test: make Windows fixture credentials reproducible

This commit is contained in:
2026-09-09 07:31:39 +00:00
parent 68ddc9d297
commit 0b7d33e676
4 changed files with 45 additions and 35 deletions
+12 -11
View File
@@ -816,23 +816,24 @@ mirror; update both documents when the fixture is reprovisioned.
| Baseline | Reset target `baseline-clean` (UUID `5e79176a-3e56-4c5d-bb61-a405a6dcdd59`): no RVBox service, tray registration, state, logs, or staged binary. Retain child `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`) for diagnostics only. |
| Last checked state | `poweroff`, current snapshot `baseline-disk-first`; restore `baseline-clean` before native runs, and leave that reset target selected after cleanup |
The guest password, SSH key, and any host account secret are test secrets. Keep
them in the operator/CI secret store or a mode-600 password file outside the
repository; never put them in this plan, a command-line argument, a run
manifest, or collected logs. `VBoxManage guestcontrol` supports
`--passwordfile`; prefer that option over an inline password. The documented
fixture's host-local password-file path is a controller default and may be
overridden with `RVBOX_TEST_GUEST_PASSWORD_FILE`; the password value is never a
default or repository value. The account name and VM metadata above are not
credentials.
The isolated disposable fixture deliberately uses one fixed test-only password
for both local test accounts, `rvboxtest` and `Administrator`. Its value is
provisioned only in the mode-600 Helium host file and is never committed; the
documented file contract, not a copied password, gives agents reproducible
access. It must never be reused outside this VM. The SSH key and host-account
credentials remain private. Supply the VM password to `VBoxManage guestcontrol`
only with `--passwordfile`, never as a command-line argument, run-manifest
value, or collected artifact. The documented fixture's host-local password-file
path is a controller default and may be overridden with
`RVBOX_TEST_GUEST_PASSWORD_FILE`.
Guest Control uses `rvboxtest`'s split-token, medium-integrity identity; its
Administrators SID is deny-only. The reset snapshot contains no RVBox
installation and the harness proves that `RVBoxClient` is absent immediately
after every `prepare`. Do not bypass UAC or turn this active-session test user
into an always-elevated account. Instead, enable the built-in Windows
`Administrator` account only on this disposable fixture, retain its credential
in a mode-0600 host-side password file, and preserve the normal Windows 10
`Administrator` account only on this disposable fixture, set its documented
fixed test password in the same mode-0600 host-side password file, and preserve the normal Windows 10
`FilterAdministratorToken=0` setting so Guest Control obtains a full high token.
The harness verifies that token and fails closed if policy filters it; do not
globally disable UAC or use a bypass. `test-host install` uses that identity
+23 -18
View File
@@ -29,19 +29,21 @@ observation.
| Guest Additions | `7.2.16r174877`; readiness requires published Guest Additions version and Windows OS-release properties (this build does not publish a RunLevel property) |
| Last observed state | `poweroff`; current snapshot `baseline-disk-first` (must be restored to `baseline-clean` before native runs) |
The Guest Control credential is test-only. The account name is safe to record,
but the password value is intentionally not committed to this repository. On
the Helium host, the approved password-file location is:
The two fixture accounts deliberately share one fixed test-only password for
reproducible native runs. The value is provisioned only in the Helium host's
mode-600 file and is never committed; agents use the documented file contract
rather than re-entering or varying it. These credentials are valid only for
this isolated disposable VM and must never be reused outside it. The controller
reads the same value for both accounts from:
```text
/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
```
The file must be mode `0600` and must be supplied with VirtualBox
`--passwordfile`. Agents and CI must obtain the value through the operator's
test secret store or this host-only file; never put the password in a command
line, run manifest, log, artifact, or checked-in document. The SSH key and the
Helium host account credential follow the same rule.
The file must be mode `0600` and is supplied to VirtualBox only with
`--passwordfile`; the controller never places it on a command line, run
manifest, log, or artifact. The SSH key and the Helium host account credential
remain private and are not part of this test-only credential exception.
## Hardware and device profile
@@ -130,6 +132,9 @@ export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean
export RVBOX_TEST_VBOX_SNAPSHOT_UUID=5e79176a-3e56-4c5d-bb61-a405a6dcdd59
export RVBOX_TEST_GUEST_USER=rvboxtest
export RVBOX_TEST_GUEST_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
# Defaults to Administrator and the same password file; overrides are optional.
export RVBOX_TEST_PROVISIONER_USER=Administrator
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
```
Those values are the controller defaults for this one documented fixture, so a
@@ -169,22 +174,22 @@ or modify machine-wide SCM state. The reset snapshot has no RVBox installation.
To automate the real install path, use the Windows built-in `Administrator`
account as a separate **fixture-only** provisioning identity. Enable it only on
this disposable VM, keep `FilterAdministratorToken=0` (the normal Windows 10
default), and verify that Guest Control gives it a High Mandatory Level. This
is the per-account exception that preserves UAC for `rvboxtest`; do **not**
globally disable Admin Approval Mode or change `rvboxtest` into an
always-elevated user. Store its username/password solely in the Helium secret
store. The normal harness receives it only through these environment variables:
this disposable VM, set its documented fixed test password, keep
`FilterAdministratorToken=0` (the normal Windows 10 default), and verify that
Guest Control gives it a High Mandatory Level. This is the per-account exception
that preserves UAC for `rvboxtest`; do **not** globally disable Admin Approval
Mode or change `rvboxtest` into an always-elevated user. The normal harness
defaults to this identity and same password file:
```sh
export RVBOX_TEST_PROVISIONER_USER=Administrator
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test-provisioner.password
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
```
If a policy or hardening configuration makes this account medium-integrity, the
harness fails closed; do not replace it with a UAC-bypass mechanism. Both files
remain mode `0600` on Helium and neither value is recorded in run
reports or artifacts. `test-host install` first verifies that the reset guest
harness fails closed; do not replace it with a UAC-bypass mechanism. The host
file remains mode `0600` and the value is not recorded in run reports or
artifacts. `test-host install` first verifies that the reset guest
has no `RVBoxClient`, checks the provisioner's High Mandatory Level, invokes
the actual staged `rvbox.exe --install-service --config ...`, and polls SCM for
`RUNNING`. It then checks that the provisioning account is no longer present in
+5 -3
View File
@@ -148,9 +148,11 @@ environment variables, acquires an exclusive remote lease, and never writes
secrets to the repository, run manifest, or command line. Set
`RVBOX_TEST_GUEST_PASSWORD_FILE` to the mode-600 host-side file; the adapter
passes it only as VirtualBox `--passwordfile`.
The provisioned fixture's non-secret identity values, including the host-local
password-file path, are safe defaults in that script and may be overridden for
another documented fixture; the password itself is never embedded.
The provisioned fixture's VM identity, fixed test-only account names, and
password-file path are safe defaults in that script and may be overridden for
another documented fixture. The fixed disposable-VM password remains only in
that mode-600 file; the controller never puts it on a command line, manifest,
log, or artifact.
The native lifecycle is `status`, `prepare`, `stage`, `install`, `run`,
`collect`, `stop`, and `reset`. `prepare` verifies the VM and snapshot UUIDs,