test: make Windows fixture credentials reproducible
This commit is contained in:
@@ -816,23 +816,24 @@ mirror; update both documents when the fixture is reprovisioned.
|
||||
| Baseline | Reset target `baseline-clean` (UUID `5e79176a-3e56-4c5d-bb61-a405a6dcdd59`): no RVBox service, tray registration, state, logs, or staged binary. Retain child `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`) for diagnostics only. |
|
||||
| Last checked state | `poweroff`, current snapshot `baseline-disk-first`; restore `baseline-clean` before native runs, and leave that reset target selected after cleanup |
|
||||
|
||||
The guest password, SSH key, and any host account secret are test secrets. Keep
|
||||
them in the operator/CI secret store or a mode-600 password file outside the
|
||||
repository; never put them in this plan, a command-line argument, a run
|
||||
manifest, or collected logs. `VBoxManage guestcontrol` supports
|
||||
`--passwordfile`; prefer that option over an inline password. The documented
|
||||
fixture's host-local password-file path is a controller default and may be
|
||||
overridden with `RVBOX_TEST_GUEST_PASSWORD_FILE`; the password value is never a
|
||||
default or repository value. The account name and VM metadata above are not
|
||||
credentials.
|
||||
The isolated disposable fixture deliberately uses one fixed test-only password
|
||||
for both local test accounts, `rvboxtest` and `Administrator`. Its value is
|
||||
provisioned only in the mode-600 Helium host file and is never committed; the
|
||||
documented file contract, not a copied password, gives agents reproducible
|
||||
access. It must never be reused outside this VM. The SSH key and host-account
|
||||
credentials remain private. Supply the VM password to `VBoxManage guestcontrol`
|
||||
only with `--passwordfile`, never as a command-line argument, run-manifest
|
||||
value, or collected artifact. The documented fixture's host-local password-file
|
||||
path is a controller default and may be overridden with
|
||||
`RVBOX_TEST_GUEST_PASSWORD_FILE`.
|
||||
|
||||
Guest Control uses `rvboxtest`'s split-token, medium-integrity identity; its
|
||||
Administrators SID is deny-only. The reset snapshot contains no RVBox
|
||||
installation and the harness proves that `RVBoxClient` is absent immediately
|
||||
after every `prepare`. Do not bypass UAC or turn this active-session test user
|
||||
into an always-elevated account. Instead, enable the built-in Windows
|
||||
`Administrator` account only on this disposable fixture, retain its credential
|
||||
in a mode-0600 host-side password file, and preserve the normal Windows 10
|
||||
`Administrator` account only on this disposable fixture, set its documented
|
||||
fixed test password in the same mode-0600 host-side password file, and preserve the normal Windows 10
|
||||
`FilterAdministratorToken=0` setting so Guest Control obtains a full high token.
|
||||
The harness verifies that token and fails closed if policy filters it; do not
|
||||
globally disable UAC or use a bypass. `test-host install` uses that identity
|
||||
|
||||
+23
-18
@@ -29,19 +29,21 @@ observation.
|
||||
| Guest Additions | `7.2.16r174877`; readiness requires published Guest Additions version and Windows OS-release properties (this build does not publish a RunLevel property) |
|
||||
| Last observed state | `poweroff`; current snapshot `baseline-disk-first` (must be restored to `baseline-clean` before native runs) |
|
||||
|
||||
The Guest Control credential is test-only. The account name is safe to record,
|
||||
but the password value is intentionally not committed to this repository. On
|
||||
the Helium host, the approved password-file location is:
|
||||
The two fixture accounts deliberately share one fixed test-only password for
|
||||
reproducible native runs. The value is provisioned only in the Helium host's
|
||||
mode-600 file and is never committed; agents use the documented file contract
|
||||
rather than re-entering or varying it. These credentials are valid only for
|
||||
this isolated disposable VM and must never be reused outside it. The controller
|
||||
reads the same value for both accounts from:
|
||||
|
||||
```text
|
||||
/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
|
||||
```
|
||||
|
||||
The file must be mode `0600` and must be supplied with VirtualBox
|
||||
`--passwordfile`. Agents and CI must obtain the value through the operator's
|
||||
test secret store or this host-only file; never put the password in a command
|
||||
line, run manifest, log, artifact, or checked-in document. The SSH key and the
|
||||
Helium host account credential follow the same rule.
|
||||
The file must be mode `0600` and is supplied to VirtualBox only with
|
||||
`--passwordfile`; the controller never places it on a command line, run
|
||||
manifest, log, or artifact. The SSH key and the Helium host account credential
|
||||
remain private and are not part of this test-only credential exception.
|
||||
|
||||
## Hardware and device profile
|
||||
|
||||
@@ -130,6 +132,9 @@ export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean
|
||||
export RVBOX_TEST_VBOX_SNAPSHOT_UUID=5e79176a-3e56-4c5d-bb61-a405a6dcdd59
|
||||
export RVBOX_TEST_GUEST_USER=rvboxtest
|
||||
export RVBOX_TEST_GUEST_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
|
||||
# Defaults to Administrator and the same password file; overrides are optional.
|
||||
export RVBOX_TEST_PROVISIONER_USER=Administrator
|
||||
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
|
||||
```
|
||||
|
||||
Those values are the controller defaults for this one documented fixture, so a
|
||||
@@ -169,22 +174,22 @@ or modify machine-wide SCM state. The reset snapshot has no RVBox installation.
