test: baseline Windows fixture with Administrator
This commit is contained in:
+17
-15
@@ -6,9 +6,8 @@ Windows release matrix. Keep the values here in sync with the VM before adding
|
||||
or changing native test automation.
|
||||
|
||||
Last configuration check: 2026-09-09 UTC. The VM was observed powered off with
|
||||
`baseline-disk-first` selected. The native harness now targets `baseline-clean`;
|
||||
the fixture must be rechecked and its current snapshot returned to that clean
|
||||
baseline before native runs resume. A test run must still perform its own identity,
|
||||
`baseline-clean-administrator` selected. The native harness targets that snapshot;
|
||||
the fixture is ready for native runs. A test run must still perform its own identity,
|
||||
snapshot, readiness, and exclusive-lease checks rather than relying on that
|
||||
observation.
|
||||
|
||||
@@ -27,7 +26,7 @@ observation.
|
||||
| Guest OS | Windows 10 Pro 22H2, build `19045.2006`, en-US, BIOS boot |
|
||||
| Guest account | Local `rvboxtest`; split-token local administrator; console session 1 was observed during provisioning |
|
||||
| Guest Additions | `7.2.16r174877`; readiness requires published Guest Additions version and Windows OS-release properties (this build does not publish a RunLevel property) |
|
||||
| Last observed state | `poweroff`; current snapshot `baseline-disk-first` (must be restored to `baseline-clean` before native runs) |
|
||||
| Last observed state | `poweroff`; current snapshot `baseline-clean-administrator`, the reset target for native runs |
|
||||
|
||||
The two fixture accounts deliberately share one fixed test-only password for
|
||||
reproducible native runs. The value is provisioned only in the Helium host's
|
||||
@@ -88,28 +87,31 @@ and collection. Do not expose the VM's RDP endpoints beyond the test LAN.
|
||||
|
||||
## Snapshots and reset contract
|
||||
|
||||
Two clean snapshots exist and must be retained. `baseline-clean` is the only
|
||||
reset target: it contains no `RVBoxClient` SCM service, RVBox tray Run-key
|
||||
registration, RVBox state, logs, or staged binaries.
|
||||
Three clean snapshots exist and must be retained. `baseline-clean-administrator`
|
||||
is the only reset target: it contains no `RVBoxClient` SCM service, RVBox tray
|
||||
Run-key registration, RVBox state, logs, or staged binaries; it also has the
|
||||
fixture-only built-in `Administrator` account enabled for high-token Guest
|
||||
Control installation.
|
||||
|
||||
| Snapshot | UUID | Description |
|
||||
| --- | --- | --- |
|
||||
| `baseline-clean` | `5e79176a-3e56-4c5d-bb61-a405a6dcdd59` | `baseline-windows10-pro-22h2-rvboxtest-guest-additions` |
|
||||
| `baseline-disk-first` | `9430a9a4-754a-4b22-beaa-8dfd90043f5b` | `baseline-windows10-pro-22h2-disk-first`; current smoke baseline |
|
||||
| `baseline-disk-first` | `9430a9a4-754a-4b22-beaa-8dfd90043f5b` | `baseline-windows10-pro-22h2-disk-first`; retained diagnostic snapshot |
|
||||
| `baseline-clean-administrator` | `ba5ce5f1-77e3-44b0-8d91-534becce27ff` | `baseline-windows10-pro-22h2-administrator-enabled-full-token`; current reset target |
|
||||
|
||||
Restore only while the VM is powered off. Every destructive or potentially
|
||||
stateful run must:
|
||||
|
||||
1. Acquire the run lease and verify the VM name, UUID, and snapshot UUID.
|
||||
2. Restore `baseline-clean` if the current state is not the baseline.
|
||||
2. Restore `baseline-clean-administrator` if the current state is not the baseline.
|
||||
3. Start headless and wait for `VMState=running` plus Guest Additions readiness.
|
||||
4. Run the bounded test, collect redacted artifacts, and close every Guest
|
||||
Control process that was opened by the run.
|
||||
5. Request a graceful guest shutdown and wait for `VMState=poweroff`.
|
||||
6. Restore `baseline-clean` again and leave the VM powered off.
|
||||
6. Restore `baseline-clean-administrator` again and leave the VM powered off.
|
||||
|
||||
Use `controlvm ... poweroff` only for a hung, disposable test; it can lose
|
||||
guest state. Never delete either clean snapshot, unregister the VM, or alter
|
||||
guest state. Never delete any clean snapshot, unregister the VM, or alter
|
||||
the stale unregistered `win10_dev` configuration (its disk is missing).
|
||||
|
||||
## Harness contract
|
||||
@@ -128,8 +130,8 @@ The adapter takes identity and credentials only from its environment:
|
||||
export RVBOX_TEST_VBOX_HOST=helium-remote
|
||||
export RVBOX_TEST_VBOX_VM=rvbox-win10-test
|
||||
export RVBOX_TEST_VBOX_VM_UUID=6cdc114f-71e5-4167-a394-e922e14e6f5c
|
||||
export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean
|
||||
export RVBOX_TEST_VBOX_SNAPSHOT_UUID=5e79176a-3e56-4c5d-bb61-a405a6dcdd59
|
||||
export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean-administrator
|
||||
export RVBOX_TEST_VBOX_SNAPSHOT_UUID=ba5ce5f1-77e3-44b0-8d91-534becce27ff
|
||||
export RVBOX_TEST_GUEST_USER=rvboxtest
|
||||
export RVBOX_TEST_GUEST_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
|
||||
# Defaults to Administrator and the same password file; overrides are optional.
|
||||
@@ -173,8 +175,8 @@ therefore launches it at medium integrity and it must never be used to create
|
||||
or modify machine-wide SCM state. The reset snapshot has no RVBox installation.
|
||||
|
||||
To automate the real install path, use the Windows built-in `Administrator`
|
||||
account as a separate **fixture-only** provisioning identity. Enable it only on
|
||||
this disposable VM, set its documented fixed test password, keep
|
||||
account as a separate **fixture-only** provisioning identity. It is enabled only
|
||||
on this disposable VM, has its documented fixed test password, and keeps
|
||||
`FilterAdministratorToken=0` (the normal Windows 10 default), and verify that
|
||||
Guest Control gives it a High Mandatory Level. This is the per-account exception
|
||||
that preserves UAC for `rvboxtest`; do **not** globally disable Admin Approval
|
||||
|
||||
Reference in New Issue
Block a user