diff --git a/docs/implementation-plan.v1.md b/docs/implementation-plan.v1.md index 5d223cc..fed366c 100644 --- a/docs/implementation-plan.v1.md +++ b/docs/implementation-plan.v1.md @@ -813,8 +813,8 @@ mirror; update both documents when the fixture is reprovisioned. | Diagnostic VRDE | Enabled at `192.168.50.162:3389`, external/`VBoxAuthSimple` authentication, input/display enabled, audio/USB/clipboard/RDPDR disabled; diagnostic-only because client compatibility is unreliable | | Native Windows RDP | Disabled in baseline (`TermService` stopped, `fDenyTSConnections=1`); port 3390 must not be treated as a usable control endpoint | | Test account | Local `rvboxtest`; split-token local administrator; console session 1 observed; Guest Control verified with `whoami`, `whoami /groups`, and `query user` | -| Baseline | Reset target `baseline-clean` (UUID `5e79176a-3e56-4c5d-bb61-a405a6dcdd59`): no RVBox service, tray registration, state, logs, or staged binary. Retain child `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`) for diagnostics only. | -| Last checked state | `poweroff`, current snapshot `baseline-disk-first`; restore `baseline-clean` before native runs, and leave that reset target selected after cleanup | +| Baseline | Reset target `baseline-clean-administrator` (UUID `ba5ce5f1-77e3-44b0-8d91-534becce27ff`): no RVBox service, tray registration, state, logs, or staged binary; built-in `Administrator` is enabled only for the fixture's high-token Guest Control installation path. Retain `baseline-clean` (UUID `5e79176a-3e56-4c5d-bb61-a405a6dcdd59`) and child `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`) as pristine diagnostics. | +| Last checked state | `poweroff`, current snapshot `baseline-clean-administrator`; restore that reset target before native runs, and leave it selected after cleanup | The isolated disposable fixture deliberately uses one fixed test-only password for both local test accounts, `rvboxtest` and `Administrator`. Its value is @@ -831,9 +831,9 @@ Guest Control uses `rvboxtest`'s split-token, medium-integrity identity; its Administrators SID is deny-only. The reset snapshot contains no RVBox installation and the harness proves that `RVBoxClient` is absent immediately after every `prepare`. Do not bypass UAC or turn this active-session test user -into an always-elevated account. Instead, enable the built-in Windows -`Administrator` account only on this disposable fixture, set its documented -fixed test password in the same mode-0600 host-side password file, and preserve the normal Windows 10 +into an always-elevated account. Instead, keep the built-in Windows +`Administrator` account enabled only on this disposable fixture, with its +documented fixed test password in the same mode-0600 host-side password file, and preserve the normal Windows 10 `FilterAdministratorToken=0` setting so Guest Control obtains a full high token. The harness verifies that token and fails closed if policy filters it; do not globally disable UAC or use a bypass. `test-host install` uses that identity @@ -870,7 +870,8 @@ identity in the run manifest: ```sh export RVBOX_TEST_VBOX_HOST=helium-remote export RVBOX_TEST_VBOX_VM=rvbox-win10-test -export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean +export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean-administrator +export RVBOX_TEST_VBOX_SNAPSHOT_UUID=ba5ce5f1-77e3-44b0-8d91-534becce27ff export RVBOX_TEST_GUEST_USER=rvboxtest export RVBOX_TEST_GUEST_PASSWORD_FILE=/secure/outside-repo/rvbox-win10-test.password ``` @@ -889,7 +890,7 @@ ssh "$RVBOX_TEST_VBOX_HOST" \ # Restore only while powered off, then boot without a GUI. ssh "$RVBOX_TEST_VBOX_HOST" \ - 'VBoxManage snapshot "rvbox-win10-test" restore "baseline-clean"' + 'VBoxManage snapshot "rvbox-win10-test" restore "baseline-clean-administrator"' ssh "$RVBOX_TEST_VBOX_HOST" \ 'VBoxManage startvm "rvbox-win10-test" --type headless' @@ -937,8 +938,8 @@ Use this shutdown/reset sequence for every native run: acpipowerbutton` and poll. Use `controlvm ... poweroff` only for a hung, disposable test; it intentionally loses guest state. 