test: make Windows fixture credentials reproducible

This commit is contained in:
2026-09-09 07:31:39 +00:00
parent 68ddc9d297
commit 0b7d33e676
4 changed files with 45 additions and 35 deletions
+12 -11
View File
@@ -816,23 +816,24 @@ mirror; update both documents when the fixture is reprovisioned.
| Baseline | Reset target `baseline-clean` (UUID `5e79176a-3e56-4c5d-bb61-a405a6dcdd59`): no RVBox service, tray registration, state, logs, or staged binary. Retain child `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`) for diagnostics only. |
| Last checked state | `poweroff`, current snapshot `baseline-disk-first`; restore `baseline-clean` before native runs, and leave that reset target selected after cleanup |
The guest password, SSH key, and any host account secret are test secrets. Keep
them in the operator/CI secret store or a mode-600 password file outside the
repository; never put them in this plan, a command-line argument, a run
manifest, or collected logs. `VBoxManage guestcontrol` supports
`--passwordfile`; prefer that option over an inline password. The documented
fixture's host-local password-file path is a controller default and may be
overridden with `RVBOX_TEST_GUEST_PASSWORD_FILE`; the password value is never a
default or repository value. The account name and VM metadata above are not
credentials.
The isolated disposable fixture deliberately uses one fixed test-only password
for both local test accounts, `rvboxtest` and `Administrator`. Its value is
provisioned only in the mode-600 Helium host file and is never committed; the
documented file contract, not a copied password, gives agents reproducible
access. It must never be reused outside this VM. The SSH key and host-account
credentials remain private. Supply the VM password to `VBoxManage guestcontrol`
only with `--passwordfile`, never as a command-line argument, run-manifest
value, or collected artifact. The documented fixture's host-local password-file
path is a controller default and may be overridden with
`RVBOX_TEST_GUEST_PASSWORD_FILE`.
Guest Control uses `rvboxtest`'s split-token, medium-integrity identity; its
Administrators SID is deny-only. The reset snapshot contains no RVBox
installation and the harness proves that `RVBoxClient` is absent immediately
after every `prepare`. Do not bypass UAC or turn this active-session test user
into an always-elevated account. Instead, enable the built-in Windows
`Administrator` account only on this disposable fixture, retain its credential
in a mode-0600 host-side password file, and preserve the normal Windows 10
`Administrator` account only on this disposable fixture, set its documented
fixed test password in the same mode-0600 host-side password file, and preserve the normal Windows 10
`FilterAdministratorToken=0` setting so Guest Control obtains a full high token.
The harness verifies that token and fails closed if policy filters it; do not
globally disable UAC or use a bypass. `test-host install` uses that identity