test: make Windows fixture credentials reproducible
This commit is contained in:
@@ -816,23 +816,24 @@ mirror; update both documents when the fixture is reprovisioned.
|
|||||||
| Baseline | Reset target `baseline-clean` (UUID `5e79176a-3e56-4c5d-bb61-a405a6dcdd59`): no RVBox service, tray registration, state, logs, or staged binary. Retain child `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`) for diagnostics only. |
|
| Baseline | Reset target `baseline-clean` (UUID `5e79176a-3e56-4c5d-bb61-a405a6dcdd59`): no RVBox service, tray registration, state, logs, or staged binary. Retain child `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`) for diagnostics only. |
|
||||||
| Last checked state | `poweroff`, current snapshot `baseline-disk-first`; restore `baseline-clean` before native runs, and leave that reset target selected after cleanup |
|
| Last checked state | `poweroff`, current snapshot `baseline-disk-first`; restore `baseline-clean` before native runs, and leave that reset target selected after cleanup |
|
||||||
|
|
||||||
The guest password, SSH key, and any host account secret are test secrets. Keep
|
The isolated disposable fixture deliberately uses one fixed test-only password
|
||||||
them in the operator/CI secret store or a mode-600 password file outside the
|
for both local test accounts, `rvboxtest` and `Administrator`. Its value is
|
||||||
repository; never put them in this plan, a command-line argument, a run
|
provisioned only in the mode-600 Helium host file and is never committed; the
|
||||||
manifest, or collected logs. `VBoxManage guestcontrol` supports
|
documented file contract, not a copied password, gives agents reproducible
|
||||||
`--passwordfile`; prefer that option over an inline password. The documented
|
access. It must never be reused outside this VM. The SSH key and host-account
|
||||||
fixture's host-local password-file path is a controller default and may be
|
credentials remain private. Supply the VM password to `VBoxManage guestcontrol`
|
||||||
overridden with `RVBOX_TEST_GUEST_PASSWORD_FILE`; the password value is never a
|
only with `--passwordfile`, never as a command-line argument, run-manifest
|
||||||
default or repository value. The account name and VM metadata above are not
|
value, or collected artifact. The documented fixture's host-local password-file
|
||||||
credentials.
|
path is a controller default and may be overridden with
|
||||||
|
`RVBOX_TEST_GUEST_PASSWORD_FILE`.
|
||||||
|
|
||||||
Guest Control uses `rvboxtest`'s split-token, medium-integrity identity; its
|
Guest Control uses `rvboxtest`'s split-token, medium-integrity identity; its
|
||||||
Administrators SID is deny-only. The reset snapshot contains no RVBox
|
Administrators SID is deny-only. The reset snapshot contains no RVBox
|
||||||
installation and the harness proves that `RVBoxClient` is absent immediately
|
installation and the harness proves that `RVBoxClient` is absent immediately
|
||||||
after every `prepare`. Do not bypass UAC or turn this active-session test user
|
after every `prepare`. Do not bypass UAC or turn this active-session test user
|
||||||
into an always-elevated account. Instead, enable the built-in Windows
|
into an always-elevated account. Instead, enable the built-in Windows
|
||||||
`Administrator` account only on this disposable fixture, retain its credential
|
`Administrator` account only on this disposable fixture, set its documented
|
||||||
in a mode-0600 host-side password file, and preserve the normal Windows 10
|
fixed test password in the same mode-0600 host-side password file, and preserve the normal Windows 10
|
||||||
`FilterAdministratorToken=0` setting so Guest Control obtains a full high token.
|
`FilterAdministratorToken=0` setting so Guest Control obtains a full high token.
|
||||||
The harness verifies that token and fails closed if policy filters it; do not
|
The harness verifies that token and fails closed if policy filters it; do not
|
||||||
globally disable UAC or use a bypass. `test-host install` uses that identity
|
globally disable UAC or use a bypass. `test-host install` uses that identity
|
||||||
|
|||||||
+23
-18
@@ -29,19 +29,21 @@ observation.
|
|||||||
| Guest Additions | `7.2.16r174877`; readiness requires published Guest Additions version and Windows OS-release properties (this build does not publish a RunLevel property) |
|
| Guest Additions | `7.2.16r174877`; readiness requires published Guest Additions version and Windows OS-release properties (this build does not publish a RunLevel property) |
|
||||||
| Last observed state | `poweroff`; current snapshot `baseline-disk-first` (must be restored to `baseline-clean` before native runs) |
|
| Last observed state | `poweroff`; current snapshot `baseline-disk-first` (must be restored to `baseline-clean` before native runs) |
|
||||||
|
|
||||||
The Guest Control credential is test-only. The account name is safe to record,
|
The two fixture accounts deliberately share one fixed test-only password for
|
||||||
but the password value is intentionally not committed to this repository. On
|
reproducible native runs. The value is provisioned only in the Helium host's
|
||||||
the Helium host, the approved password-file location is:
|
mode-600 file and is never committed; agents use the documented file contract
|
||||||
|
rather than re-entering or varying it. These credentials are valid only for
|
||||||
|
this isolated disposable VM and must never be reused outside it. The controller
|
||||||
|
reads the same value for both accounts from:
|
||||||
|
|
||||||
```text
|
```text
|
||||||
/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
|
/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
|
||||||
```
|
```
|
||||||
|
|
||||||
The file must be mode `0600` and must be supplied with VirtualBox
|
The file must be mode `0600` and is supplied to VirtualBox only with
|
||||||
`--passwordfile`. Agents and CI must obtain the value through the operator's
|
`--passwordfile`; the controller never places it on a command line, run
|
||||||
test secret store or this host-only file; never put the password in a command
|
manifest, log, or artifact. The SSH key and the Helium host account credential
|
||||||
line, run manifest, log, artifact, or checked-in document. The SSH key and the
|
remain private and are not part of this test-only credential exception.