|
||||
|
||||
To automate the real install path, use the Windows built-in `Administrator`
|
||||
account as a separate **fixture-only** provisioning identity. Enable it only on
|
||||
this disposable VM, keep `FilterAdministratorToken=0` (the normal Windows 10
|
||||
default), and verify that Guest Control gives it a High Mandatory Level. This
|
||||
is the per-account exception that preserves UAC for `rvboxtest`; do **not**
|
||||
globally disable Admin Approval Mode or change `rvboxtest` into an
|
||||
always-elevated user. Store its username/password solely in the Helium secret
|
||||
store. The normal harness receives it only through these environment variables:
|
||||
this disposable VM, set its documented fixed test password, keep
|
||||
`FilterAdministratorToken=0` (the normal Windows 10 default), and verify that
|
||||
Guest Control gives it a High Mandatory Level. This is the per-account exception
|
||||
that preserves UAC for `rvboxtest`; do **not** globally disable Admin Approval
|
||||
Mode or change `rvboxtest` into an always-elevated user. The normal harness
|
||||
defaults to this identity and same password file:
|
||||
|
||||
```sh
|
||||
export RVBOX_TEST_PROVISIONER_USER=Administrator
|
||||
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test-provisioner.password
|
||||
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
|
||||
```
|
||||
|
||||
If a policy or hardening configuration makes this account medium-integrity, the
|
||||
harness fails closed; do not replace it with a UAC-bypass mechanism. Both files
|
||||
remain mode `0600` on Helium and neither value is recorded in run
|
||||
reports or artifacts. `test-host install` first verifies that the reset guest
|
||||
harness fails closed; do not replace it with a UAC-bypass mechanism. The host
|
||||
file remains mode `0600` and the value is not recorded in run reports or
|
||||
artifacts. `test-host install` first verifies that the reset guest
|
||||
has no `RVBoxClient`, checks the provisioner's High Mandatory Level, invokes
|
||||
the actual staged `rvbox.exe --install-service --config ...`, and polls SCM for
|
||||
`RUNNING`. It then checks that the provisioning account is no longer present in
|
||||
|
||||
+5
-3
@@ -148,9 +148,11 @@ environment variables, acquires an exclusive remote lease, and never writes
|
||||
secrets to the repository, run manifest, or command line. Set
|
||||
`RVBOX_TEST_GUEST_PASSWORD_FILE` to the mode-600 host-side file; the adapter
|
||||
passes it only as VirtualBox `--passwordfile`.
|
||||
The provisioned fixture's non-secret identity values, including the host-local
|
||||
password-file path, are safe defaults in that script and may be overridden for
|
||||
another documented fixture; the password itself is never embedded.
|
||||
The provisioned fixture's VM identity, fixed test-only account names, and
|
||||
password-file path are safe defaults in that script and may be overridden for
|
||||
another documented fixture. The fixed disposable-VM password remains only in
|
||||
that mode-600 file; the controller never puts it on a command line, manifest,
|
||||
log, or artifact.
|
||||
|
||||
The native lifecycle is `status`, `prepare`, `stage`, `install`, `run`,
|
||||
`collect`, `stop`, and `reset`. `prepare` verifies the VM and snapshot UUIDs,
|
||||
|
||||
@@ -31,7 +31,7 @@ Optional environment:
|
||||
RVBOX_TEST_VBOX_SNAPSHOT, RVBOX_TEST_VBOX_SNAPSHOT_UUID,
|
||||
RVBOX_TEST_GUEST_USER, RVBOX_TEST_GUEST_PASSWORD_FILE (overrides)
|
||||
RVBOX_TEST_PROVISIONER_USER, RVBOX_TEST_PROVISIONER_PASSWORD_FILE
|
||||
(required by install; a fixture-only full-token administrator)
|
||||
(default Administrator and the documented fixture password file)
|
||||
RVBOX_TEST_HOST_STAGE_ROOT (default /home/cabbage/.local/state/rvbox-test-runs)
|
||||
RVBOX_TEST_RUN_ROOT (default .test-runs/windows-vm)
|
||||
EOF
|
||||
@@ -104,8 +104,10 @@ if [ -n "$endpoint" ]; then safe_word endpoint "$endpoint"; fi
|
||||
: "${RVBOX_TEST_VBOX_SNAPSHOT_UUID:=5e79176a-3e56-4c5d-bb61-a405a6dcdd59}"
|
||||
: "${RVBOX_TEST_GUEST_USER:=rvboxtest}"
|
||||
: "${RVBOX_TEST_GUEST_PASSWORD_FILE:=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password}"
|
||||
provisioner_user=${RVBOX_TEST_PROVISIONER_USER:-}
|
||||
provisioner_password_file=${RVBOX_TEST_PROVISIONER_PASSWORD_FILE:-}
|
||||
: "${RVBOX_TEST_PROVISIONER_USER:=Administrator}"
|
||||
: "${RVBOX_TEST_PROVISIONER_PASSWORD_FILE:=$RVBOX_TEST_GUEST_PASSWORD_FILE}"
|
||||
provisioner_user=$RVBOX_TEST_PROVISIONER_USER
|
||||
provisioner_password_file=$RVBOX_TEST_PROVISIONER_PASSWORD_FILE
|
||||
|
||||
for name in RVBOX_TEST_VBOX_HOST RVBOX_TEST_VBOX_VM RVBOX_TEST_VBOX_VM_UUID \
|
||||
RVBOX_TEST_VBOX_SNAPSHOT RVBOX_TEST_VBOX_SNAPSHOT_UUID \
|
||||
|
||||
Reference in New Issue
Block a user