test: make Windows fixture credentials reproducible
This commit is contained in:
+23
-18
@@ -29,19 +29,21 @@ observation.
|
||||
| Guest Additions | `7.2.16r174877`; readiness requires published Guest Additions version and Windows OS-release properties (this build does not publish a RunLevel property) |
|
||||
| Last observed state | `poweroff`; current snapshot `baseline-disk-first` (must be restored to `baseline-clean` before native runs) |
|
||||
|
||||
The Guest Control credential is test-only. The account name is safe to record,
|
||||
but the password value is intentionally not committed to this repository. On
|
||||
the Helium host, the approved password-file location is:
|
||||
The two fixture accounts deliberately share one fixed test-only password for
|
||||
reproducible native runs. The value is provisioned only in the Helium host's
|
||||
mode-600 file and is never committed; agents use the documented file contract
|
||||
rather than re-entering or varying it. These credentials are valid only for
|
||||
this isolated disposable VM and must never be reused outside it. The controller
|
||||
reads the same value for both accounts from:
|
||||
|
||||
```text
|
||||
/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
|
||||
```
|
||||
|
||||
The file must be mode `0600` and must be supplied with VirtualBox
|
||||
`--passwordfile`. Agents and CI must obtain the value through the operator's
|
||||
test secret store or this host-only file; never put the password in a command
|
||||
line, run manifest, log, artifact, or checked-in document. The SSH key and the
|
||||
Helium host account credential follow the same rule.
|
||||
The file must be mode `0600` and is supplied to VirtualBox only with
|
||||
`--passwordfile`; the controller never places it on a command line, run
|
||||
manifest, log, or artifact. The SSH key and the Helium host account credential
|
||||
remain private and are not part of this test-only credential exception.
|
||||
|
||||
## Hardware and device profile
|
||||
|
||||
@@ -130,6 +132,9 @@ export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean
|
||||
export RVBOX_TEST_VBOX_SNAPSHOT_UUID=5e79176a-3e56-4c5d-bb61-a405a6dcdd59
|
||||
export RVBOX_TEST_GUEST_USER=rvboxtest
|
||||
export RVBOX_TEST_GUEST_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
|
||||
# Defaults to Administrator and the same password file; overrides are optional.
|
||||
export RVBOX_TEST_PROVISIONER_USER=Administrator
|
||||
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
|
||||
```
|
||||
|
||||
Those values are the controller defaults for this one documented fixture, so a
|
||||
@@ -169,22 +174,22 @@ or modify machine-wide SCM state. The reset snapshot has no RVBox installation.
|
||||
|
||||
To automate the real install path, use the Windows built-in `Administrator`
|
||||
account as a separate **fixture-only** provisioning identity. Enable it only on
|
||||
this disposable VM, keep `FilterAdministratorToken=0` (the normal Windows 10
|
||||
default), and verify that Guest Control gives it a High Mandatory Level. This
|
||||
is the per-account exception that preserves UAC for `rvboxtest`; do **not**
|
||||
globally disable Admin Approval Mode or change `rvboxtest` into an
|
||||
always-elevated user. Store its username/password solely in the Helium secret
|
||||
store. The normal harness receives it only through these environment variables:
|
||||
this disposable VM, set its documented fixed test password, keep
|
||||
`FilterAdministratorToken=0` (the normal Windows 10 default), and verify that
|
||||
Guest Control gives it a High Mandatory Level. This is the per-account exception
|
||||
that preserves UAC for `rvboxtest`; do **not** globally disable Admin Approval
|
||||
Mode or change `rvboxtest` into an always-elevated user. The normal harness
|
||||
defaults to this identity and same password file:
|
||||
|
||||
```sh
|
||||
export RVBOX_TEST_PROVISIONER_USER=Administrator
|
||||
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test-provisioner.password
|
||||
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
|
||||
```
|
||||
|
||||
If a policy or hardening configuration makes this account medium-integrity, the
|
||||
harness fails closed; do not replace it with a UAC-bypass mechanism. Both files
|
||||
remain mode `0600` on Helium and neither value is recorded in run
|
||||
reports or artifacts. `test-host install` first verifies that the reset guest
|
||||
harness fails closed; do not replace it with a UAC-bypass mechanism. The host
|
||||
file remains mode `0600` and the value is not recorded in run reports or
|
||||
artifacts. `test-host install` first verifies that the reset guest
|
||||
has no `RVBoxClient`, checks the provisioner's High Mandatory Level, invokes
|
||||
the actual staged `rvbox.exe --install-service --config ...`, and polls SCM for
|
||||
`RUNNING`. It then checks that the provisioning account is no longer present in
|
||||
|
||||
Reference in New Issue
Block a user