|
||||||
Helium host account credential follow the same rule.
|
|
||||||
|
|
||||||
## Hardware and device profile
|
## Hardware and device profile
|
||||||
|
|
||||||
@@ -130,6 +132,9 @@ export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean
|
|||||||
export RVBOX_TEST_VBOX_SNAPSHOT_UUID=5e79176a-3e56-4c5d-bb61-a405a6dcdd59
|
export RVBOX_TEST_VBOX_SNAPSHOT_UUID=5e79176a-3e56-4c5d-bb61-a405a6dcdd59
|
||||||
export RVBOX_TEST_GUEST_USER=rvboxtest
|
export RVBOX_TEST_GUEST_USER=rvboxtest
|
||||||
export RVBOX_TEST_GUEST_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
|
export RVBOX_TEST_GUEST_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
|
||||||
|
# Defaults to Administrator and the same password file; overrides are optional.
|
||||||
|
export RVBOX_TEST_PROVISIONER_USER=Administrator
|
||||||
|
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
|
||||||
```
|
```
|
||||||
|
|
||||||
Those values are the controller defaults for this one documented fixture, so a
|
Those values are the controller defaults for this one documented fixture, so a
|
||||||
@@ -169,22 +174,22 @@ or modify machine-wide SCM state. The reset snapshot has no RVBox installation.
|
|||||||
|
|
||||||
To automate the real install path, use the Windows built-in `Administrator`
|
To automate the real install path, use the Windows built-in `Administrator`
|
||||||
account as a separate **fixture-only** provisioning identity. Enable it only on
|
account as a separate **fixture-only** provisioning identity. Enable it only on
|
||||||
this disposable VM, keep `FilterAdministratorToken=0` (the normal Windows 10
|
this disposable VM, set its documented fixed test password, keep
|
||||||
default), and verify that Guest Control gives it a High Mandatory Level. This
|
`FilterAdministratorToken=0` (the normal Windows 10 default), and verify that
|
||||||
is the per-account exception that preserves UAC for `rvboxtest`; do **not**
|
Guest Control gives it a High Mandatory Level. This is the per-account exception
|
||||||
globally disable Admin Approval Mode or change `rvboxtest` into an
|
that preserves UAC for `rvboxtest`; do **not** globally disable Admin Approval
|
||||||
always-elevated user. Store its username/password solely in the Helium secret
|
Mode or change `rvboxtest` into an always-elevated user. The normal harness
|
||||||
store. The normal harness receives it only through these environment variables:
|
defaults to this identity and same password file:
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
export RVBOX_TEST_PROVISIONER_USER=Administrator
|
export RVBOX_TEST_PROVISIONER_USER=Administrator
|
||||||
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test-provisioner.password
|
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
|
||||||
```
|
```
|
||||||
|
|
||||||
If a policy or hardening configuration makes this account medium-integrity, the
|
If a policy or hardening configuration makes this account medium-integrity, the
|
||||||
harness fails closed; do not replace it with a UAC-bypass mechanism. Both files
|
harness fails closed; do not replace it with a UAC-bypass mechanism. The host
|
||||||
remain mode `0600` on Helium and neither value is recorded in run
|
file remains mode `0600` and the value is not recorded in run reports or
|
||||||
reports or artifacts. `test-host install` first verifies that the reset guest
|
artifacts. `test-host install` first verifies that the reset guest
|
||||||
has no `RVBoxClient`, checks the provisioner's High Mandatory Level, invokes
|
has no `RVBoxClient`, checks the provisioner's High Mandatory Level, invokes
|
||||||
the actual staged `rvbox.exe --install-service --config ...`, and polls SCM for
|
the actual staged `rvbox.exe --install-service --config ...`, and polls SCM for
|
||||||
`RUNNING`. It then checks that the provisioning account is no longer present in
|
`RUNNING`. It then checks that the provisioning account is no longer present in
|
||||||
|
|||||||
+5
-3
@@ -148,9 +148,11 @@ environment variables, acquires an exclusive remote lease, and never writes
|
|||||||
secrets to the repository, run manifest, or command line. Set
|
secrets to the repository, run manifest, or command line. Set
|
||||||
`RVBOX_TEST_GUEST_PASSWORD_FILE` to the mode-600 host-side file; the adapter
|
`RVBOX_TEST_GUEST_PASSWORD_FILE` to the mode-600 host-side file; the adapter
|
||||||
passes it only as VirtualBox `--passwordfile`.
