feat: add native Windows hierarchy test harness

This commit is contained in:
2026-09-09 16:48:54 +00:00
parent 8985457d37
commit 409b64a2fb
30 changed files with 1033 additions and 44 deletions
+39
View File
@@ -740,6 +740,45 @@ side effect must add a hook and coverage row before merging.
### 2.6 Native Windows test-host requirements
#### 2.6.0 Implemented current-controller native hierarchy lane
Implement scripts/windows/native-test as the first-class production-shaped
native gate. One run must create an immutable run directory, compile a
separately tagged fixture-only rvbox.exe in the pinned Docker toolchain, and
run the Linux server and nginx fixture from test/linux-server in a labeled
Docker Compose project on the current controller. Helium hosts only the
Windows VM and the VirtualBox Guest Control bridge: no RVBox server, proxy,
or Compose resource may be staged or run there. The local stack must create a
two-day matching-host self-signed leaf for the explicit current-controller
endpoint (x1.xcel.me by default, overridable by
RVBOX_NATIVE_ENDPOINT_HOST). It binds the configured test port on the current
controller and copies only rvbox.exe and client configuration to the Windows
guest test root.
The Windows service must connect through that WSS endpoint; controller-side
success is not enough. With no tls.ca_file configured, the v1 client must
accept the matching-host self-signed leaf while retaining hostname validation;
that is encrypted routing only and makes no claim that the endpoint is
authenticated. Wait for the client to become connected through the local
server's actual Unix rvc socket, issue real CMD commands, wait for durable
terminal success, and retain the resulting command status records. Verify,
in order: normal ACTIVE_USER; elevated ACTIVE_USER_ELEVATED; forced
ACTIVE_USER_ELEVATED preparation failure falling back to ACTIVE_SYSTEM; forced
ACTIVE_USER_ELEVATED plus ACTIVE_SYSTEM failure falling back to LOCAL_SYSTEM;
then log off the sole fixture console session and verify normal LOCAL_SERVICE
and elevated LOCAL_SYSTEM. The forced faults must be available only in the
separately tagged fixture binary, only before child-process creation, and only
for these two active elevated contexts. They are not a protocol field, TOML
knob, release-build behavior, or product broker.
On ordinary success collect bounded guest and local server/proxy artifacts,
remove only that labeled Compose project and its volumes, and restore the exact
snapshot. On failure retain the exact local stack and VM lease for recover;
clean must reset the fixture and retain artifacts, while an explicit purge with
a confirmation removes only the matching local run root. Add static
tests for the runner's file layout and tagged-build boundary, and promote the
native coverage row only after this lane passes on the documented VM.
Native Windows is mandatory for the Phase 4/5 gates. Development can begin with
unit tests and cross-compilation before a host is connected, but the Windows
supervisor/service/tray implementation cannot be called complete without it.