diff --git a/docs/implementation-plan.v1.md b/docs/implementation-plan.v1.md index fed366c..1233006 100644 --- a/docs/implementation-plan.v1.md +++ b/docs/implementation-plan.v1.md @@ -810,7 +810,7 @@ mirror; update both documents when the fixture is reprovisioned. | Disk / source media | `/home/cabbage/VMs/rvbox-win10-test.vdi`; source ISO `/media/Data2/Downloaded/Win10_22H2_English_x64.iso` (Windows image index 6) | | Devices | Audio (`none`), playback/capture, USB (OHCI/EHCI/xHCI), clipboard/file transfer, drag-and-drop, and shared folders disabled; Intel 82540EM NIC, cable connected | | Network | NAT; last observed guest IPv4 `10.0.2.15` is DHCP state only; NAT rule `rvbox-rdp` maps host `192.168.50.162:3390` to guest `:3389` | -| Diagnostic VRDE | Enabled at `192.168.50.162:3389`, external/`VBoxAuthSimple` authentication, input/display enabled, audio/USB/clipboard/RDPDR disabled; diagnostic-only because client compatibility is unreliable | +| Diagnostic VRDE | Enabled only on Helium loopback at `127.0.0.1:3389`, external/`VBoxAuthSimple` authentication, input/display enabled, audio/USB/clipboard/RDPDR disabled; reach it only through an explicitly temporary, private SSH forward, and treat it as diagnostic-only because client compatibility is unreliable | | Native Windows RDP | Disabled in baseline (`TermService` stopped, `fDenyTSConnections=1`); port 3390 must not be treated as a usable control endpoint | | Test account | Local `rvboxtest`; split-token local administrator; console session 1 observed; Guest Control verified with `whoami`, `whoami /groups`, and `query user` | | Baseline | Reset target `baseline-clean-administrator` (UUID `ba5ce5f1-77e3-44b0-8d91-534becce27ff`): no RVBox service, tray registration, state, logs, or staged binary; built-in `Administrator` is enabled only for the fixture's high-token Guest Control installation path. Retain `baseline-clean` (UUID `5e79176a-3e56-4c5d-bb61-a405a6dcdd59`) and child `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`) as pristine diagnostics. | diff --git a/docs/testing-vm.md b/docs/testing-vm.md index 230eb51..8e34349 100644 --- a/docs/testing-vm.md +++ b/docs/testing-vm.md @@ -73,7 +73,7 @@ hard-coded into a harness. | --- | --- | | Host management | SSH to `helium-remote`, then invoke `VBoxManage`; do not assume `VBoxManage` is installed on the Linux controller | | Guest management | VirtualBox Guest Control over the host; use explicit executable/argument vectors and the password file above | -| VRDE (VirtualBox RDP) | Enabled for diagnostics at `192.168.50.162:3389`; external authentication, `VBoxAuthSimple` user `rvboxtest`, `Security/Method=negotiate`, single connection reuse, multiconnection off | +| VRDE (VirtualBox RDP) | Enabled for diagnostics on Helium loopback at `127.0.0.1:3389`; external authentication, `VBoxAuthSimple` user `rvboxtest`, `Security/Method=negotiate`, single connection reuse, multiconnection off. Reach it only through an explicitly temporary, private SSH forward. | | VRDE TLS material | Auto-generated certificate and private key under `/home/cabbage/VirtualBox VMs/RVBox/Tests/rvbox-win10-test/`; keep both on Helium and do not copy them into the repository or test artifacts | | VRDE channels | Input/display enabled; audio, upstream audio, USB, clipboard, and RDP device redirection disabled; no video channel | | Native Windows RDP forward | NAT rule `rvbox-rdp`: host `192.168.50.162:3390` to guest port `3389` | diff --git a/docs/testing.md b/docs/testing.md index cff4f70..76c8571 100644 --- a/docs/testing.md +++ b/docs/testing.md @@ -134,8 +134,8 @@ hardware and device profile, NAT and VRDE endpoints, snapshot UUIDs, credential-file contract, and the required reset sequence. At the last check the VM was powered off with `baseline-clean-administrator` selected. The guest address `10.0.2.15` is DHCP state only; use SSH plus VirtualBox Guest Control rather -than treating it as a stable endpoint. VRDE is enabled at -`192.168.50.162:3389` for diagnostics, while native Windows RDP is disabled in +than treating it as a stable endpoint. VRDE is enabled only on Helium loopback +at `127.0.0.1:3389` for diagnostics, while native Windows RDP is disabled in the baseline. The canonical headless VirtualBox/Guest Control adapter is