeez/hackme
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathbuild_security_task_pack.sh
More file actions
executable file
·98 lines (85 loc) · 2.69 KB
/
Copy pathbuild_security_task_pack.sh
File metadata and controls
executable file
·98 lines (85 loc) · 2.69 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
#!/usr/bin/env bash
set -euo pipefail
ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
SEC_SRC="$ROOT_DIR/tasks/sources/security"
OUT_DIR="$ROOT_DIR/tasks/artifacts/security"
MANIFEST_DIR="$ROOT_DIR/tasks/manifests/security"
mkdir -p "$OUT_DIR" "$MANIFEST_DIR"
require_cmd() {
command -v "$1" >/dev/null 2>&1 || {
echo "Missing dependency: $1" >&2
exit 1
}
}
require_cmd rustc
require_cmd clang
require_cmd sha256sum
build_rust() {
local name="$1"
local src="$SEC_SRC/rust_${name}.rs"
local out="$OUT_DIR/rust_${name}.wasm"
rustc \
--target wasm32-unknown-unknown \
-C panic=abort -C opt-level=z -C lto=fat \
--crate-type=cdylib \
"$src" -o "$out"
}
build_cpp() {
local name="$1"
local src="$SEC_SRC/cpp_${name}.cpp"
local out="$OUT_DIR/cpp_${name}.wasm"
clang \
--target=wasm32 \
-O3 -nostdlib \
-Wl,--no-entry -Wl,--export=check -Wl,--strip-all \
-o "$out" "$src"
}
mk_manifest() {
local id="$1"
local payer="$2"
local path="$3"
local hash="$4"
cat > "$MANIFEST_DIR/${id}.json" <<EOF
{
"id":"$id",
"kind":"synthetic_poh_v1",
"reward_hmc":0.02,
"difficulty_score":25,
"target_solves":3,
"payer_ref":"$payer",
"wasm_artifact_path":"security/$(basename "$path")",
"artifact_hash":"$hash"
}
EOF
}
tasks=(bounds_guard overflow_guard state_transition_guard script_push_bounds_guard)
# Phase 2 B2B bytes guards — required by go test (fluxtap_wasm_compare, sandbox, wizard packs).
fuzz_guard_tasks=(fluxtap_filter_bytes_guard tracefuse_detector_bytes_guard parser_expat_bytes_guard)
echo "Building security task pack..."
for t in "${tasks[@]}"; do
build_rust "$t"
build_cpp "$t"
done
echo "Building Phase 2 B2B fuzz guard wasm..."
for t in "${fuzz_guard_tasks[@]}"; do
build_rust "$t"
done
echo "Building Scan smoke guard aliases..."
bash "$ROOT_DIR/scripts/ops/build_scan_smoke_guards.sh"
echo "Generating manifests..."
for t in "${tasks[@]}"; do
rust_path="$OUT_DIR/rust_${t}.wasm"
cpp_path="$OUT_DIR/cpp_${t}.wasm"
rust_hash="$(sha256sum "$rust_path" | awk '{print $1}')"
cpp_hash="$(sha256sum "$cpp_path" | awk '{print $1}')"
mk_manifest "order-rust-${t}-001" "company:rust-${t}" "$rust_path" "$rust_hash"
mk_manifest "order-cpp-${t}-001" "company:cpp-${t}" "$cpp_path" "$cpp_hash"
done
echo
echo "Done."
echo "Artifacts dir: $OUT_DIR"
echo "Manifests dir: $MANIFEST_DIR"
echo
echo "Submit examples:"
echo " curl -s -X POST http://127.0.0.1:8080/api/tasks -H 'Content-Type: application/json' --data-binary @${MANIFEST_DIR}/order-rust-bounds_guard-001.json | jq"
echo " curl -s -X POST http://127.0.0.1:8080/api/tasks -H 'Content-Type: application/json' --data-binary @${MANIFEST_DIR}/order-cpp-bounds_guard-001.json | jq"