test: baseline Windows fixture with Administrator

This commit is contained in:
2026-09-09 08:45:41 +00:00
parent 0b7d33e676
commit 0cd1e17629
4 changed files with 30 additions and 27 deletions
+10 -9
View File
@@ -813,8 +813,8 @@ mirror; update both documents when the fixture is reprovisioned.
| Diagnostic VRDE | Enabled at `192.168.50.162:3389`, external/`VBoxAuthSimple` authentication, input/display enabled, audio/USB/clipboard/RDPDR disabled; diagnostic-only because client compatibility is unreliable | | Diagnostic VRDE | Enabled at `192.168.50.162:3389`, external/`VBoxAuthSimple` authentication, input/display enabled, audio/USB/clipboard/RDPDR disabled; diagnostic-only because client compatibility is unreliable |
| Native Windows RDP | Disabled in baseline (`TermService` stopped, `fDenyTSConnections=1`); port 3390 must not be treated as a usable control endpoint | | Native Windows RDP | Disabled in baseline (`TermService` stopped, `fDenyTSConnections=1`); port 3390 must not be treated as a usable control endpoint |
| Test account | Local `rvboxtest`; split-token local administrator; console session 1 observed; Guest Control verified with `whoami`, `whoami /groups`, and `query user` | | Test account | Local `rvboxtest`; split-token local administrator; console session 1 observed; Guest Control verified with `whoami`, `whoami /groups`, and `query user` |
| Baseline | Reset target `baseline-clean` (UUID `5e79176a-3e56-4c5d-bb61-a405a6dcdd59`): no RVBox service, tray registration, state, logs, or staged binary. Retain child `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`) for diagnostics only. | | Baseline | Reset target `baseline-clean-administrator` (UUID `ba5ce5f1-77e3-44b0-8d91-534becce27ff`): no RVBox service, tray registration, state, logs, or staged binary; built-in `Administrator` is enabled only for the fixture's high-token Guest Control installation path. Retain `baseline-clean` (UUID `5e79176a-3e56-4c5d-bb61-a405a6dcdd59`) and child `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`) as pristine diagnostics. |
| Last checked state | `poweroff`, current snapshot `baseline-disk-first`; restore `baseline-clean` before native runs, and leave that reset target selected after cleanup | | Last checked state | `poweroff`, current snapshot `baseline-clean-administrator`; restore that reset target before native runs, and leave it selected after cleanup |
The isolated disposable fixture deliberately uses one fixed test-only password The isolated disposable fixture deliberately uses one fixed test-only password
for both local test accounts, `rvboxtest` and `Administrator`. Its value is for both local test accounts, `rvboxtest` and `Administrator`. Its value is
@@ -831,9 +831,9 @@ Guest Control uses `rvboxtest`'s split-token, medium-integrity identity; its
Administrators SID is deny-only. The reset snapshot contains no RVBox Administrators SID is deny-only. The reset snapshot contains no RVBox
installation and the harness proves that `RVBoxClient` is absent immediately installation and the harness proves that `RVBoxClient` is absent immediately
after every `prepare`. Do not bypass UAC or turn this active-session test user after every `prepare`. Do not bypass UAC or turn this active-session test user
into an always-elevated account. Instead, enable the built-in Windows into an always-elevated account. Instead, keep the built-in Windows
`Administrator` account only on this disposable fixture, set its documented `Administrator` account enabled only on this disposable fixture, with its
fixed test password in the same mode-0600 host-side password file, and preserve the normal Windows 10 documented fixed test password in the same mode-0600 host-side password file, and preserve the normal Windows 10
`FilterAdministratorToken=0` setting so Guest Control obtains a full high token. `FilterAdministratorToken=0` setting so Guest Control obtains a full high token.
