test: add temporary Guacamole fixture access helper
This commit is contained in:
@@ -20,6 +20,8 @@ Read the documents in this order:
|
||||
8. [Provisioned Windows test VM](testing-vm.md) — exact fixture identity,
|
||||
host/guest access, endpoints, snapshots, credentials contract, reset
|
||||
procedure, and known limitations.
|
||||
9. [Interactive VM access](../test/rdp-access/README.md) — temporary,
|
||||
self-signed HTTPS browser gateway for the rare manual UAC recovery step.
|
||||
|
||||
The wire authority is in [`../protos/rvbox/v1`](../protos/rvbox/v1):
|
||||
`common.proto` contains shared data types, `agent.proto` contains the
|
||||
|
||||
@@ -847,6 +847,14 @@ The normal active `rvboxtest` session remains the target for execution-role
|
||||
tests. The consent-prompt branch itself remains an interactive UAC test; an
|
||||
invisible Guest Control session must never answer it.
|
||||
|
||||
When that bounded manual step is necessary, use the tracked Docker-only
|
||||
[`test/rdp-access`](../test/rdp-access/README.md) helper. It starts a
|
||||
self-signed HTTPS Guacamole gateway only after `test-host prepare` holds the
|
||||
fixture lease; VRDE remains loopback-only on Helium and its SSH tunnel is bound
|
||||
only to the helper's private Docker gateway. Stop the helper before the normal
|
||||
`test-host reset`. It is a recovery interface, not a product component or a
|
||||
replacement for Guest Control/native test automation.
|
||||
|
||||
For this provisioned lane, the approved host-only credential-file location is
|
||||
`/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password`. It must
|
||||
remain mode `0600`, is never read into a repository process, and is supplied to
|
||||
|
||||
@@ -85,6 +85,12 @@ VirtualBox 7.2.16 does not handle reliably, and earlier probes included
|
||||
headless-server crashes. Use Guest Control for deterministic setup, execution,
|
||||
and collection. Do not expose the VM's RDP endpoints beyond the test LAN.
|
||||
|
||||
For the rare interactive UAC/manual-recovery step, use the Docker-only helper
|
||||
in [`test/rdp-access`](../test/rdp-access/README.md). It creates a temporary
|
||||
self-signed HTTPS Guacamole gateway while retaining VRDE on Helium loopback and
|
||||
the SSH tunnel on a private Docker gateway. Follow its full lease/prepare/up/
|
||||
down/reset lifecycle; it is not an alternative to the native test controller.
|
||||
|
||||
## Snapshots and reset contract
|
||||
|
||||
Three clean snapshots exist and must be retained. `baseline-clean-administrator`
|
||||
|
||||
@@ -138,6 +138,11 @@ than treating it as a stable endpoint. VRDE is enabled only on Helium loopback
|
||||
at `127.0.0.1:3389` for diagnostics, while native Windows RDP is disabled in
|
||||
the baseline.
|
||||
|
||||
Interactive browser access is a deliberately temporary recovery path only. See
|
||||
[`test/rdp-access`](../test/rdp-access/README.md) for the Docker-only,
|
||||
self-signed HTTPS Guacamole lifecycle; it must be started only after the native
|
||||
fixture controller has prepared and leased the VM, and stopped before reset.
|
||||
|
||||
The canonical headless VirtualBox/Guest Control adapter is
|
||||
`scripts/windows/test-host`. It is a POSIX controller script because the
|
||||
fixture's VirtualBox host is Arch Linux and has no PowerShell runtime. The
|
||||
|
||||
Reference in New Issue
Block a user