diff --git a/docs/implementation-plan.v1.md b/docs/implementation-plan.v1.md index 714189e..9cf621a 100644 --- a/docs/implementation-plan.v1.md +++ b/docs/implementation-plan.v1.md @@ -837,8 +837,11 @@ in a mode-0600 host-side password file, and preserve the normal Windows 10 The harness verifies that token and fails closed if policy filters it; do not globally disable UAC or use a bypass. `test-host install` uses that identity only to execute the staged real `rvbox.exe --install-service` path and proves it -by polling SCM. It is not an RVBox product process, a service/broker, or a Task -Scheduler dependency, and it never enters the daemon's command-context choice. +by polling SCM. It then requires that the provisioning identity is absent from +`query user`; otherwise reset before any active-session command test, because a +second logon could contaminate WTS candidate selection. It is not an RVBox +product process, a service/broker, or a Task Scheduler dependency, and it never +enters the daemon's command-context choice. The normal active `rvboxtest` session remains the target for execution-role tests. The consent-prompt branch itself remains an interactive UAC test; an invisible Guest Control session must never answer it. diff --git a/docs/testing-vm.md b/docs/testing-vm.md index d723845..1f99b4d 100644 --- a/docs/testing-vm.md +++ b/docs/testing-vm.md @@ -187,8 +187,12 @@ remain mode `0600` on Helium and neither value is recorded in run reports or artifacts. `test-host install` first verifies that the reset guest has no `RVBoxClient`, checks the provisioner's High Mandatory Level, invokes the actual staged `rvbox.exe --install-service --config ...`, and polls SCM for -`RUNNING`. `run` may then exercise reconfigure/start/restart paths. Snapshot -reset removes the installed service and all RVBox data again. +`RUNNING`. It then checks that the provisioning account is no longer present in +`query user`. A lingering Administrator session could become a second WTS +candidate and contaminate `ACTIVE_USER` / `ACTIVE_USER_ELEVATED` tests, so the +harness fails before command dispatch and the run must reset. `run` may then +exercise reconfigure/start/restart paths. Snapshot reset removes the installed +service and all RVBox data again. The provisioner is fixture administration only: it is not shipped with RVBox, not a product service/broker, not a Task Scheduler dependency, and never diff --git a/scripts/windows/test-host b/scripts/windows/test-host index f2eb42f..0904c1b 100755 --- a/scripts/windows/test-host +++ b/scripts/windows/test-host @@ -250,6 +250,15 @@ assert_staged_guest() { fail "staged guest bundle is missing rvbox.exe or client.toml" } +assert_provisioner_absent() { + # A second logged-on Administrator could become an additional WTS active + # candidate and invalidate ACTIVE_* selection tests. Do not guess which + # account the supervisor would choose: fail before dispatch and reset. + guest_run --exe 'C:\Windows\System32\cmd.exe' --wait-stdout --wait-stderr --unquoted-args -- \ + /d /s /c "query user | findstr /i /c:\"$provisioner_user\" >NUL & if errorlevel 1 echo RVBOX_GUEST_OK" >/dev/null || \ + fail "fixture provisioner remains logged on; reset before active-session tests" +} + wait_guest_additions() { attempt=0 while [ "$attempt" -lt 60 ]; do @@ -357,6 +366,7 @@ case "$action" in run --exe "$guest_root\\rvbox.exe" --unquoted-args -- \ --install-service --config "$guest_root\\client.toml" /dev/null 2>&1 || true wait_service RUNNING + assert_provisioner_absent step install-scm-service-running printf 'service=RVBoxClient state=RUNNING install=clean-baseline\n' ;;