test: make Windows fixture credentials reproducible

This commit is contained in:
2026-09-09 07:31:39 +00:00
parent 68ddc9d297
commit 0b7d33e676
4 changed files with 45 additions and 35 deletions
+23 -18
View File
@@ -29,19 +29,21 @@ observation.
| Guest Additions | `7.2.16r174877`; readiness requires published Guest Additions version and Windows OS-release properties (this build does not publish a RunLevel property) |
| Last observed state | `poweroff`; current snapshot `baseline-disk-first` (must be restored to `baseline-clean` before native runs) |
The Guest Control credential is test-only. The account name is safe to record,
but the password value is intentionally not committed to this repository. On
the Helium host, the approved password-file location is:
The two fixture accounts deliberately share one fixed test-only password for
reproducible native runs. The value is provisioned only in the Helium host's
mode-600 file and is never committed; agents use the documented file contract
rather than re-entering or varying it. These credentials are valid only for
this isolated disposable VM and must never be reused outside it. The controller
reads the same value for both accounts from:
```text
/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
```
The file must be mode `0600` and must be supplied with VirtualBox
`--passwordfile`. Agents and CI must obtain the value through the operator's
test secret store or this host-only file; never put the password in a command
line, run manifest, log, artifact, or checked-in document. The SSH key and the
Helium host account credential follow the same rule.
The file must be mode `0600` and is supplied to VirtualBox only with
`--passwordfile`; the controller never places it on a command line, run
manifest, log, or artifact. The SSH key and the Helium host account credential
remain private and are not part of this test-only credential exception.
## Hardware and device profile
@@ -130,6 +132,9 @@ export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean
export RVBOX_TEST_VBOX_SNAPSHOT_UUID=5e79176a-3e56-4c5d-bb61-a405a6dcdd59
export RVBOX_TEST_GUEST_USER=rvboxtest
export RVBOX_TEST_GUEST_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
# Defaults to Administrator and the same password file; overrides are optional.
export RVBOX_TEST_PROVISIONER_USER=Administrator
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
```
Those values are the controller defaults for this one documented fixture, so a
@@ -169,22 +174,22 @@ or modify machine-wide SCM state. The reset snapshot has no RVBox installation.
To automate the real install path, use the Windows built-in `Administrator`
account as a separate **fixture-only** provisioning identity. Enable it only on
this disposable VM, keep `FilterAdministratorToken=0` (the normal Windows 10
default), and verify that Guest Control gives it a High Mandatory Level. This
is the per-account exception that preserves UAC for `rvboxtest`; do **not**
globally disable Admin Approval Mode or change `rvboxtest` into an
always-elevated user. Store its username/password solely in the Helium secret
store. The normal harness receives it only through these environment variables:
this disposable VM, set its documented fixed test password, keep
`FilterAdministratorToken=0` (the normal Windows 10 default), and verify that
Guest Control gives it a High Mandatory Level. This is the per-account exception
that preserves UAC for `rvboxtest`; do **not** globally disable Admin Approval
Mode or change `rvboxtest` into an always-elevated user. The normal harness
defaults to this identity and same password file:
```sh
export RVBOX_TEST_PROVISIONER_USER=Administrator
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test-provisioner.password
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
```
If a policy or hardening configuration makes this account medium-integrity, the
harness fails closed; do not replace it with a UAC-bypass mechanism. Both files
remain mode `0600` on Helium and neither value is recorded in run
reports or artifacts. `test-host install` first verifies that the reset guest
harness fails closed; do not replace it with a UAC-bypass mechanism. The host
file remains mode `0600` and the value is not recorded in run reports or
artifacts. `test-host install` first verifies that the reset guest
has no `RVBoxClient`, checks the provisioner's High Mandatory Level, invokes
the actual staged `rvbox.exe --install-service --config ...`, and polls SCM for
`RUNNING`. It then checks that the provisioning account is no longer present in