test: baseline Windows fixture with Administrator
This commit is contained in:
@@ -813,8 +813,8 @@ mirror; update both documents when the fixture is reprovisioned.
|
||||
| Diagnostic VRDE | Enabled at `192.168.50.162:3389`, external/`VBoxAuthSimple` authentication, input/display enabled, audio/USB/clipboard/RDPDR disabled; diagnostic-only because client compatibility is unreliable |
|
||||
| Native Windows RDP | Disabled in baseline (`TermService` stopped, `fDenyTSConnections=1`); port 3390 must not be treated as a usable control endpoint |
|
||||
| Test account | Local `rvboxtest`; split-token local administrator; console session 1 observed; Guest Control verified with `whoami`, `whoami /groups`, and `query user` |
|
||||
| Baseline | Reset target `baseline-clean` (UUID `5e79176a-3e56-4c5d-bb61-a405a6dcdd59`): no RVBox service, tray registration, state, logs, or staged binary. Retain child `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`) for diagnostics only. |
|
||||
| Last checked state | `poweroff`, current snapshot `baseline-disk-first`; restore `baseline-clean` before native runs, and leave that reset target selected after cleanup |
|
||||
| Baseline | Reset target `baseline-clean-administrator` (UUID `ba5ce5f1-77e3-44b0-8d91-534becce27ff`): no RVBox service, tray registration, state, logs, or staged binary; built-in `Administrator` is enabled only for the fixture's high-token Guest Control installation path. Retain `baseline-clean` (UUID `5e79176a-3e56-4c5d-bb61-a405a6dcdd59`) and child `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`) as pristine diagnostics. |
|
||||
| Last checked state | `poweroff`, current snapshot `baseline-clean-administrator`; restore that reset target before native runs, and leave it selected after cleanup |
|
||||
|
||||
The isolated disposable fixture deliberately uses one fixed test-only password
|
||||
for both local test accounts, `rvboxtest` and `Administrator`. Its value is
|
||||
@@ -831,9 +831,9 @@ Guest Control uses `rvboxtest`'s split-token, medium-integrity identity; its
|
||||
Administrators SID is deny-only. The reset snapshot contains no RVBox
|
||||
installation and the harness proves that `RVBoxClient` is absent immediately
|
||||
after every `prepare`. Do not bypass UAC or turn this active-session test user
|
||||
into an always-elevated account. Instead, enable the built-in Windows
|
||||
`Administrator` account only on this disposable fixture, set its documented
|
||||
fixed test password in the same mode-0600 host-side password file, and preserve the normal Windows 10
|
||||
into an always-elevated account. Instead, keep the built-in Windows
|
||||
`Administrator` account enabled only on this disposable fixture, with its
|
||||
documented fixed test password in the same mode-0600 host-side password file, and preserve the normal Windows 10
|
||||
`FilterAdministratorToken=0` setting so Guest Control obtains a full high token.
|
||||
The harness verifies that token and fails closed if policy filters it; do not
|
||||
globally disable UAC or use a bypass. `test-host install` uses that identity
|
||||
@@ -870,7 +870,8 @@ identity in the run manifest:
|
||||
```sh
|
||||
export RVBOX_TEST_VBOX_HOST=helium-remote
|
||||
export RVBOX_TEST_VBOX_VM=rvbox-win10-test
|
||||
export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean
|
||||
export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean-administrator
|
||||
export RVBOX_TEST_VBOX_SNAPSHOT_UUID=ba5ce5f1-77e3-44b0-8d91-534becce27ff
|
||||
export RVBOX_TEST_GUEST_USER=rvboxtest
|
||||
export RVBOX_TEST_GUEST_PASSWORD_FILE=/secure/outside-repo/rvbox-win10-test.password
|
||||
```
|
||||
@@ -889,7 +890,7 @@ ssh "$RVBOX_TEST_VBOX_HOST" \
|
||||
|
||||
# Restore only while powered off, then boot without a GUI.
|
||||
ssh "$RVBOX_TEST_VBOX_HOST" \
|
||||
'VBoxManage snapshot "rvbox-win10-test" restore "baseline-clean"'
|
||||
'VBoxManage snapshot "rvbox-win10-test" restore "baseline-clean-administrator"'
|
||||
ssh "$RVBOX_TEST_VBOX_HOST" \
|
||||
'VBoxManage startvm "rvbox-win10-test" --type headless'
|
||||
|
||||
@@ -937,8 +938,8 @@ Use this shutdown/reset sequence for every native run:
|
||||
acpipowerbutton` and poll. Use `controlvm ... poweroff` only for a hung,
|
||||
disposable test; it intentionally loses guest state.
|
||||
3. Collect diagnostics while the VM is still available, then restore
|
||||
`baseline-clean` and verify the snapshot UUID/current marker.
|
||||
4. Leave the VM powered off after cleanup. Never delete either baseline
|
||||
`baseline-clean-administrator` and verify the snapshot UUID/current marker.
|
||||
4. Leave the VM powered off after cleanup. Never delete any baseline
|
||||
snapshot, unregister the VM, or modify `win10_dev` (that name refers to a
|
||||
stale unregistered configuration with a missing disk on this host).
|
||||
|
||||
|
||||
Reference in New Issue
Block a user