feat: isolate simultaneous RDP fixture profiles

This commit is contained in:
2026-09-14 07:16:39 +00:00
parent 9a2b0fd3c1
commit 620f882fe2
6 changed files with 97 additions and 14 deletions
+6
View File
@@ -904,6 +904,12 @@ response”. If the public browser hostname has an AAAA record, `rdp-access up
--bind 0.0.0.0` must own a tracked IPv6-to-IPv4 forward and expose its
`ipv6_forward` status; this prevents a browser selecting IPv6 for the WebSocket
from silently taking a different, refused path.
The helper preserves the single-fixture `default` profile for compatibility;
simultaneous already-running VM gateways use a unique `RDP_ACCESS_PROFILE` (or
`--profile`) with separate runtime/project state and HTTP/tunnel ports, while
`RVBOX_TEST_VBOX_HOST`, the documented VM/snapshot identity variables, and
`RDP_ACCESS_VRDE_PORT` select the actual target. Profile isolation does not
override the native controller's exclusive lease for prepare/reset operations.
For this provisioned lane, the approved host-only credential-file location is
`/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password`. It must
+4
View File
@@ -94,6 +94,10 @@ down/reset lifecycle; it is not an alternative to the native test controller.
In public-bind mode the helper also owns a tracked IPv6-to-IPv4 `socat` forward
when the browser hostname has an AAAA record; check `ipv6_forward=active` in
`rdp-access status` before diagnosing a browser-side “Waiting for response”.
When more than one already-running VM needs browser access, set matching
`RVBOX_TEST_VBOX_*`/`RDP_ACCESS_VRDE_PORT` values and a unique
`RDP_ACCESS_PROFILE` plus HTTP/tunnel ports; the helper README has the
copy/paste example and explains the native-host lease boundary.
## Snapshots and reset contract
+3 -1
View File
@@ -210,7 +210,9 @@ self-signed HTTPS Guacamole lifecycle; it must be started only after the native
fixture controller has prepared and leased the VM, and stopped before reset.
For a public hostname with an AAAA record, its `up --bind 0.0.0.0` mode also
tracks an IPv6-to-IPv4 forward; verify `ipv6_forward=active` before debugging
a browser stuck at “Waiting for response”.
a browser stuck at “Waiting for response”. If several already-running VMs need
browser access at once, use the documented `RDP_ACCESS_PROFILE` and matching
host/VRDE/HTTP/tunnel-port overrides in the helper README.
The Linux production Compose asset has a separate, loopback-only smoke lane. It
uses a disposable self-signed key only under the ignored `.test-runs` tree,