docs: define full-token Windows fixture provisioner

This commit is contained in:
2026-09-09 07:14:43 +00:00
parent 985a2c2422
commit 6866adf0c1
3 changed files with 24 additions and 14 deletions
+8 -5
View File
@@ -830,11 +830,14 @@ Guest Control uses `rvboxtest`'s split-token, medium-integrity identity; its
Administrators SID is deny-only. The reset snapshot contains no RVBox
installation and the harness proves that `RVBoxClient` is absent immediately
after every `prepare`. Do not bypass UAC or turn this active-session test user
into an always-elevated account. Instead, provision a separate fixture-only
full-token administrator, with its username and a mode-0600 host-side password
file held outside the repository. `test-host install` uses that identity only
to execute the staged real `rvbox.exe --install-service` path and proves it by
polling SCM. It is not an RVBox product process, a service/broker, or a Task
into an always-elevated account. Instead, enable the built-in Windows
`Administrator` account only on this disposable fixture, retain its credential
in a mode-0600 host-side password file, and preserve the normal Windows 10
`FilterAdministratorToken=0` setting so Guest Control obtains a full high token.
The harness verifies that token and fails closed if policy filters it; do not
globally disable UAC or use a bypass. `test-host install` uses that identity
only to execute the staged real `rvbox.exe --install-service` path and proves it
by polling SCM. It is not an RVBox product process, a service/broker, or a Task
Scheduler dependency, and it never enters the daemon's command-context choice.
The normal active `rvboxtest` session remains the target for execution-role
tests. The consent-prompt branch itself remains an interactive UAC test; an