test: reset Windows native runs from clean baseline
This commit is contained in:
@@ -192,7 +192,7 @@ scripts/test-e2e [--scenario NAME|all] [--run-id ID] [--resume]
|
||||
scripts/test-env doctor|coverage|status|logs|collect|recover|reuse|stop|reset|purge|gc ...
|
||||
scripts/build build|verify|doctor|recover|clean (pinned toolchain; host-safe)
|
||||
scripts/windows/build-test-bundle --run-id ID --config FILE [--ca FILE]
|
||||
scripts/windows/test-host status|prepare|stage|run|collect|stop|reset|recover
|
||||
scripts/windows/test-host status|prepare|stage|install|run|collect|stop|reset|recover
|
||||
```
|
||||
|
||||
Scripts are thin, reviewed orchestration wrappers. `scripts/test-unit` invokes
|
||||
@@ -813,8 +813,8 @@ mirror; update both documents when the fixture is reprovisioned.
|
||||
| Diagnostic VRDE | Enabled at `192.168.50.162:3389`, external/`VBoxAuthSimple` authentication, input/display enabled, audio/USB/clipboard/RDPDR disabled; diagnostic-only because client compatibility is unreliable |
|
||||
| Native Windows RDP | Disabled in baseline (`TermService` stopped, `fDenyTSConnections=1`); port 3390 must not be treated as a usable control endpoint |
|
||||
| Test account | Local `rvboxtest`; split-token local administrator; console session 1 observed; Guest Control verified with `whoami`, `whoami /groups`, and `query user` |
|
||||
| Baseline | `baseline-clean` (UUID `5e79176a-3e56-4c5d-bb61-a405a6dcdd59`) and child `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`); both are clean and must be retained |
|
||||
| Last checked state | `poweroff`, current snapshot `baseline-disk-first`; the harness must re-check state and leave the VM powered off after cleanup |
|
||||
| Baseline | Reset target `baseline-clean` (UUID `5e79176a-3e56-4c5d-bb61-a405a6dcdd59`): no RVBox service, tray registration, state, logs, or staged binary. Retain child `baseline-disk-first` (UUID `9430a9a4-754a-4b22-beaa-8dfd90043f5b`) for diagnostics only. |
|
||||
| Last checked state | `poweroff`, current snapshot `baseline-disk-first`; restore `baseline-clean` before native runs, and leave that reset target selected after cleanup |
|
||||
|
||||
The guest password, SSH key, and any host account secret are test secrets. Keep
|
||||
them in the operator/CI secret store or a mode-600 password file outside the
|
||||
@@ -826,17 +826,19 @@ overridden with `RVBOX_TEST_GUEST_PASSWORD_FILE`; the password value is never a
|
||||
default or repository value. The account name and VM metadata above are not
|
||||
credentials.
|
||||
|
||||
Guest Control uses this split-token administrator's medium-integrity token; its
|
||||
Administrators SID is deny-only. Do not bypass UAC to create the service during
|
||||
automation. A one-time interactive elevated fixture bootstrap must install the
|
||||
test `RVBoxClient` service in the reset baseline and grant `rvboxtest` only
|
||||
query/change-config/start/stop service access plus write access to its dedicated
|
||||
test subtree. Each native run then changes that bootstrapped service's explicit
|
||||
image/configuration and starts it through SCM. This is fixture administration,
|
||||
not a second product worker/elevation broker or a Task Scheduler dependency.
|
||||
Keep the exact service SDDL and test-subtree ACL with the fixture record before
|
||||
taking its replacement baseline snapshot. The production installer/UAC flow is
|
||||
tested separately through an interactive elevated lane.
|
||||
Guest Control uses `rvboxtest`'s split-token, medium-integrity identity; its
|
||||
Administrators SID is deny-only. The reset snapshot contains no RVBox
|
||||
installation and the harness proves that `RVBoxClient` is absent immediately
|
||||
after every `prepare`. Do not bypass UAC or turn this active-session test user
|
||||
into an always-elevated account. Instead, provision a separate fixture-only
|
||||
full-token administrator, with its username and a mode-0600 host-side password
|
||||
file held outside the repository. `test-host install` uses that identity only
|
||||
to execute the staged real `rvbox.exe --install-service` path and proves it by
|
||||
polling SCM. It is not an RVBox product process, a service/broker, or a Task
|
||||
Scheduler dependency, and it never enters the daemon's command-context choice.
|
||||
The normal active `rvboxtest` session remains the target for execution-role
|
||||
tests. The consent-prompt branch itself remains an interactive UAC test; an
|
||||
invisible Guest Control session must never answer it.
|
||||
|
||||
For this provisioned lane, the approved host-only credential-file location is
|
||||
`/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test.password`. It must
|
||||
@@ -861,7 +863,7 @@ identity in the run manifest:
|
||||
```sh
|
||||
export RVBOX_TEST_VBOX_HOST=helium-remote
|
||||
export RVBOX_TEST_VBOX_VM=rvbox-win10-test
|
||||
export RVBOX_TEST_VBOX_SNAPSHOT=baseline-disk-first
|
||||
export RVBOX_TEST_VBOX_SNAPSHOT=baseline-clean
|
||||
export RVBOX_TEST_GUEST_USER=rvboxtest
|
||||
export RVBOX_TEST_GUEST_PASSWORD_FILE=/secure/outside-repo/rvbox-win10-test.password
|
||||
```
|
||||
@@ -880,7 +882,7 @@ ssh "$RVBOX_TEST_VBOX_HOST" \
|
||||
|
||||
# Restore only while powered off, then boot without a GUI.
|
||||
ssh "$RVBOX_TEST_VBOX_HOST" \
|
||||
'VBoxManage snapshot "rvbox-win10-test" restore "baseline-disk-first"'
|
||||
'VBoxManage snapshot "rvbox-win10-test" restore "baseline-clean"'
|
||||
ssh "$RVBOX_TEST_VBOX_HOST" \
|
||||
'VBoxManage startvm "rvbox-win10-test" --type headless'
|
||||
|
||||
@@ -928,7 +930,7 @@ Use this shutdown/reset sequence for every native run:
|
||||
acpipowerbutton` and poll. Use `controlvm ... poweroff` only for a hung,
|
||||
disposable test; it intentionally loses guest state.
|
||||
3. Collect diagnostics while the VM is still available, then restore
|
||||
`baseline-disk-first` and verify the snapshot UUID/current marker.
|
||||
`baseline-clean` and verify the snapshot UUID/current marker.
|
||||
4. Leave the VM powered off after cleanup. Never delete either baseline
|
||||
snapshot, unregister the VM, or modify `win10_dev` (that name refers to a
|
||||
stale unregistered configuration with a missing disk on this host).
|
||||
|
||||
Reference in New Issue
Block a user