test: guard Windows active-session fixture isolation

This commit is contained in:
2026-09-09 07:20:48 +00:00
parent 6866adf0c1
commit 68ddc9d297
3 changed files with 21 additions and 4 deletions
+5 -2
View File
@@ -837,8 +837,11 @@ in a mode-0600 host-side password file, and preserve the normal Windows 10
The harness verifies that token and fails closed if policy filters it; do not
globally disable UAC or use a bypass. `test-host install` uses that identity
only to execute the staged real `rvbox.exe --install-service` path and proves it
by polling SCM. It is not an RVBox product process, a service/broker, or a Task
Scheduler dependency, and it never enters the daemon's command-context choice.
by polling SCM. It then requires that the provisioning identity is absent from
`query user`; otherwise reset before any active-session command test, because a
second logon could contaminate WTS candidate selection. It is not an RVBox
product process, a service/broker, or a Task Scheduler dependency, and it never
enters the daemon's command-context choice.
The normal active `rvboxtest` session remains the target for execution-role
tests. The consent-prompt branch itself remains an interactive UAC test; an
invisible Guest Control session must never answer it.
+6 -2
View File
@@ -187,8 +187,12 @@ remain mode `0600` on Helium and neither value is recorded in run
reports or artifacts. `test-host install` first verifies that the reset guest
has no `RVBoxClient`, checks the provisioner's High Mandatory Level, invokes
the actual staged `rvbox.exe --install-service --config ...`, and polls SCM for
`RUNNING`. `run` may then exercise reconfigure/start/restart paths. Snapshot
reset removes the installed service and all RVBox data again.
`RUNNING`. It then checks that the provisioning account is no longer present in
`query user`. A lingering Administrator session could become a second WTS
candidate and contaminate `ACTIVE_USER` / `ACTIVE_USER_ELEVATED` tests, so the
harness fails before command dispatch and the run must reset. `run` may then
exercise reconfigure/start/restart paths. Snapshot reset removes the installed
service and all RVBox data again.
The provisioner is fixture administration only: it is not shipped with RVBox,
not a product service/broker, not a Task Scheduler dependency, and never
+10
View File
@@ -250,6 +250,15 @@ assert_staged_guest() {
fail "staged guest bundle is missing rvbox.exe or client.toml"
}
assert_provisioner_absent() {
# A second logged-on Administrator could become an additional WTS active
# candidate and invalidate ACTIVE_* selection tests. Do not guess which
# account the supervisor would choose: fail before dispatch and reset.
guest_run --exe 'C:\Windows\System32\cmd.exe' --wait-stdout --wait-stderr --unquoted-args -- \
/d /s /c "query user | findstr /i /c:\"$provisioner_user\" >NUL & if errorlevel 1 echo RVBOX_GUEST_OK" >/dev/null || \
fail "fixture provisioner remains logged on; reset before active-session tests"
}
wait_guest_additions() {
attempt=0
while [ "$attempt" -lt 60 ]; do
@@ -357,6 +366,7 @@ case "$action" in
run --exe "$guest_root\\rvbox.exe" --unquoted-args -- \
--install-service --config "$guest_root\\client.toml" </dev/null >/dev/null 2>&1 || true
wait_service RUNNING
assert_provisioner_absent
step install-scm-service-running
printf 'service=RVBoxClient state=RUNNING install=clean-baseline\n'
;;