feat: add native Windows hierarchy test harness

This commit is contained in:
2026-09-09 16:48:54 +00:00
parent 8985457d37
commit 409b64a2fb
30 changed files with 1033 additions and 44 deletions
+221
View File
@@ -0,0 +1,221 @@
#!/bin/sh
# Production-shaped Linux server/nginx -> native Windows client test lane.
set -eu
repo_root=$(CDPATH= cd -- "$(dirname -- "$0")/../.." && pwd)
usage() {
cat <<'EOF'
usage: scripts/windows/native-test run|recover|clean --run-id ID [options]
run options:
--port PORT Current-controller TLS port (default RVBOX_NATIVE_PORT or 16899)
--keep retain the stack/VM lease for inspection
recover reports the exact VM lease and Compose resources.
clean stops only the matching stack and resets the matching VM run.
--purge --yes also delete only the matching local and Helium run files
run uses a separately tagged disposable fixture binary to prove every Windows
execution context through SCM, nginx WSS, the Linux server, and rvc. Release
binaries reject the fixture-only pre-launch failure switch.
EOF
}
fail() { printf '%s\n' "native-test: $*" >&2; exit 2; }
safe_id() {
case $1 in [a-z0-9]* ) ;; *) fail "run ID must start with lowercase alphanumeric" ;; esac
case $1 in ''|*[!a-z0-9-]*|????????????????????????????????????????????????????????????????*) fail "run ID must match [a-z0-9][a-z0-9-]{0,63}" ;; esac
}
action=${1-}
[ -n "$action" ] || { usage >&2; exit 2; }
shift
case $action in run|recover|clean|--help|-h) ;; *) usage >&2; fail "unknown action $action" ;; esac
[ "$action" != --help ] && [ "$action" != -h ] || { usage; exit 0; }
run_id=
port=${RVBOX_NATIVE_PORT:-16899}
keep=no
purge=no
yes=no
while [ "$#" -gt 0 ]; do
case $1 in
--run-id) [ "$#" -ge 2 ] || fail "--run-id needs a value"; run_id=$2; shift 2 ;;
--port) [ "$#" -ge 2 ] || fail "--port needs a value"; port=$2; shift 2 ;;
--keep) keep=yes; shift ;;
--purge) purge=yes; shift ;;
--yes) yes=yes; shift ;;
--help|-h) usage; exit 0 ;;
*) fail "unknown argument $1" ;;
esac
done
[ -n "$run_id" ] || fail "$action requires --run-id"
safe_id "$run_id"
case $port in *[!0-9]*|'') fail "--port must be an integer" ;; esac
[ "$port" -ge 1024 ] && [ "$port" -le 65535 ] || fail "--port must be 1024..65535"
[ "$purge" = no ] || [ "$action" = clean ] || fail "--purge is only valid with clean"
[ "$yes" = no ] || [ "$action" = clean ] || fail "--yes is only valid with clean"
[ "$purge" = no ] || [ "$yes" = yes ] || fail "--purge requires --yes"
: "${RVBOX_TEST_VBOX_HOST:=helium-remote}"
case $RVBOX_TEST_VBOX_HOST in ''|*[!A-Za-z0-9._:@-]*) fail "RVBOX_TEST_VBOX_HOST contains unsupported characters" ;; esac
endpoint_host=${RVBOX_NATIVE_ENDPOINT_HOST:-x1.xcel.me}
case $endpoint_host in ''|*[!A-Za-z0-9.-]*) fail "RVBOX_NATIVE_ENDPOINT_HOST contains unsupported characters" ;; esac
project=rvbox-native-$run_id
run_root=$repo_root/.test-runs/$run_id
fixture_dir=$run_root/native-windows
client_id=native-$run_id
client_config=$fixture_dir/client.toml
server_config=$fixture_dir/server.toml
vm_prepared=no
compose() {
RVBOX_NATIVE_RUN_ID="$run_id" RVBOX_NATIVE_PORT="$port" \
RVBOX_NATIVE_BIND=0.0.0.0 RVBOX_NATIVE_UID="$(id -u)" RVBOX_NATIVE_GID="$(id -g)" \
RVBOX_NATIVE_RUNTIME_DIR="$fixture_dir" RVBOX_NATIVE_ENDPOINT_HOST="$endpoint_host" \
docker compose -p "$project" -f "$repo_root/test/linux-server/compose.yaml" "$@"
}
rvc() {
compose exec -T server /opt/rvbox/rvc --socket /run/rvbox/server.sock "$@"
}
prepare_files() {
umask 077
mkdir -p "$fixture_dir"
[ ! -e "$server_config" ] || fail "refusing to overwrite existing $server_config"
[ ! -e "$client_config" ] || fail "refusing to overwrite existing $client_config"
printf '%s\n' '[server]' 'data_dir = "/state/data"' 'agent_listen = "0.0.0.0:6899"' 'control_socket = "/run/rvbox/server.sock"' '' '[observability]' 'listen = "0.0.0.0:6901"' >"$server_config"
printf '%s\n' \
'[client]' \
"server_url = \"wss://$endpoint_host:$port/v1/agent\"" \
'state_dir = "C:\\ProgramData\\RVBox\\test-state"' \
"client_id = \"$client_id\"" \
'daemon_cwd = "C:\\ProgramData\\RVBox\\test-work"' \
'' '[tls]' \
'# Empty intentionally exercises v1 matching-host self-signed TLS.' \
'ca_file = ""' \
"server_name = \"$endpoint_host\"" \
'' '[observability]' \
'listen = "127.0.0.1:6902"' \
'log_file = "C:\\ProgramData\\RVBox\\test-logs\\rvbox.log"' >"$client_config"
chmod 600 "$server_config" "$client_config"
