docs: define full-token Windows fixture provisioner

This commit is contained in:
2026-09-09 07:14:43 +00:00
parent 985a2c2422
commit 6866adf0c1
3 changed files with 24 additions and 14 deletions
+4 -2
View File
@@ -176,8 +176,10 @@ coverage.
The clean baseline intentionally contains no RVBox service, tray registration,
or RVBox state. Guest Control supplies `rvboxtest` with a filtered medium UAC
token, so it cannot safely perform the first machine-wide install. The fixture
therefore has a separate test-only full-token automation principal, whose
username and mode-600 host-side password-file are provided only as
therefore uses its separately enabled built-in `Administrator` account as a
test-only full-token automation principal. Its `FilterAdministratorToken` must
remain `0`, preserving UAC for `rvboxtest` rather than disabling it machine-wide.
Its username and mode-600 host-side password-file are provided only as
`RVBOX_TEST_PROVISIONER_USER` and `RVBOX_TEST_PROVISIONER_PASSWORD_FILE` for
the `install`/machine-mutation actions. It is not an RVBox process, service,
broker, or Task Scheduler dependency, and it is never used to choose a command