3. Collect diagnostics while the VM is still available, then restore - `baseline-clean` and verify the snapshot UUID/current marker. -4. Leave the VM powered off after cleanup. Never delete either baseline + `baseline-clean-administrator` and verify the snapshot UUID/current marker. +4. Leave the VM powered off after cleanup. Never delete any baseline snapshot, unregister the VM, or modify `win10_dev` (that name refers to a stale unregistered configuration with a missing disk on this host). diff --git a/docs/testing-vm.md b/docs/testing-vm.md index fd58919..230eb51 100644 --- a/docs/testing-vm.md +++ b/docs/testing-vm.md @@ -6,9 +6,8 @@ Windows release matrix. Keep the values here in sync with the VM before adding or changing native test automation. Last configuration check: 2026-09-09 UTC. The VM was observed powered off with -`baseline-disk-first` selected. The native harness now targets `baseline-clean`; -the fixture must be rechecked and its current snapshot returned to that clean -baseline before native runs resume. A test run must still perform its own identity, +`baseline-clean-administrator` selected. The native harness targets that snapshot; +the fixture is ready for native runs. A test run must still perform its own identity, snapshot, readiness, and exclusive-lease checks rather than relying on that observation. @@ -27,7 +26,7 @@ observation. | Guest OS | Windows 10 Pro 22H2, build `19045.2006`, en-US, BIOS boot | | Guest account | Local `rvboxtest`; split-token local administrator; console session 1 was observed during provisioning | | Guest Additions | `7.2.16r174877`; readiness requires published Guest Additions version and Windows OS-release properties (this build does not publish a RunLevel property) | -| Last observed state | `poweroff`; current snapshot `baseline-disk-first` (must be restored to `baseline-clean` before native runs) | +| Last observed state | `poweroff`; current snapshot `baseline-clean-administrator`, the reset target for native runs | The two fixture accounts deliberately share one fixed test-only password for reproducible native runs. The value is provisioned only in the Helium host's @@ -88,28 +87,31 @@ and collection. Do not expose the VM's RDP endpoints beyond the test LAN. ## Snapshots and reset contract -Two clean snapshots exist and must be retained. `baseline-clean` is the only -reset target: it contains no `RVBoxClient` SCM service, RVBox tray Run-key -registration, RVBox state, logs, or staged binaries. +Three clean snapshots exist and must be retained. `baseline-clean-administrator` +is the only reset target: it contains no `RVBoxClient` SCM service, RVBox tray +Run-key registration, RVBox state, logs, or staged binaries; it also has the +fixture-only built-in `Administrator` account enabled for high-token Guest +Control installation. | Snapshot | UUID | Description | | --- | --- | --- | | `baseline-clean` | `5e79176a-3e56-4c5d-bb61-a405a6dcdd59` | `baseline-windows10-pro-22h2-rvboxtest-guest-additions` | -| `baseline-disk-first` | `9430a9a4-754a-4b22-beaa-8dfd90043f5b` | `baseline-windows10-pro-22h2-disk-first`; current smoke baseline | +| `baseline-disk-first` | `9430a9a4-754a-4b22-beaa-8dfd90043f5b` | `baseline-windows10-pro-22h2-disk-first`; retained diagnostic snapshot | +| `baseline-clean-administrator` | `ba5ce5f1-77e3-44b0-8d91-534becce27ff` | `baseline-windows10-pro-22h2-administrator-enabled-full-token`; current reset target | Restore only while the VM is powered off. Every destructive or potentially stateful run must: 1. Acquire the run lease and verify the VM name, UUID, and snapshot UUID. -2. Restore `baseline-clean` if the current state is not the baseline. +2. Restore `baseline-clean-administrator` if the current state is not the baseline. 