The harness verifies that token and fails closed if policy filters it; do not The harness verifies that token and fails closed if policy filters it; do not
globally disable UAC or use a bypass. `test-host install` uses that identity globally disable UAC or use a bypass. `test-host install` uses that identity
@@ -870,7 +870,8 @@ identity in the run manifest:
```sh ```sh
export RVBOX_TEST_VBOX_HOST=helium-remote export RVBOX_TEST_VBOX_HOST=helium-remote
export RVBOX_TEST_VBOX_VM=rvbox-win10-test export RVBOX_TEST_VBOX_VM=rvbox-win10-test
export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean-administrator
export RVBOX_TEST_VBOX_SNAPSHOT_UUID=ba5ce5f1-77e3-44b0-8d91-534becce27ff
export RVBOX_TEST_GUEST_USER=rvboxtest export RVBOX_TEST_GUEST_USER=rvboxtest
export RVBOX_TEST_GUEST_PASSWORD_FILE=/secure/outside-repo/rvbox-win10-test.password export RVBOX_TEST_GUEST_PASSWORD_FILE=/secure/outside-repo/rvbox-win10-test.password
``` ```
@@ -889,7 +890,7 @@ ssh "$RVBOX_TEST_VBOX_HOST" \
# Restore only while powered off, then boot without a GUI. # Restore only while powered off, then boot without a GUI.
ssh "$RVBOX_TEST_VBOX_HOST" \ ssh "$RVBOX_TEST_VBOX_HOST" \
'VBoxManage snapshot "rvbox-win10-test" restore "baseline-clean"' 'VBoxManage snapshot "rvbox-win10-test" restore "baseline-clean-administrator"'
ssh "$RVBOX_TEST_VBOX_HOST" \ ssh "$RVBOX_TEST_VBOX_HOST" \
'VBoxManage startvm "rvbox-win10-test" --type headless' 'VBoxManage startvm "rvbox-win10-test" --type headless'
@@ -937,8 +938,8 @@ Use this shutdown/reset sequence for every native run:
acpipowerbutton` and poll. Use `controlvm ... poweroff` only for a hung, acpipowerbutton` and poll. Use `controlvm ... poweroff` only for a hung,
disposable test; it intentionally loses guest state. disposable test; it intentionally loses guest state.
3. Collect diagnostics while the VM is still available, then restore 3. Collect diagnostics while the VM is still available, then restore
`baseline-clean` and verify the snapshot UUID/current marker. `baseline-clean-administrator` and verify the snapshot UUID/current marker.
4. Leave the VM powered off after cleanup. Never delete either baseline 4. Leave the VM powered off after cleanup. Never delete any baseline
snapshot, unregister the VM, or modify `win10_dev` (that name refers to a snapshot, unregister the VM, or modify `win10_dev` (that name refers to a
stale unregistered configuration with a missing disk on this host). stale unregistered configuration with a missing disk on this host).
+17 -15
View File
@@ -6,9 +6,8 @@ Windows release matrix. Keep the values here in sync with the VM before adding
or changing native test automation. or changing native test automation.
Last configuration check: 2026-09-09 UTC. The VM was observed powered off with Last configuration check: 2026-09-09 UTC. The VM was observed powered off with
`baseline-disk-first` selected. The native harness now targets `baseline-clean`; `baseline-clean-administrator` selected. The native harness targets that snapshot;
the fixture must be rechecked and its current snapshot returned to that clean the fixture is ready for native runs. A test run must still perform its own identity,
baseline before native runs resume. A test run must still perform its own identity,
snapshot, readiness, and exclusive-lease checks rather than relying on that snapshot, readiness, and exclusive-lease checks rather than relying on that
observation. observation.
@@ -27,7 +26,7 @@ observation.
| Guest OS | Windows 10 Pro 22H2, build `19045.2006`, en-US, BIOS boot | | Guest OS | Windows 10 Pro 22H2, build `19045.2006`, en-US, BIOS boot |
| Guest account | Local `rvboxtest`; split-token local administrator; console session 1 was observed during provisioning | | Guest account | Local `rvboxtest`; split-token local administrator; console session 1 was observed during provisioning |
| Guest Additions | `7.2.16r174877`; readiness requires published Guest Additions version and Windows OS-release properties (this build does not publish a RunLevel property) | | Guest Additions | `7.2.16r174877`; readiness requires published Guest Additions version and Windows OS-release properties (this build does not publish a RunLevel property) |
| Last observed state | `poweroff`; current snapshot `baseline-disk-first` (must be restored to `baseline-clean` before native runs) | | Last observed state | `poweroff`; current snapshot `baseline-clean-administrator`, the reset target for native runs |
The two fixture accounts deliberately share one fixed test-only password for The two fixture accounts deliberately share one fixed test-only password for
reproducible native runs. The value is provisioned only in the Helium host's reproducible native runs. The value is provisioned only in the Helium host's
@@ -88,28 +87,31 @@ and collection. Do not expose the VM's RDP endpoints beyond the test LAN.
