test: make Windows fixture credentials reproducible

This commit is contained in:
2026-09-09 07:31:39 +00:00
parent 68ddc9d297
commit 0b7d33e676
4 changed files with 45 additions and 35 deletions
+12 -11
View File
@@ -816,23 +816,24 @@ mirror; update both documents when the fixture is reprovisioned.
| Baseline | Reset target `baseline-clean` (UUID `5e79176a-3e56-4c5d-bb61-a405a6dcdd59`): no RVBox service, tray registration, state, logs, or staged binary. Retain child `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`) for diagnostics only. | | Baseline | Reset target `baseline-clean` (UUID `5e79176a-3e56-4c5d-bb61-a405a6dcdd59`): no RVBox service, tray registration, state, logs, or staged binary. Retain child `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`) for diagnostics only. |
| Last checked state | `poweroff`, current snapshot `baseline-disk-first`; restore `baseline-clean` before native runs, and leave that reset target selected after cleanup | | Last checked state | `poweroff`, current snapshot `baseline-disk-first`; restore `baseline-clean` before native runs, and leave that reset target selected after cleanup |
The guest password, SSH key, and any host account secret are test secrets. Keep The isolated disposable fixture deliberately uses one fixed test-only password
them in the operator/CI secret store or a mode-600 password file outside the for both local test accounts, `rvboxtest` and `Administrator`. Its value is
repository; never put them in this plan, a command-line argument, a run provisioned only in the mode-600 Helium host file and is never committed; the
manifest, or collected logs. `VBoxManage guestcontrol` supports documented file contract, not a copied password, gives agents reproducible
`--passwordfile`; prefer that option over an inline password. The documented access. It must never be reused outside this VM. The SSH key and host-account
fixture's host-local password-file path is a controller default and may be credentials remain private. Supply the VM password to `VBoxManage guestcontrol`
overridden with `RVBOX_TEST_GUEST_PASSWORD_FILE`; the password value is never a only with `--passwordfile`, never as a command-line argument, run-manifest
default or repository value. The account name and VM metadata above are not value, or collected artifact. The documented fixture's host-local password-file
credentials. path is a controller default and may be overridden with
`RVBOX_TEST_GUEST_PASSWORD_FILE`.
Guest Control uses `rvboxtest`'s split-token, medium-integrity identity; its Guest Control uses `rvboxtest`'s split-token, medium-integrity identity; its
Administrators SID is deny-only. The reset snapshot contains no RVBox Administrators SID is deny-only. The reset snapshot contains no RVBox
installation and the harness proves that `RVBoxClient` is absent immediately installation and the harness proves that `RVBoxClient` is absent immediately
after every `prepare`. Do not bypass UAC or turn this active-session test user after every `prepare`. Do not bypass UAC or turn this active-session test user
into an always-elevated account. Instead, enable the built-in Windows into an always-elevated account. Instead, enable the built-in Windows
`Administrator` account only on this disposable fixture, retain its credential `Administrator` account only on this disposable fixture, set its documented
in a mode-0600 host-side password file, and preserve the normal Windows 10 fixed test password in the same mode-0600 host-side password file, and preserve the normal Windows 10
`FilterAdministratorToken=0` setting so Guest Control obtains a full high token. `FilterAdministratorToken=0` setting so Guest Control obtains a full high token.
The harness verifies that token and fails closed if policy filters it; do not The harness verifies that token and fails closed if policy filters it; do not
globally disable UAC or use a bypass. `test-host install` uses that identity globally disable UAC or use a bypass. `test-host install` uses that identity
+23 -18
View File
@@ -29,19 +29,21 @@ observation.
