FROM alpine:3.21@sha256:48b0309ca019d89d40f670aa1bc06e426dc0931948452e8491e3d65087abc07d

# Disable the pager for commands like git
ENV PAGER=''

# Set the working directory inside the container
WORKDIR /home/challenger

# Install necessary packages: git, python3, and socat
# The pins are fuzzy (=~MAJOR.MINOR) on purpose. The base image digest above is
# pinned, but apk still resolves against the rolling dl-cdn v3.21 branch, which
# only ever carries the newest patch build of each package and drops superseded
# ones. An exact =X.Y.Z-rN pin therefore rots the moment Alpine ships a patch
# release and the build fails with "unable to select packages". Do not re-pin
# these to exact versions.
RUN apk add --no-cache "git=~2.47" "python3=~3.12" "socat=~1.8"

# Copy all challenge files into the working directory
COPY . .

# Copy the flag file into the image
COPY flag.txt /flag.txt

# Make the scripts executable
RUN chmod +x entrypoint.sh exec.sh

# Add an unprivileged user to run the challenge
RUN adduser -D challenger
USER challenger

EXPOSE 1337

# Set the entrypoint to execute the 'exec.sh' script
ENTRYPOINT ["sh", "exec.sh"]
