feat: add native Windows hierarchy test harness

This commit is contained in:
2026-09-09 16:48:54 +00:00
parent 8985457d37
commit 409b64a2fb
30 changed files with 1033 additions and 44 deletions
+59
View File
@@ -174,6 +174,65 @@ connectivity and CA-trust probe. The resulting service and artifact paths are
recorded in the run report and reclaimed by the snapshot reset rather than broad
guest deletion.
The first-class end-to-end controller is scripts/windows/native-test run
--run-id ID. It runs the per-run Linux server and nginx stack in Docker Compose
under test/linux-server on the current controller. Helium hosts only the
Windows VM and VirtualBox Guest Control bridge. The client connects to the
explicit current-controller WSS endpoint (x1.xcel.me by default), never the
DHCP guest address, and intentionally accepts that endpoint's matching-host
self-signed certificate in v1. The controller drives requests with the local
stack's rvc, collects bounded artifacts, and deletes just its labeled Compose
project during cleanup.
The test bundle never sends a Windows executable over the controller-to-Helium
SSH hop. The tagged fixture build strips symbol and DWARF tables; `test-host
stage` creates a temporary `xz -3` payload, publishes it to the authenticated
controller HTTP endpoint, and directs Helium to download it through its SOCKS5
acceleration proxy. Helium resumes the HTTP payload, verifies its compressed
SHA-256, atomically decompresses it into the exact host stage, then validates
the ordinary uncompressed bundle manifest before Guest Control copies files
into Windows. The baseline Helium host must provide `curl` and `xz`. Small
non-secret `client.toml` and optional CA files still use bounded-retry SSH
copies; executable staging fails closed if the accelerated route is unavailable.
Each successful stage prints `verified transfer_sha256` and the verified
manifest. No manual remote checksum check is needed for a normal or resumed
test run. The controller uses bounded SSH retries (four attempts, short
backoff) for idempotent inspection, staging, installation, and service-run
operations. Reset, stop, and logoff intentionally remain single-attempt;
after an interrupted lifecycle transition, use `recover` and decide whether to
resume or reset instead of replaying an ambiguous action.
For this controller/Helium fixture, the required executable route publishes
only the stripped, compressed test executable under the current controller's
Downloads HTTP endpoint
(`http://x1.xcel.me:9124`, authentication `x1:x1`) and asks Helium to fetch it
through its metered `socks5h://127.0.0.1:1085` proxy. The endpoint currently
advertises Basic authentication, so the harness deliberately uses curl's
`--anyauth` negotiation rather than assuming Digest. It never publishes
`client.toml`, CA material, passwords, or other configuration. Helium resumes
the HTTP download, verifies the compressed SHA-256, atomically decompresses it
into its stage, and the ordinary manifest check still runs before Guest
Control copies files into Windows. The uniquely named published artifact is
removed after successful guest staging (and on a subsequently failed stage).
`RVBOX_TEST_ACCEL_HTTP_URL`, `RVBOX_TEST_ACCEL_HTTP_AUTH`,
`RVBOX_TEST_ACCEL_HTTP_PUBLISH_DIR`, and `RVBOX_TEST_ACCEL_SOCKS5` override the
documented fixture defaults.
Early Windows-service failures are appended to
`C:\ProgramData\RVBox\service-startup.log`, before client config, durable
state, or normal observability logging begins. This is intentionally outside a
per-run bundle directory so the LocalSystem service can report an ACL/path
failure affecting that directory.
To prove the complete elevated fallback chain in one single-user fixture, the
controller builds a separately tagged disposable rvbox.exe. Its only extra
behavior is the internal --test-fail-contexts switch, which can force
ACTIVE_USER_ELEVATED and then ACTIVE_SYSTEM token preparation to fail before
launch. Release binaries reject the switch. The normal active-user,
active-user-elevated, active-system, local-system, local-service, and
logged-out local-system rows are therefore observed through the real SCM
service without adding a product broker or protocol field.
### Clean baseline and non-interactive installation
`rvboxtest` deliberately remains a split-token administrator. Guest Control