test: guard Windows active-session fixture isolation

This commit is contained in:
2026-09-09 07:20:48 +00:00
parent 6866adf0c1
commit 68ddc9d297
3 changed files with 21 additions and 4 deletions
+5 -2
View File
@@ -837,8 +837,11 @@ in a mode-0600 host-side password file, and preserve the normal Windows 10
The harness verifies that token and fails closed if policy filters it; do not
globally disable UAC or use a bypass. `test-host install` uses that identity
only to execute the staged real `rvbox.exe --install-service` path and proves it
by polling SCM. It is not an RVBox product process, a service/broker, or a Task
Scheduler dependency, and it never enters the daemon's command-context choice.
by polling SCM. It then requires that the provisioning identity is absent from
`query user`; otherwise reset before any active-session command test, because a
second logon could contaminate WTS candidate selection. It is not an RVBox
product process, a service/broker, or a Task Scheduler dependency, and it never
enters the daemon's command-context choice.
The normal active `rvboxtest` session remains the target for execution-role
tests. The consent-prompt branch itself remains an interactive UAC test; an
invisible Guest Control session must never answer it.