## Snapshots and reset contract ## Snapshots and reset contract
Two clean snapshots exist and must be retained. `baseline-clean` is the only Three clean snapshots exist and must be retained. `baseline-clean-administrator`
reset target: it contains no `RVBoxClient` SCM service, RVBox tray Run-key is the only reset target: it contains no `RVBoxClient` SCM service, RVBox tray
registration, RVBox state, logs, or staged binaries. Run-key registration, RVBox state, logs, or staged binaries; it also has the
fixture-only built-in `Administrator` account enabled for high-token Guest
Control installation.
| Snapshot | UUID | Description | | Snapshot | UUID | Description |
| --- | --- | --- | | --- | --- | --- |
| `baseline-clean` | `5e79176a-3e56-4c5d-bb61-a405a6dcdd59` | `baseline-windows10-pro-22h2-rvboxtest-guest-additions` | | `baseline-clean` | `5e79176a-3e56-4c5d-bb61-a405a6dcdd59` | `baseline-windows10-pro-22h2-rvboxtest-guest-additions` |
| `baseline-disk-first` | `9430a9a4-754a-4b22-beaa-8dfd90043f5b` | `baseline-windows10-pro-22h2-disk-first`; current smoke baseline | | `baseline-disk-first` | `9430a9a4-754a-4b22-beaa-8dfd90043f5b` | `baseline-windows10-pro-22h2-disk-first`; retained diagnostic snapshot |
| `baseline-clean-administrator` | `ba5ce5f1-77e3-44b0-8d91-534becce27ff` | `baseline-windows10-pro-22h2-administrator-enabled-full-token`; current reset target |
Restore only while the VM is powered off. Every destructive or potentially Restore only while the VM is powered off. Every destructive or potentially
stateful run must: stateful run must:
1. Acquire the run lease and verify the VM name, UUID, and snapshot UUID. 1. Acquire the run lease and verify the VM name, UUID, and snapshot UUID.
2. Restore `baseline-clean` if the current state is not the baseline. 2. Restore `baseline-clean-administrator` if the current state is not the baseline.
3. Start headless and wait for `VMState=running` plus Guest Additions readiness. 3. Start headless and wait for `VMState=running` plus Guest Additions readiness.
4. Run the bounded test, collect redacted artifacts, and close every Guest 4. Run the bounded test, collect redacted artifacts, and close every Guest
Control process that was opened by the run. Control process that was opened by the run.
5. Request a graceful guest shutdown and wait for `VMState=poweroff`. 5. Request a graceful guest shutdown and wait for `VMState=poweroff`.
6. Restore `baseline-clean` again and leave the VM powered off. 6. Restore `baseline-clean-administrator` again and leave the VM powered off.
Use `controlvm ... poweroff` only for a hung, disposable test; it can lose Use `controlvm ... poweroff` only for a hung, disposable test; it can lose
guest state. Never delete either clean snapshot, unregister the VM, or alter guest state. Never delete any clean snapshot, unregister the VM, or alter
the stale unregistered `win10_dev` configuration (its disk is missing). the stale unregistered `win10_dev` configuration (its disk is missing).
## Harness contract ## Harness contract
@@ -128,8 +130,8 @@ The adapter takes identity and credentials only from its environment:
export RVBOX_TEST_VBOX_HOST=helium-remote export RVBOX_TEST_VBOX_HOST=helium-remote
export RVBOX_TEST_VBOX_VM=rvbox-win10-test export RVBOX_TEST_VBOX_VM=rvbox-win10-test
export RVBOX_TEST_VBOX_VM_UUID=6cdc114f-71e5-4167-a394-e922e14e6f5c export RVBOX_TEST_VBOX_VM_UUID=6cdc114f-71e5-4167-a394-e922e14e6f5c
export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean-administrator
export RVBOX_TEST_VBOX_SNAPSHOT_UUID=5e79176a-3e56-4c5d-bb61-a405a6dcdd59 export RVBOX_TEST_VBOX_SNAPSHOT_UUID=ba5ce5f1-77e3-44b0-8d91-534becce27ff
export RVBOX_TEST_GUEST_USER=rvboxtest export RVBOX_TEST_GUEST_USER=rvboxtest
export RVBOX_TEST_GUEST_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password export RVBOX_TEST_GUEST_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password
# Defaults to Administrator and the same password file; overrides are optional. # Defaults to Administrator and the same password file; overrides are optional.
