fix: make Guacamole fixture dual-stack and keep VM display awake

This commit is contained in:
2026-09-14 06:31:07 +00:00
parent d01bb5a9a7
commit 102a5486f4
9 changed files with 180 additions and 11 deletions
+8
View File
@@ -893,6 +893,14 @@ watchdog/tunnel is bound
only to the helper's private Docker gateway. Stop the helper before the normal
`test-host reset`. It is a recovery interface, not a product component or a
replacement for Guest Control/native test automation.
Because Windows can power off the virtual monitor while the VM remains
running, `test-host prepare` must also reapply the disposable display/sleep
keepalive and record `prepare-display-keepalive`. A zero-bpp VRDE framebuffer
otherwise leaves an otherwise authenticated Guacamole browser at “Waiting for
response”. If the public browser hostname has an AAAA record, `rdp-access up
--bind 0.0.0.0` must own a tracked IPv6-to-IPv4 forward and expose its
`ipv6_forward` status; this prevents a browser selecting IPv6 for the WebSocket
from silently taking a different, refused path.
For this provisioned lane, the approved host-only credential-file location is
`/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password`. It must
+10 -3
View File
@@ -91,6 +91,9 @@ self-signed HTTPS Guacamole gateway while retaining VRDE on Helium loopback and
the reconnecting SSH watchdog/tunnel on a private Docker gateway. Follow its
full lease/prepare/up/
down/reset lifecycle; it is not an alternative to the native test controller.
In public-bind mode the helper also owns a tracked IPv6-to-IPv4 `socat` forward
when the browser hostname has an AAAA record; check `ipv6_forward=active` in
`rdp-access status` before diagnosing a browser-side “Waiting for response”.
## Snapshots and reset contract
@@ -112,10 +115,14 @@ stateful run must:
1. Acquire the run lease and verify the VM name, UUID, and snapshot UUID.
2. Restore `baseline-clean-administrator` if the current state is not the baseline.
3. Start headless and wait for `VMState=running` plus Guest Additions readiness.
4. Run the bounded test, collect redacted artifacts, and close every Guest
4. Apply the disposable display/sleep keepalive (`monitor-timeout`, standby,
and hibernate timers set to zero) so VirtualBox VRDE cannot expose a
zero-bpp framebuffer after Windows idle timeout. This is recorded as
`prepare-display-keepalive` and is reapplied after every snapshot restore.
5. Run the bounded test, collect redacted artifacts, and close every Guest
Control process that was opened by the run.
5. Request a graceful guest shutdown and wait for `VMState=poweroff`.
6. Restore `baseline-clean-administrator` again and leave the VM powered off.
6. Request a graceful guest shutdown and wait for `VMState=poweroff`.
7. Restore `baseline-clean-administrator` again and leave the VM powered off.
Use `controlvm ... poweroff` only for a hung, disposable test; it can lose
guest state. Never delete any clean snapshot, unregister the VM, or alter
+3
View File
@@ -208,6 +208,9 @@ Interactive browser access is a deliberately temporary recovery path only. See
[`test/rdp-access`](../test/rdp-access/README.md) for the Docker-only,
self-signed HTTPS Guacamole lifecycle; it must be started only after the native
fixture controller has prepared and leased the VM, and stopped before reset.
For a public hostname with an AAAA record, its `up --bind 0.0.0.0` mode also
tracks an IPv6-to-IPv4 forward; verify `ipv6_forward=active` before debugging
a browser stuck at “Waiting for response”.
The Linux production Compose asset has a separate, loopback-only smoke lane. It
uses a disposable self-signed key only under the ignored `.test-runs` tree,