}
stage_stack() {
# scripts/build intentionally execs its Docker command. Keep that process
# replacement inside a subshell so this lifecycle controller continues.
("$repo_root/scripts/build" build)
install -d -m 700 "$fixture_dir/pki" "$fixture_dir/state/data" "$fixture_dir/state/control"
compose --profile tools run --rm certgen
compose up -d server nginx
attempt=0
while [ "$attempt" -lt 30 ]; do
if rvc stat >/dev/null 2>&1; then return 0; fi
attempt=$((attempt + 1)); sleep 1
done
compose logs --tail=200
fail "server control socket did not become ready"
}
wait_client() {
attempt=0
while [ "$attempt" -lt 45 ]; do
state=$(rvc stat "$client_id" 2>/dev/null || true)
if printf '%s\n' "$state" | grep -q "client $client_id connected=true"; then return 0; fi
attempt=$((attempt + 1)); sleep 1
done
compose logs --tail=200
fail "native Windows client did not connect through nginx WSS"
}
assert_context() {
label=$1
elevated=$2
want=$3
if [ "$elevated" = yes ]; then
issued=$(rvc run --background --shell cmd --elevated "$client_id" "echo RVBOX_NATIVE_$label" 2>&1) || fail "$label admission failed: $issued"
else
issued=$(rvc run --background --shell cmd "$client_id" "echo RVBOX_NATIVE_$label" 2>&1) || fail "$label admission failed: $issued"
fi
issue=$(printf '%s\n' "$issued" | awk 'NR == 1 { print $1 }')
case $issue in ????????-????-7???-????-????????????) ;; *) fail "$label returned invalid issue UUID: $issued" ;; esac
attempt=0
while [ "$attempt" -lt 45 ]; do
result=$(rvc stat "$client_id" "$issue" 2>/dev/null || true)
if printf '%s\n' "$result" | grep -q 'lifecycle=COMMAND_SUCCEEDED'; then
printf '%s\n' "$result" | grep -q "windows_effective_context=$want" || fail "$label effective context mismatch: $result"
printf '%s\n' "$result" >"$fixture_dir/$label.stat"
printf 'passed %s issue=%s context=%s\n' "$label" "$issue" "$want"
return 0
fi
case $result in *'lifecycle=COMMAND_FAILED'*|*'lifecycle=COMMAND_REJECTED'*|*'lifecycle=COMMAND_TERMINATED'*) fail "$label did not succeed: $result" ;; esac
attempt=$((attempt + 1)); sleep 1
done
fail "$label did not reach terminal success"
}
collect() {
if [ "$vm_prepared" = yes ]; then
"$repo_root/scripts/windows/test-host" collect --run-id "$run_id" || true
fi
if [ -d "$fixture_dir" ]; then
compose logs --no-color --tail=500 >"$fixture_dir/server-proxy.log" 2>&1 || true
fi
}
clean() {
compose down --volumes --remove-orphans || true
# A reset is the isolation boundary for the next run. Do not conceal a
# failed shutdown/snapshot restore behind a successful-looking `clean`:
# callers must repair or explicitly inspect the retained VM lease first.
"$repo_root/scripts/windows/test-host" reset --run-id "$run_id"
if [ "$purge" = yes ]; then
[ -L "$run_root" ] && fail "refusing symlink run root $run_root"
rm -rf "$run_root"
fi
}
case $action in
recover)
"$repo_root/scripts/windows/test-host" recover --run-id "$run_id"
compose ps
printf 'run_root=%s\n' "$run_root"
;;
clean)
collect
clean
printf 'cleaned run_id=%s\n' "$run_id"
;;
run)
trap 'status=$?; if [ "$status" -ne 0 ]; then collect; fi' EXIT
[ ! -e "$run_root" ] || fail "refusing to reuse existing run root $run_root; inspect with recover or remove with clean --purge --yes"
prepare_files
stage_stack
"$repo_root/scripts/windows/build-test-bundle" --native-fixture --run-id "$run_id" --config "$client_config"
"$repo_root/scripts/windows/test-host" prepare --run-id "$run_id"
vm_prepared=yes
"$repo_root/scripts/windows/test-host" stage --run-id "$run_id" --bundle "$run_root/windows-bundle"
"$repo_root/scripts/windows/test-host" install --run-id "$run_id"
"$repo_root/scripts/windows/test-host" run --run-id "$run_id" --endpoint "$endpoint_host:$port"
wait_client
assert_context active-user no active-user
assert_context active-user-elevated yes active-user-elevated
"$repo_root/scripts/windows/test-host" run --run-id "$run_id" --fail-contexts ACTIVE_USER_ELEVATED
wait_client
assert_context active-system yes active-system
"$repo_root/scripts/windows/test-host" run --run-id "$run_id" --fail-contexts ACTIVE_USER_ELEVATED,ACTIVE_SYSTEM
wait_client
assert_context local-system-active-fallback yes local-system
"$repo_root/scripts/windows/test-host" run --run-id "$run_id"
wait_client
"$repo_root/scripts/windows/test-host" logoff --run-id "$run_id"
assert_context local-service no local-service
assert_context local-system-no-user yes local-system
collect
if [ "$keep" = no ]; then clean; fi
printf 'native Windows hierarchy run passed: %s\n' "$run_id"
;;
esac