@@ -173,8 +175,8 @@ therefore launches it at medium integrity and it must never be used to create
or modify machine-wide SCM state. The reset snapshot has no RVBox installation. or modify machine-wide SCM state. The reset snapshot has no RVBox installation.
To automate the real install path, use the Windows built-in `Administrator` To automate the real install path, use the Windows built-in `Administrator`
account as a separate **fixture-only** provisioning identity. Enable it only on account as a separate **fixture-only** provisioning identity. It is enabled only
this disposable VM, set its documented fixed test password, keep on this disposable VM, has its documented fixed test password, and keeps
`FilterAdministratorToken=0` (the normal Windows 10 default), and verify that `FilterAdministratorToken=0` (the normal Windows 10 default), and verify that
Guest Control gives it a High Mandatory Level. This is the per-account exception Guest Control gives it a High Mandatory Level. This is the per-account exception
that preserves UAC for `rvboxtest`; do **not** globally disable Admin Approval that preserves UAC for `rvboxtest`; do **not** globally disable Admin Approval
+1 -1
View File
@@ -132,7 +132,7 @@ The authoritative fixture record is
[testing-vm.md](testing-vm.md): it lists the VM/host UUIDs, Windows build, [testing-vm.md](testing-vm.md): it lists the VM/host UUIDs, Windows build,
hardware and device profile, NAT and VRDE endpoints, snapshot UUIDs, hardware and device profile, NAT and VRDE endpoints, snapshot UUIDs,
credential-file contract, and the required reset sequence. At the last check credential-file contract, and the required reset sequence. At the last check
the VM was powered off with `baseline-disk-first` selected. The guest address the VM was powered off with `baseline-clean-administrator` selected. The guest address
`10.0.2.15` is DHCP state only; use SSH plus VirtualBox Guest Control rather `10.0.2.15` is DHCP state only; use SSH plus VirtualBox Guest Control rather
than treating it as a stable endpoint. VRDE is enabled at than treating it as a stable endpoint. VRDE is enabled at
`192.168.50.162:3389` for diagnostics, while native Windows RDP is disabled in `192.168.50.162:3389` for diagnostics, while native Windows RDP is disabled in
+2 -2
View File
@@ -100,8 +100,8 @@ if [ -n "$endpoint" ]; then safe_word endpoint "$endpoint"; fi
: "${RVBOX_TEST_VBOX_HOST:=helium-remote}" : "${RVBOX_TEST_VBOX_HOST:=helium-remote}"
: "${RVBOX_TEST_VBOX_VM:=rvbox-win10-test}" : "${RVBOX_TEST_VBOX_VM:=rvbox-win10-test}"
: "${RVBOX_TEST_VBOX_VM_UUID:=6cdc114f-71e5-4167-a394-e922e14e6f5c}" : "${RVBOX_TEST_VBOX_VM_UUID:=6cdc114f-71e5-4167-a394-e922e14e6f5c}"
: "${RVBOX_TEST_VBOX_SNAPSHOT:=baseline-clean}" : "${RVBOX_TEST_VBOX_SNAPSHOT:=baseline-clean-administrator}"
: "${RVBOX_TEST_VBOX_SNAPSHOT_UUID:=5e79176a-3e56-4c5d-bb61-a405a6dcdd59}" : "${RVBOX_TEST_VBOX_SNAPSHOT_UUID:=ba5ce5f1-77e3-44b0-8d91-534becce27ff}"
: "${RVBOX_TEST_GUEST_USER:=rvboxtest}" : "${RVBOX_TEST_GUEST_USER:=rvboxtest}"
: "${RVBOX_TEST_GUEST_PASSWORD_FILE:=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password}" : "${RVBOX_TEST_GUEST_PASSWORD_FILE:=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password}"
: "${RVBOX_TEST_PROVISIONER_USER:=Administrator}" : "${RVBOX_TEST_PROVISIONER_USER:=Administrator}"