diff --git a/docs/implementation-plan.v1.md b/docs/implementation-plan.v1.md index 9cf621a..5d223cc 100644 --- a/docs/implementation-plan.v1.md +++ b/docs/implementation-plan.v1.md @@ -816,23 +816,24 @@ mirror; update both documents when the fixture is reprovisioned. | Baseline | Reset target `baseline-clean` (UUID `5e79176a-3e56-4c5d-bb61-a405a6dcdd59`): no RVBox service, tray registration, state, logs, or staged binary. Retain child `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`) for diagnostics only. | | Last checked state | `poweroff`, current snapshot `baseline-disk-first`; restore `baseline-clean` before native runs, and leave that reset target selected after cleanup | -The guest password, SSH key, and any host account secret are test secrets. Keep -them in the operator/CI secret store or a mode-600 password file outside the -repository; never put them in this plan, a command-line argument, a run -manifest, or collected logs. `VBoxManage guestcontrol` supports -`--passwordfile`; prefer that option over an inline password. The documented -fixture's host-local password-file path is a controller default and may be -overridden with `RVBOX_TEST_GUEST_PASSWORD_FILE`; the password value is never a -default or repository value. The account name and VM metadata above are not -credentials. +The isolated disposable fixture deliberately uses one fixed test-only password +for both local test accounts, `rvboxtest` and `Administrator`. Its value is +provisioned only in the mode-600 Helium host file and is never committed; the +documented file contract, not a copied password, gives agents reproducible +access. It must never be reused outside this VM. The SSH key and host-account +credentials remain private. Supply the VM password to `VBoxManage guestcontrol` +only with `--passwordfile`, never as a command-line argument, run-manifest +value, or collected artifact. The documented fixture's host-local password-file +path is a controller default and may be overridden with +`RVBOX_TEST_GUEST_PASSWORD_FILE`. Guest Control uses `rvboxtest`'s split-token, medium-integrity identity; its Administrators SID is deny-only. The reset snapshot contains no RVBox installation and the harness proves that `RVBoxClient` is absent immediately after every `prepare`. Do not bypass UAC or turn this active-session test user into an always-elevated account. Instead, enable the built-in Windows -`Administrator` account only on this disposable fixture, retain its credential -in a mode-0600 host-side password file, and preserve the normal Windows 10 +`Administrator` account only on this disposable fixture, set its documented +fixed test password in the same mode-0600 host-side password file, and preserve the normal Windows 10 `FilterAdministratorToken=0` setting so Guest Control obtains a full high token. The harness verifies that token and fails closed if policy filters it; do not globally disable UAC or use a bypass. `test-host install` uses that identity diff --git a/docs/testing-vm.md b/docs/testing-vm.md index 1f99b4d..fd58919 100644 --- a/docs/testing-vm.md +++ b/docs/testing-vm.md @@ -29,19 +29,21 @@ observation. | Guest Additions | `7.2.16r174877`; readiness requires published Guest Additions version and Windows OS-release properties (this build does not publish a RunLevel property) | | Last observed state | `poweroff`; current snapshot `baseline-disk-first` (must be restored to `baseline-clean` before native runs) | -The Guest Control credential is test-only. The account name is safe to record, -but the password value is intentionally not committed to this repository. On -the Helium host, the approved password-file location is: +The two fixture accounts deliberately share one fixed test-only password for +reproducible native runs. The value is provisioned only in the Helium host's +mode-600 file and is never committed; agents use the documented file contract +rather than re-entering or varying it. These credentials are valid only for +this isolated disposable VM and must never be reused outside it. The controller +reads the same value for both accounts from: ```text /home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password ``` -The file must be mode `0600` and must be supplied with VirtualBox -`--passwordfile`. Agents and CI must obtain the value through the operator's -test secret store or this host-only file; never put the password in a command -line, run manifest, log, artifact, or checked-in document. The SSH key and the -Helium host account credential follow the same rule. +The file must be mode `0600` and is supplied to VirtualBox only with +`--passwordfile`; the controller never places it on a command line, run +manifest, log, or artifact. The SSH key and the Helium host account credential +remain private and are not part of this test-only credential exception. ## Hardware and device profile @@ -130,6 +132,9 @@ export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean export RVBOX_TEST_VBOX_SNAPSHOT_UUID=5e79176a-3e56-4c5d-bb61-a405a6dcdd59 export RVBOX_TEST_GUEST_USER=rvboxtest