New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 652796 link

Starred by 1 user

Issue metadata

Status: Assigned
Owner:
Last visit > 30 days ago
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 2
Type: Feature



Sign in to add a comment

Add 5-minute delay to recovery initramfs scripts

Project Member Reported by jorgelo@chromium.org, Oct 4 2016

Issue description

This would prevent someone from switching to dev-mode and immediately using a recovery image to bypass the stateful wipe delay.
 
Labels: -Pri-1 Pri-2
Note that this behavior (switch to dev mode, reboot) is needed to run factory install shims.  

So we'd only want to fix this for normal recovery images.  The delay should only be used if dev mode is enabled via the TPM, and not if it's set via GBB (indicating someone already modified or could modify RO firmware) or if soft WP is not enabled (ditto).

Comment 3 Deleted

Sign in to add a comment