From 6866adf0c129fa150519a605d5e0ac3c0a3b6173 Mon Sep 17 00:00:00 2001 From: cabbage Date: Wed, 9 Sep 2026 07:14:43 +0000 Subject: [PATCH] docs: define full-token Windows fixture provisioner --- docs/implementation-plan.v1.md | 13 ++++++++----- docs/testing-vm.md | 19 ++++++++++++------- docs/testing.md | 6 ++++-- 3 files changed, 24 insertions(+), 14 deletions(-) diff --git a/docs/implementation-plan.v1.md b/docs/implementation-plan.v1.md index 70a4e19..714189e 100644 --- a/docs/implementation-plan.v1.md +++ b/docs/implementation-plan.v1.md @@ -830,11 +830,14 @@ Guest Control uses `rvboxtest`'s split-token, medium-integrity identity; its Administrators SID is deny-only. The reset snapshot contains no RVBox installation and the harness proves that `RVBoxClient` is absent immediately after every `prepare`. Do not bypass UAC or turn this active-session test user -into an always-elevated account. Instead, provision a separate fixture-only -full-token administrator, with its username and a mode-0600 host-side password -file held outside the repository. `test-host install` uses that identity only -to execute the staged real `rvbox.exe --install-service` path and proves it by -polling SCM. It is not an RVBox product process, a service/broker, or a Task +into an always-elevated account. Instead, enable the built-in Windows +`Administrator` account only on this disposable fixture, retain its credential +in a mode-0600 host-side password file, and preserve the normal Windows 10 +`FilterAdministratorToken=0` setting so Guest Control obtains a full high token. +The harness verifies that token and fails closed if policy filters it; do not +globally disable UAC or use a bypass. `test-host install` uses that identity +only to execute the staged real `rvbox.exe --install-service` path and proves it +by polling SCM. It is not an RVBox product process, a service/broker, or a Task Scheduler dependency, and it never enters the daemon's command-context choice. The normal active `rvboxtest` session remains the target for execution-role tests. The consent-prompt branch itself remains an interactive UAC test; an diff --git a/docs/testing-vm.md b/docs/testing-vm.md index e4ad17e..d723845 100644 --- a/docs/testing-vm.md +++ b/docs/testing-vm.md @@ -167,18 +167,23 @@ guest deletion. therefore launches it at medium integrity and it must never be used to create or modify machine-wide SCM state. The reset snapshot has no RVBox installation. -To automate the real install path, provision one separate **fixture-only** -full-token local administrator and retain its username/password solely in the -Helium secret store. It must be a genuinely high-integrity Guest Control token; -do not globally disable UAC or change `rvboxtest` into an always-elevated user. -The normal harness receives it only through these environment variables: +To automate the real install path, use the Windows built-in `Administrator` +account as a separate **fixture-only** provisioning identity. Enable it only on +this disposable VM, keep `FilterAdministratorToken=0` (the normal Windows 10 +default), and verify that Guest Control gives it a High Mandatory Level. This +is the per-account exception that preserves UAC for `rvboxtest`; do **not** +globally disable Admin Approval Mode or change `rvboxtest` into an +always-elevated user. Store its username/password solely in the Helium secret +store. The normal harness receives it only through these environment variables: ```sh -export RVBOX_TEST_PROVISIONER_USER=FIXTURE_ONLY_FULL_ADMIN +export RVBOX_TEST_PROVISIONER_USER=Administrator export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test-provisioner.password ``` -Both files remain mode `0600` on Helium and neither value is recorded in run +If a policy or hardening configuration makes this account medium-integrity, the +harness fails closed; do not replace it with a UAC-bypass mechanism. Both files +remain mode `0600` on Helium and neither value is recorded in run reports or artifacts. `test-host install` first verifies that the reset guest has no `RVBoxClient`, checks the provisioner's High Mandatory Level, invokes the actual staged `rvbox.exe --install-service --config ...`, and polls SCM for diff --git a/docs/testing.md b/docs/testing.md index 6fe9c81..310e388 100644 --- a/docs/testing.md +++ b/docs/testing.md @@ -176,8 +176,10 @@ coverage. The clean baseline intentionally contains no RVBox service, tray registration, or RVBox state. Guest Control supplies `rvboxtest` with a filtered medium UAC token, so it cannot safely perform the first machine-wide install. The fixture -therefore has a separate test-only full-token automation principal, whose -username and mode-600 host-side password-file are provided only as +therefore uses its separately enabled built-in `Administrator` account as a +test-only full-token automation principal. Its `FilterAdministratorToken` must +remain `0`, preserving UAC for `rvboxtest` rather than disabling it machine-wide. +Its username and mode-600 host-side password-file are provided only as `RVBOX_TEST_PROVISIONER_USER` and `RVBOX_TEST_PROVISIONER_PASSWORD_FILE` for the `install`/machine-mutation actions. It is not an RVBox process, service, broker, or Task Scheduler dependency, and it is never used to choose a command