feat: add native Windows hierarchy test harness

This commit is contained in:
2026-09-09 16:48:54 +00:00
parent 8985457d37
commit 409b64a2fb
30 changed files with 1033 additions and 44 deletions
+39
View File
@@ -56,6 +56,37 @@ The bundle manifest records the source commit and SHA-256 of every bundled
file. It is a test artifact, not a signed release package; release signing,
version resources, and publication are Phase 8 gates.
The preferred complete native lane is now one command:
~~~sh
scripts/windows/native-test run --run-id windows-hierarchy
~~~
It builds a disposable fixture-tagged Windows binary in the pinned toolchain,
starts the real Linux server and nginx TLS proxy in Docker Compose under
test/linux-server on the current controller, and connects the Helium-hosted
NAT guest to the current controller's explicit endpoint (x1.xcel.me by
default). Helium hosts the VM only; it does not host any RVBox server
containers. The self-signed server certificate is intentionally accepted by
the v1 client without a test CA. It then drives the installed SCM service
through the server's real Unix control socket and verifies every Windows
execution context. The tagged binary's controlled pre-launch failures are
limited to the test fixture; a release binary rejects that switch.
Successful runs collect bounded artifacts, remove only their labeled Compose
project, and restore the exact clean snapshot. A failed or --keep run stays
recoverable:
~~~sh
scripts/windows/native-test recover --run-id windows-hierarchy
scripts/windows/native-test clean --run-id windows-hierarchy
scripts/windows/native-test clean --run-id windows-hierarchy --purge --yes
~~~
clean retains local artifacts by default. The explicit purge form removes only
the exact local run root after the local stack is down and the VM snapshot has
been restored.
The integration harness provides the Phase 0 `sample` suite, the incremental
Phase 2 `store` suite, and the incremental Phase 3 `server-session` suite.
The resumable E2E harness adds `smoke`, `script`, `recovery`, and `all`
@@ -180,6 +211,14 @@ also performs a bounded guest-to-nginx HTTPS/TCP readiness probe before it
starts the service. Wine and protocol stubs are not equivalent Windows
coverage.
For the hierarchy fixture only, run --fail-contexts
ACTIVE_USER_ELEVATED[,ACTIVE_SYSTEM] restarts the separately tagged test
service and forces the named token preparation step to fail before process
creation. This proves the real daemon's fallback order without changing the
wire protocol, normal client TOML, or release binary. The logoff action ends
the sole active fixture session so the LocalService and no-user LocalSystem
rows can be tested with the same running service.
The clean baseline intentionally contains no RVBox service, tray registration,
or RVBox state. Guest Control supplies `rvboxtest` with a filtered medium UAC
token, so it cannot safely perform the first machine-wide install. The fixture