docs: clarify Windows VM guest-control contract

This commit is contained in:
2026-09-06 05:30:19 +00:00
parent 2f07f7ce73
commit 5660541dc8
+6 -4
View File
@@ -782,9 +782,9 @@ fixture, no ambiguous multi-session fixture, and no Server Core variant.
| Guest OS | Windows 10 Pro 22H2, build `19045.2006`, en-US, BIOS boot |
| Resources | 2 vCPU, 4096 MiB RAM, 32 MiB VRAM, 40 GiB dynamically allocated VDI |
| Disk / source media | `/home/cabbage/VMs/rvbox-win10-test.vdi`; source ISO `/media/Data2/Downloaded/Win10_22H2_English_x64.iso` (Windows image index 6) |
| Devices/network | NAT NIC; audio, USB, 3D, clipboard, drag-and-drop, and VRDE disabled |
| Devices/network | NAT NIC; audio, USB, 3D, clipboard, drag-and-drop, and VRDE disabled; last observed guest IPv4 was `10.0.2.15` (DHCP observation only, never a management identity) |
| Guest control | Guest Additions installed and verified (`GuestAdditionsRunLevel=3`) |
| Test account | local `rvboxtest`; one active console session (session 1); split-token local administrator |
| Test account | local `rvboxtest`; one active console session (session 1); split-token local administrator; Guest Control was verified with `whoami`, `whoami /groups`, and `query user` |
| Baseline | snapshot `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`), current known-good snapshot; parent `baseline-clean` is retained |
| Initial state | VM is normally left powered off; restore the baseline before each destructive run |
@@ -792,8 +792,10 @@ The guest password, SSH key, and any host account secret are test secrets. Keep
them in the operator/CI secret store or a mode-600 password file outside the
repository; never put them in this plan, a command-line argument, a run
manifest, or collected logs. `VBoxManage guestcontrol` supports
`--passwordfile`; prefer that option over an inline password. The account name
and VM metadata above are not credentials.
`--passwordfile`; prefer that option over an inline password. Every operator or
agent must set `RVBOX_TEST_GUEST_PASSWORD_FILE` to the absolute path of that
host-side file before a native run. The account name and VM metadata above are
not credentials.
Use a local, non-secret environment description when operating the lane. The
host alias must resolve through the operator's SSH config; another controller