|
passes it only as VirtualBox `--passwordfile`.
|
||||||
The provisioned fixture's non-secret identity values, including the host-local
|
The provisioned fixture's VM identity, fixed test-only account names, and
|
||||||
password-file path, are safe defaults in that script and may be overridden for
|
password-file path are safe defaults in that script and may be overridden for
|
||||||
another documented fixture; the password itself is never embedded.
|
another documented fixture. The fixed disposable-VM password remains only in
|
||||||
|
that mode-600 file; the controller never puts it on a command line, manifest,
|
||||||
|
log, or artifact.
|
||||||
|
|
||||||
The native lifecycle is `status`, `prepare`, `stage`, `install`, `run`,
|
The native lifecycle is `status`, `prepare`, `stage`, `install`, `run`,
|
||||||
`collect`, `stop`, and `reset`. `prepare` verifies the VM and snapshot UUIDs,
|
`collect`, `stop`, and `reset`. `prepare` verifies the VM and snapshot UUIDs,
|
||||||
|
|||||||
@@ -31,7 +31,7 @@ Optional environment:
|
|||||||
RVBOX_TEST_VBOX_SNAPSHOT, RVBOX_TEST_VBOX_SNAPSHOT_UUID,
|
RVBOX_TEST_VBOX_SNAPSHOT, RVBOX_TEST_VBOX_SNAPSHOT_UUID,
|
||||||
RVBOX_TEST_GUEST_USER, RVBOX_TEST_GUEST_PASSWORD_FILE (overrides)
|
RVBOX_TEST_GUEST_USER, RVBOX_TEST_GUEST_PASSWORD_FILE (overrides)
|
||||||
RVBOX_TEST_PROVISIONER_USER, RVBOX_TEST_PROVISIONER_PASSWORD_FILE
|
RVBOX_TEST_PROVISIONER_USER, RVBOX_TEST_PROVISIONER_PASSWORD_FILE
|
||||||
(required by install; a fixture-only full-token administrator)
|
(default Administrator and the documented fixture password file)
|
||||||
RVBOX_TEST_HOST_STAGE_ROOT (default /home/cabbage/.local/state/rvbox-test-runs)
|
RVBOX_TEST_HOST_STAGE_ROOT (default /home/cabbage/.local/state/rvbox-test-runs)
|
||||||
RVBOX_TEST_RUN_ROOT (default .test-runs/windows-vm)
|
RVBOX_TEST_RUN_ROOT (default .test-runs/windows-vm)
|
||||||
EOF
|
EOF
|
||||||
@@ -104,8 +104,10 @@ if [ -n "$endpoint" ]; then safe_word endpoint "$endpoint"; fi
|
|||||||
: "${RVBOX_TEST_VBOX_SNAPSHOT_UUID:=5e79176a-3e56-4c5d-bb61-a405a6dcdd59}"
|
: "${RVBOX_TEST_VBOX_SNAPSHOT_UUID:=5e79176a-3e56-4c5d-bb61-a405a6dcdd59}"
|
||||||
: "${RVBOX_TEST_GUEST_USER:=rvboxtest}"
|
: "${RVBOX_TEST_GUEST_USER:=rvboxtest}"
|
||||||
: "${RVBOX_TEST_GUEST_PASSWORD_FILE:=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password}"
|
: "${RVBOX_TEST_GUEST_PASSWORD_FILE:=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password}"
|
||||||
provisioner_user=${RVBOX_TEST_PROVISIONER_USER:-}
|
: "${RVBOX_TEST_PROVISIONER_USER:=Administrator}"
|
||||||
provisioner_password_file=${RVBOX_TEST_PROVISIONER_PASSWORD_FILE:-}
|
: "${RVBOX_TEST_PROVISIONER_PASSWORD_FILE:=$RVBOX_TEST_GUEST_PASSWORD_FILE}"
|
||||||
|
provisioner_user=$RVBOX_TEST_PROVISIONER_USER
|
||||||
|
provisioner_password_file=$RVBOX_TEST_PROVISIONER_PASSWORD_FILE
|
||||||
|
|
||||||
for name in RVBOX_TEST_VBOX_HOST RVBOX_TEST_VBOX_VM RVBOX_TEST_VBOX_VM_UUID \
|
for name in RVBOX_TEST_VBOX_HOST RVBOX_TEST_VBOX_VM RVBOX_TEST_VBOX_VM_UUID \
|
||||||
RVBOX_TEST_VBOX_SNAPSHOT RVBOX_TEST_VBOX_SNAPSHOT_UUID \
|
RVBOX_TEST_VBOX_SNAPSHOT RVBOX_TEST_VBOX_SNAPSHOT_UUID \
|
||||||
|
|||||||
Reference in New Issue
Block a user