3. Start headless and wait for `VMState=running` plus Guest Additions readiness. 4. Run the bounded test, collect redacted artifacts, and close every Guest Control process that was opened by the run. 5. Request a graceful guest shutdown and wait for `VMState=poweroff`. -6. Restore `baseline-clean` again and leave the VM powered off. +6. Restore `baseline-clean-administrator` again and leave the VM powered off. Use `controlvm ... poweroff` only for a hung, disposable test; it can lose -guest state. Never delete either clean snapshot, unregister the VM, or alter +guest state. Never delete any clean snapshot, unregister the VM, or alter the stale unregistered `win10_dev` configuration (its disk is missing). ## Harness contract @@ -128,8 +130,8 @@ The adapter takes identity and credentials only from its environment: export RVBOX_TEST_VBOX_HOST=helium-remote export RVBOX_TEST_VBOX_VM=rvbox-win10-test export RVBOX_TEST_VBOX_VM_UUID=6cdc114f-71e5-4167-a394-e922e14e6f5c -export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean -export RVBOX_TEST_VBOX_SNAPSHOT_UUID=5e79176a-3e56-4c5d-bb61-a405a6dcdd59 +export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean-administrator +export RVBOX_TEST_VBOX_SNAPSHOT_UUID=ba5ce5f1-77e3-44b0-8d91-534becce27ff export RVBOX_TEST_GUEST_USER=rvboxtest export RVBOX_TEST_GUEST_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password # Defaults to Administrator and the same password file; overrides are optional. @@ -173,8 +175,8 @@ therefore launches it at medium integrity and it must never be used to create or modify machine-wide SCM state. The reset snapshot has no RVBox installation. To automate the real install path, use the Windows built-in `Administrator` -account as a separate **fixture-only** provisioning identity. Enable it only on -this disposable VM, set its documented fixed test password, keep +account as a separate **fixture-only** provisioning identity. It is enabled only +on this disposable VM, has its documented fixed test password, and keeps `FilterAdministratorToken=0` (the normal Windows 10 default), and verify that Guest Control gives it a High Mandatory Level. This is the per-account exception that preserves UAC for `rvboxtest`; do **not** globally disable Admin Approval diff --git a/docs/testing.md b/docs/testing.md index 17facd7..cff4f70 100644 --- a/docs/testing.md +++ b/docs/testing.md @@ -132,7 +132,7 @@ The authoritative fixture record is [testing-vm.md](testing-vm.md): it lists the VM/host UUIDs, Windows build, hardware and device profile, NAT and VRDE endpoints, snapshot UUIDs, credential-file contract, and the required reset sequence. At the last check -the VM was powered off with `baseline-disk-first` selected. The guest address +the VM was powered off with `baseline-clean-administrator` selected. The guest address `10.0.2.15` is DHCP state only; use SSH plus VirtualBox Guest Control rather than treating it as a stable endpoint. VRDE is enabled at `192.168.50.162:3389` for diagnostics, while native Windows RDP is disabled in diff --git a/scripts/windows/test-host b/scripts/windows/test-host index 0b8a34c..d11edd7 100755 --- a/scripts/windows/test-host +++ b/scripts/windows/test-host @@ -100,8 +100,8 @@ if [ -n "$endpoint" ]; then safe_word endpoint "$endpoint"; fi : "${RVBOX_TEST_VBOX_HOST:=helium-remote}" : "${RVBOX_TEST_VBOX_VM:=rvbox-win10-test}" : "${RVBOX_TEST_VBOX_VM_UUID:=6cdc114f-71e5-4167-a394-e922e14e6f5c}" -: "${RVBOX_TEST_VBOX_SNAPSHOT:=baseline-clean}" -: "${RVBOX_TEST_VBOX_SNAPSHOT_UUID:=5e79176a-3e56-4c5d-bb61-a405a6dcdd59}" +: "${RVBOX_TEST_VBOX_SNAPSHOT:=baseline-clean-administrator}" +: "${RVBOX_TEST_VBOX_SNAPSHOT_UUID:=ba5ce5f1-77e3-44b0-8d91-534becce27ff}" : "${RVBOX_TEST_GUEST_USER:=rvboxtest}" : "${RVBOX_TEST_GUEST_PASSWORD_FILE:=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password}" : "${RVBOX_TEST_PROVISIONER_USER:=Administrator}"