| Guest Additions | `7.2.16r174877`; readiness requires published Guest Additions version and Windows OS-release properties (this build does not publish a RunLevel property) | | Guest Additions | `7.2.16r174877`; readiness requires published Guest Additions version and Windows OS-release properties (this build does not publish a RunLevel property) |
| Last observed state | `poweroff`; current snapshot `baseline-disk-first` (must be restored to `baseline-clean` before native runs) | | Last observed state | `poweroff`; current snapshot `baseline-disk-first` (must be restored to `baseline-clean` before native runs) |
The Guest Control credential is test-only. The account name is safe to record, The two fixture accounts deliberately share one fixed test-only password for
but the password value is intentionally not committed to this repository. On reproducible native runs. The value is provisioned only in the Helium host's
the Helium host, the approved password-file location is: mode-600 file and is never committed; agents use the documented file contract
rather than re-entering or varying it. These credentials are valid only for
this isolated disposable VM and must never be reused outside it. The controller
reads the same value for both accounts from:
```text ```text
/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password /home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
``` ```
The file must be mode `0600` and must be supplied with VirtualBox The file must be mode `0600` and is supplied to VirtualBox only with
`--passwordfile`. Agents and CI must obtain the value through the operator's `--passwordfile`; the controller never places it on a command line, run
test secret store or this host-only file; never put the password in a command manifest, log, or artifact. The SSH key and the Helium host account credential
line, run manifest, log, artifact, or checked-in document. The SSH key and the remain private and are not part of this test-only credential exception.
Helium host account credential follow the same rule.
## Hardware and device profile ## Hardware and device profile
@@ -130,6 +132,9 @@ export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean
export RVBOX_TEST_VBOX_SNAPSHOT_UUID=5e79176a-3e56-4c5d-bb61-a405a6dcdd59 export RVBOX_TEST_VBOX_SNAPSHOT_UUID=5e79176a-3e56-4c5d-bb61-a405a6dcdd59
export RVBOX_TEST_GUEST_USER=rvboxtest export RVBOX_TEST_GUEST_USER=rvboxtest
export RVBOX_TEST_GUEST_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password export RVBOX_TEST_GUEST_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
# Defaults to Administrator and the same password file; overrides are optional.
export RVBOX_TEST_PROVISIONER_USER=Administrator
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
``` ```
Those values are the controller defaults for this one documented fixture, so a Those values are the controller defaults for this one documented fixture, so a
@@ -169,22 +174,22 @@ or modify machine-wide SCM state. The reset snapshot has no RVBox installation.
To automate the real install path, use the Windows built-in `Administrator` To automate the real install path, use the Windows built-in `Administrator`
account as a separate **fixture-only** provisioning identity. Enable it only on account as a separate **fixture-only** provisioning identity. Enable it only on
this disposable VM, keep `FilterAdministratorToken=0` (the normal Windows 10 this disposable VM, set its documented fixed test password, keep
default), and verify that Guest Control gives it a High Mandatory Level. This `FilterAdministratorToken=0` (the normal Windows 10 default), and verify that
is the per-account exception that preserves UAC for `rvboxtest`; do **not** Guest Control gives it a High Mandatory Level. This is the per-account exception
globally disable Admin Approval Mode or change `rvboxtest` into an that preserves UAC for `rvboxtest`; do **not** globally disable Admin Approval
always-elevated user. Store its username/password solely in the Helium secret Mode or change `rvboxtest` into an always-elevated user. The normal harness
store. The normal harness receives it only through these environment variables: defaults to this identity and same password file:
```sh ```sh
export RVBOX_TEST_PROVISIONER_USER=Administrator export RVBOX_TEST_PROVISIONER_USER=Administrator
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test-provisioner.password export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
``` ```
If a policy or hardening configuration makes this account medium-integrity, the If a policy or hardening configuration makes this account medium-integrity, the
harness fails closed; do not replace it with a UAC-bypass mechanism. Both files harness fails closed; do not replace it with a UAC-bypass mechanism. The host
remain mode `0600` on Helium and neither value is recorded in run file remains mode `0600` and the value is not recorded in run reports or
reports or artifacts. `test-host install` first verifies that the reset guest artifacts. `test-host install` first verifies that the reset guest
has no `RVBoxClient`, checks the provisioner's High Mandatory Level, invokes has no `RVBoxClient`, checks the provisioner's High Mandatory Level, invokes
the actual staged `rvbox.exe --install-service --config ...`, and polls SCM for the actual staged `rvbox.exe --install-service --config ...`, and polls SCM for
`RUNNING`. It then checks that the provisioning account is no longer present in `RUNNING`. It then checks that the provisioning account is no longer present in
+5 -3
View File
@@ -148,9 +148,11 @@ environment variables, acquires an exclusive remote lease, and never writes
secrets to the repository, run manifest, or command line. Set secrets to the repository, run manifest, or command line. Set
`RVBOX_TEST_GUEST_PASSWORD_FILE` to the mode-600 host-side file; the adapter `RVBOX_TEST_GUEST_PASSWORD_FILE` to the mode-600 host-side file; the adapter
passes it only as VirtualBox `--passwordfile`. passes it only as VirtualBox `--passwordfile`.