export RVBOX_TEST_GUEST_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password +# Defaults to Administrator and the same password file; overrides are optional. +export RVBOX_TEST_PROVISIONER_USER=Administrator +export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password ``` Those values are the controller defaults for this one documented fixture, so a @@ -169,22 +174,22 @@ or modify machine-wide SCM state. The reset snapshot has no RVBox installation. To automate the real install path, use the Windows built-in `Administrator` account as a separate **fixture-only** provisioning identity. Enable it only on -this disposable VM, keep `FilterAdministratorToken=0` (the normal Windows 10 -default), and verify that Guest Control gives it a High Mandatory Level. This -is the per-account exception that preserves UAC for `rvboxtest`; do **not** -globally disable Admin Approval Mode or change `rvboxtest` into an -always-elevated user. Store its username/password solely in the Helium secret -store. The normal harness receives it only through these environment variables: +this disposable VM, set its documented fixed test password, keep +`FilterAdministratorToken=0` (the normal Windows 10 default), and verify that +Guest Control gives it a High Mandatory Level. This is the per-account exception +that preserves UAC for `rvboxtest`; do **not** globally disable Admin Approval +Mode or change `rvboxtest` into an always-elevated user. The normal harness +defaults to this identity and same password file: ```sh export RVBOX_TEST_PROVISIONER_USER=Administrator -export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test-provisioner.password +export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password ``` If a policy or hardening configuration makes this account medium-integrity, the -harness fails closed; do not replace it with a UAC-bypass mechanism. Both files -remain mode `0600` on Helium and neither value is recorded in run -reports or artifacts. `test-host install` first verifies that the reset guest +harness fails closed; do not replace it with a UAC-bypass mechanism. The host +file remains mode `0600` and the value is not recorded in run reports or +artifacts. `test-host install` first verifies that the reset guest has no `RVBoxClient`, checks the provisioner's High Mandatory Level, invokes the actual staged `rvbox.exe --install-service --config ...`, and polls SCM for `RUNNING`. It then checks that the provisioning account is no longer present in diff --git a/docs/testing.md b/docs/testing.md index 310e388..17facd7 100644 --- a/docs/testing.md +++ b/docs/testing.md @@ -148,9 +148,11 @@ environment variables, acquires an exclusive remote lease, and never writes secrets to the repository, run manifest, or command line. Set `RVBOX_TEST_GUEST_PASSWORD_FILE` to the mode-600 host-side file; the adapter passes it only as VirtualBox `--passwordfile`. -The provisioned fixture's non-secret identity values, including the host-local -password-file path, are safe defaults in that script and may be overridden for -another documented fixture; the password itself is never embedded. +The provisioned fixture's VM identity, fixed test-only account names, and +password-file path are safe defaults in that script and may be overridden for +another documented fixture. The fixed disposable-VM password remains only in +that mode-600 file; the controller never puts it on a command line, manifest, +log, or artifact. The native lifecycle is `status`, `prepare`, `stage`, `install`, `run`, `collect`, `stop`, and `reset`. `prepare` verifies the VM and snapshot UUIDs, diff --git a/scripts/windows/test-host b/scripts/windows/test-host index 0904c1b..0b8a34c 100755 --- a/scripts/windows/test-host +++ b/scripts/windows/test-host @@ -31,7 +31,7 @@ Optional environment: RVBOX_TEST_VBOX_SNAPSHOT, RVBOX_TEST_VBOX_SNAPSHOT_UUID, RVBOX_TEST_GUEST_USER, RVBOX_TEST_GUEST_PASSWORD_FILE (overrides) RVBOX_TEST_PROVISIONER_USER, RVBOX_TEST_PROVISIONER_PASSWORD_FILE - (required by install; a fixture-only full-token administrator) + (default Administrator and the documented fixture password file) RVBOX_TEST_HOST_STAGE_ROOT (default /home/cabbage/.local/state/rvbox-test-runs) RVBOX_TEST_RUN_ROOT (default .test-runs/windows-vm) EOF @@ -104,8 +104,10 @@ if [ -n "$endpoint" ]; then safe_word endpoint "$endpoint"; fi : "${RVBOX_TEST_VBOX_SNAPSHOT_UUID:=5e79176a-3e56-4c5d-bb61-a405a6dcdd59}" : "${RVBOX_TEST_GUEST_USER:=rvboxtest}" : "${RVBOX_TEST_GUEST_PASSWORD_FILE:=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password}" -provisioner_user=${RVBOX_TEST_PROVISIONER_USER:-} -provisioner_password_file=${RVBOX_TEST_PROVISIONER_PASSWORD_FILE:-} +: "${RVBOX_TEST_PROVISIONER_USER:=Administrator}" +: "${RVBOX_TEST_PROVISIONER_PASSWORD_FILE:=$RVBOX_TEST_GUEST_PASSWORD_FILE}" +provisioner_user=$RVBOX_TEST_PROVISIONER_USER +provisioner_password_file=$RVBOX_TEST_PROVISIONER_PASSWORD_FILE for name in RVBOX_TEST_VBOX_HOST RVBOX_TEST_VBOX_VM RVBOX_TEST_VBOX_VM_UUID \ RVBOX_TEST_VBOX_SNAPSHOT RVBOX_TEST_VBOX_SNAPSHOT_UUID \