docs: define full-token Windows fixture provisioner
This commit is contained in:
@@ -830,11 +830,14 @@ Guest Control uses `rvboxtest`'s split-token, medium-integrity identity; its
|
|||||||
Administrators SID is deny-only. The reset snapshot contains no RVBox
|
Administrators SID is deny-only. The reset snapshot contains no RVBox
|
||||||
installation and the harness proves that `RVBoxClient` is absent immediately
|
installation and the harness proves that `RVBoxClient` is absent immediately
|
||||||
after every `prepare`. Do not bypass UAC or turn this active-session test user
|
after every `prepare`. Do not bypass UAC or turn this active-session test user
|
||||||
into an always-elevated account. Instead, provision a separate fixture-only
|
into an always-elevated account. Instead, enable the built-in Windows
|
||||||
full-token administrator, with its username and a mode-0600 host-side password
|
`Administrator` account only on this disposable fixture, retain its credential
|
||||||
file held outside the repository. `test-host install` uses that identity only
|
in a mode-0600 host-side password file, and preserve the normal Windows 10
|
||||||
to execute the staged real `rvbox.exe --install-service` path and proves it by
|
`FilterAdministratorToken=0` setting so Guest Control obtains a full high token.
|
||||||
polling SCM. It is not an RVBox product process, a service/broker, or a Task
|
The harness verifies that token and fails closed if policy filters it; do not
|
||||||
|
globally disable UAC or use a bypass. `test-host install` uses that identity
|
||||||
|
only to execute the staged real `rvbox.exe --install-service` path and proves it
|
||||||
|
by polling SCM. It is not an RVBox product process, a service/broker, or a Task
|
||||||
Scheduler dependency, and it never enters the daemon's command-context choice.
|
Scheduler dependency, and it never enters the daemon's command-context choice.
|
||||||
The normal active `rvboxtest` session remains the target for execution-role
|
The normal active `rvboxtest` session remains the target for execution-role
|
||||||
tests. The consent-prompt branch itself remains an interactive UAC test; an
|
tests. The consent-prompt branch itself remains an interactive UAC test; an
|
||||||
|
|||||||
+12
-7
@@ -167,18 +167,23 @@ guest deletion.
|
|||||||
therefore launches it at medium integrity and it must never be used to create
|
therefore launches it at medium integrity and it must never be used to create
|
||||||
or modify machine-wide SCM state. The reset snapshot has no RVBox installation.
|
or modify machine-wide SCM state. The reset snapshot has no RVBox installation.
|
||||||
|
|
||||||
To automate the real install path, provision one separate **fixture-only**
|
To automate the real install path, use the Windows built-in `Administrator`
|
||||||
full-token local administrator and retain its username/password solely in the
|
account as a separate **fixture-only** provisioning identity. Enable it only on
|
||||||
Helium secret store. It must be a genuinely high-integrity Guest Control token;
|
this disposable VM, keep `FilterAdministratorToken=0` (the normal Windows 10
|
||||||
do not globally disable UAC or change `rvboxtest` into an always-elevated user.
|
default), and verify that Guest Control gives it a High Mandatory Level. This
|
||||||
The normal harness receives it only through these environment variables:
|
is the per-account exception that preserves UAC for `rvboxtest`; do **not**
|
||||||
|
globally disable Admin Approval Mode or change `rvboxtest` into an
|
||||||
|
always-elevated user. Store its username/password solely in the Helium secret
|
||||||
|
store. The normal harness receives it only through these environment variables:
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
export RVBOX_TEST_PROVISIONER_USER=FIXTURE_ONLY_FULL_ADMIN
|
export RVBOX_TEST_PROVISIONER_USER=Administrator
|
||||||
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test-provisioner.password
|
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test-provisioner.password
|
||||||
```
|
```
|
||||||
|
|
||||||
Both files remain mode `0600` on Helium and neither value is recorded in run
|
If a policy or hardening configuration makes this account medium-integrity, the
|
||||||
|
harness fails closed; do not replace it with a UAC-bypass mechanism. Both files
|
||||||
|
remain mode `0600` on Helium and neither value is recorded in run
|
||||||
reports or artifacts. `test-host install` first verifies that the reset guest
|
reports or artifacts. `test-host install` first verifies that the reset guest
|
||||||
has no `RVBoxClient`, checks the provisioner's High Mandatory Level, invokes
|
has no `RVBoxClient`, checks the provisioner's High Mandatory Level, invokes
|
||||||
the actual staged `rvbox.exe --install-service --config ...`, and polls SCM for
|
the actual staged `rvbox.exe --install-service --config ...`, and polls SCM for
|
||||||
|
|||||||
+4
-2
@@ -176,8 +176,10 @@ coverage.
|
|||||||
The clean baseline intentionally contains no RVBox service, tray registration,
|
The clean baseline intentionally contains no RVBox service, tray registration,
|
||||||
or RVBox state. Guest Control supplies `rvboxtest` with a filtered medium UAC
|
or RVBox state. Guest Control supplies `rvboxtest` with a filtered medium UAC
|
||||||
token, so it cannot safely perform the first machine-wide install. The fixture
|
token, so it cannot safely perform the first machine-wide install. The fixture
|
||||||
therefore has a separate test-only full-token automation principal, whose
|
therefore uses its separately enabled built-in `Administrator` account as a
|
||||||
username and mode-600 host-side password-file are provided only as
|
test-only full-token automation principal. Its `FilterAdministratorToken` must
|
||||||
|
remain `0`, preserving UAC for `rvboxtest` rather than disabling it machine-wide.
|
||||||
|
Its username and mode-600 host-side password-file are provided only as
|
||||||
`RVBOX_TEST_PROVISIONER_USER` and `RVBOX_TEST_PROVISIONER_PASSWORD_FILE` for
|
`RVBOX_TEST_PROVISIONER_USER` and `RVBOX_TEST_PROVISIONER_PASSWORD_FILE` for
|
||||||
the `install`/machine-mutation actions. It is not an RVBox process, service,
|
the `install`/machine-mutation actions. It is not an RVBox process, service,
|
||||||
broker, or Task Scheduler dependency, and it is never used to choose a command
|
broker, or Task Scheduler dependency, and it is never used to choose a command
|
||||||
|
|||||||
Reference in New Issue
Block a user