docs: define full-token Windows fixture provisioner
This commit is contained in:
@@ -830,11 +830,14 @@ Guest Control uses `rvboxtest`'s split-token, medium-integrity identity; its
|
||||
Administrators SID is deny-only. The reset snapshot contains no RVBox
|
||||
installation and the harness proves that `RVBoxClient` is absent immediately
|
||||
after every `prepare`. Do not bypass UAC or turn this active-session test user
|
||||
into an always-elevated account. Instead, provision a separate fixture-only
|
||||
full-token administrator, with its username and a mode-0600 host-side password
|
||||
file held outside the repository. `test-host install` uses that identity only
|
||||
to execute the staged real `rvbox.exe --install-service` path and proves it by
|
||||
polling SCM. It is not an RVBox product process, a service/broker, or a Task
|
||||
into an always-elevated account. Instead, enable the built-in Windows
|
||||
`Administrator` account only on this disposable fixture, retain its credential
|
||||
in a mode-0600 host-side password file, and preserve the normal Windows 10
|
||||
`FilterAdministratorToken=0` setting so Guest Control obtains a full high token.
|
||||
The harness verifies that token and fails closed if policy filters it; do not
|
||||
globally disable UAC or use a bypass. `test-host install` uses that identity
|
||||
only to execute the staged real `rvbox.exe --install-service` path and proves it
|
||||
by polling SCM. It is not an RVBox product process, a service/broker, or a Task
|
||||
Scheduler dependency, and it never enters the daemon's command-context choice.
|
||||
The normal active `rvboxtest` session remains the target for execution-role
|
||||
tests. The consent-prompt branch itself remains an interactive UAC test; an
|
||||
|
||||
+12
-7
@@ -167,18 +167,23 @@ guest deletion.
|
||||
therefore launches it at medium integrity and it must never be used to create
|
||||
or modify machine-wide SCM state. The reset snapshot has no RVBox installation.
|
||||
|
||||
To automate the real install path, provision one separate **fixture-only**
|
||||
full-token local administrator and retain its username/password solely in the
|
||||
Helium secret store. It must be a genuinely high-integrity Guest Control token;
|
||||
do not globally disable UAC or change `rvboxtest` into an always-elevated user.
|
||||
The normal harness receives it only through these environment variables:
|
||||
To automate the real install path, use the Windows built-in `Administrator`
|
||||
account as a separate **fixture-only** provisioning identity. Enable it only on
|
||||
this disposable VM, keep `FilterAdministratorToken=0` (the normal Windows 10
|
||||
default), and verify that Guest Control gives it a High Mandatory Level. This
|
||||
is the per-account exception that preserves UAC for `rvboxtest`; do **not**
|
||||
globally disable Admin Approval Mode or change `rvboxtest` into an
|
||||
always-elevated user. Store its username/password solely in the Helium secret
|
||||
store. The normal harness receives it only through these environment variables:
|
||||
|
||||
```sh
|
||||
export RVBOX_TEST_PROVISIONER_USER=FIXTURE_ONLY_FULL_ADMIN
|
||||
export RVBOX_TEST_PROVISIONER_USER=Administrator
|
||||
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test-provisioner.password
|
||||
```
|
||||
|
||||
Both files remain mode `0600` on Helium and neither value is recorded in run
|
||||
If a policy or hardening configuration makes this account medium-integrity, the
|
||||
harness fails closed; do not replace it with a UAC-bypass mechanism. Both files
|
||||
remain mode `0600` on Helium and neither value is recorded in run
|
||||
reports or artifacts. `test-host install` first verifies that the reset guest
|
||||
has no `RVBoxClient`, checks the provisioner's High Mandatory Level, invokes
|
||||
the actual staged `rvbox.exe --install-service --config ...`, and polls SCM for
|
||||
|
||||
+4
-2
@@ -176,8 +176,10 @@ coverage.
|
||||
The clean baseline intentionally contains no RVBox service, tray registration,
|
||||
or RVBox state. Guest Control supplies `rvboxtest` with a filtered medium UAC
|
||||
token, so it cannot safely perform the first machine-wide install. The fixture
|
||||
therefore has a separate test-only full-token automation principal, whose
|
||||
username and mode-600 host-side password-file are provided only as
|
||||
therefore uses its separately enabled built-in `Administrator` account as a
|
||||
test-only full-token automation principal. Its `FilterAdministratorToken` must
|
||||
remain `0`, preserving UAC for `rvboxtest` rather than disabling it machine-wide.
|
||||
Its username and mode-600 host-side password-file are provided only as
|
||||
`RVBOX_TEST_PROVISIONER_USER` and `RVBOX_TEST_PROVISIONER_PASSWORD_FILE` for
|
||||
the `install`/machine-mutation actions. It is not an RVBox process, service,
|
||||
broker, or Task Scheduler dependency, and it is never used to choose a command
|
||||
|
||||
Reference in New Issue
Block a user