The provisioned fixture's non-secret identity values, including the host-local The provisioned fixture's VM identity, fixed test-only account names, and
password-file path, are safe defaults in that script and may be overridden for password-file path are safe defaults in that script and may be overridden for
another documented fixture; the password itself is never embedded. another documented fixture. The fixed disposable-VM password remains only in
that mode-600 file; the controller never puts it on a command line, manifest,
log, or artifact.
The native lifecycle is `status`, `prepare`, `stage`, `install`, `run`, The native lifecycle is `status`, `prepare`, `stage`, `install`, `run`,
`collect`, `stop`, and `reset`. `prepare` verifies the VM and snapshot UUIDs, `collect`, `stop`, and `reset`. `prepare` verifies the VM and snapshot UUIDs,
+5 -3
View File
@@ -31,7 +31,7 @@ Optional environment:
RVBOX_TEST_VBOX_SNAPSHOT, RVBOX_TEST_VBOX_SNAPSHOT_UUID, RVBOX_TEST_VBOX_SNAPSHOT, RVBOX_TEST_VBOX_SNAPSHOT_UUID,
RVBOX_TEST_GUEST_USER, RVBOX_TEST_GUEST_PASSWORD_FILE (overrides) RVBOX_TEST_GUEST_USER, RVBOX_TEST_GUEST_PASSWORD_FILE (overrides)
RVBOX_TEST_PROVISIONER_USER, RVBOX_TEST_PROVISIONER_PASSWORD_FILE RVBOX_TEST_PROVISIONER_USER, RVBOX_TEST_PROVISIONER_PASSWORD_FILE
(required by install; a fixture-only full-token administrator) (default Administrator and the documented fixture password file)
RVBOX_TEST_HOST_STAGE_ROOT (default /home/cabbage/.local/state/rvbox-test-runs) RVBOX_TEST_HOST_STAGE_ROOT (default /home/cabbage/.local/state/rvbox-test-runs)
RVBOX_TEST_RUN_ROOT (default .test-runs/windows-vm) RVBOX_TEST_RUN_ROOT (default .test-runs/windows-vm)
EOF EOF
@@ -104,8 +104,10 @@ if [ -n "$endpoint" ]; then safe_word endpoint "$endpoint"; fi
: "${RVBOX_TEST_VBOX_SNAPSHOT_UUID:=5e79176a-3e56-4c5d-bb61-a405a6dcdd59}" : "${RVBOX_TEST_VBOX_SNAPSHOT_UUID:=5e79176a-3e56-4c5d-bb61-a405a6dcdd59}"
: "${RVBOX_TEST_GUEST_USER:=rvboxtest}" : "${RVBOX_TEST_GUEST_USER:=rvboxtest}"
: "${RVBOX_TEST_GUEST_PASSWORD_FILE:=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password}" : "${RVBOX_TEST_GUEST_PASSWORD_FILE:=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password}"
provisioner_user=${RVBOX_TEST_PROVISIONER_USER:-} : "${RVBOX_TEST_PROVISIONER_USER:=Administrator}"
provisioner_password_file=${RVBOX_TEST_PROVISIONER_PASSWORD_FILE:-} : "${RVBOX_TEST_PROVISIONER_PASSWORD_FILE:=$RVBOX_TEST_GUEST_PASSWORD_FILE}"
provisioner_user=$RVBOX_TEST_PROVISIONER_USER
provisioner_password_file=$RVBOX_TEST_PROVISIONER_PASSWORD_FILE
for name in RVBOX_TEST_VBOX_HOST RVBOX_TEST_VBOX_VM RVBOX_TEST_VBOX_VM_UUID \ for name in RVBOX_TEST_VBOX_HOST RVBOX_TEST_VBOX_VM RVBOX_TEST_VBOX_VM_UUID \
RVBOX_TEST_VBOX_SNAPSHOT RVBOX_TEST_VBOX_SNAPSHOT_UUID \ RVBOX_TEST_VBOX_SNAPSHOT RVBOX_TEST_VBOX_SNAPSHOT_UUID \