New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 654975 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner:
Last visit > 30 days ago
Closed: Oct 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug



Sign in to add a comment

Blacklisting all extensions ("*") via GPO overriding whitelist - "Blocked by administrator"

Project Member Reported by yye...@google.com, Oct 12 2016

Issue description

Version: 53.0.2785.116 (Official Build) m (64-bit)
OS: Windows 2012 Server

Settings Active Directory GPO to blacklist all chrome browser extensions ("*") for users on a windows domain overrides the whitelist GPO.  The intended behavior should be for the whitelisted extensions to override the blacklist all policy.


What steps will reproduce the problem?
(1) Download and install Chrome ADMX/L on windows server 2012
(2) Set "Configure extension installation blacklist" to *
(3) Set "Configure extension installation blacklist" to lhpbckonakppajdgicbjdfokagjofnob
(4) gpupdate /force
(5) make sure policy is visible in chrome://policy
(6) navigate to https://chrome.google.com/webstore/detail/visor/lhpbckonakppajdgicbjdfokagjofnob?hl=en
(7) try to manually install extension...   
(8) Receive error message:  "[Extension] is blocked by your administrator"

What is the expected output?
Since extension is whitelisted, user should be able to install the extension from the webstore manually, even though blacklist policy is set to *.


What do you see instead?
Extension is blocked by administrator error.

Reproducible: Yes


PII Protected Logs:
https://drive.google.com/drive/folders/0B6fESMmJITTNQzQ2VUg0Z2tiLW8?usp=sharing

Feedback submitted @ roughly 9:45 pm eastern - 10/11/2016
(Search feedback for "admin@yehudatest.com")

Note: filing this bug as a P1 due to potential impact to enterprise/edu customers.
 

Comment 1 by yye...@google.com, Oct 12 2016

Labels: OS-Windows

Comment 2 by yye...@google.com, Oct 12 2016

Enterprise customer noted that this issue is reproducible on Chrome Browser versions 51,52,and 53 (Windows)

Comment 3 by yye...@google.com, Oct 12 2016

TYPO:  
In "what steps will reproduce the issue"...

(3) Set "Configure extension installation blacklist" to lhpbckonakppajdgicbjdfokagjofnob

should be:

(3) Set "Configure extension installation whitelist" to lhpbckonakppajdgicbjdfokagjofnob

Comment 4 by kotah@chromium.org, Oct 12 2016

Cc: kotah@chromium.org
Project Member

Comment 5 by sheriffbot@chromium.org, Oct 12 2016

Labels: Hotlist-Google

Comment 6 by roy...@google.com, Oct 14 2016

Labels: -M-53 M-54
Owner: blumberg@chromium.org
Matt: This seems like a very bad bug. Can you triage this ?
Status: Assigned (was: Untriaged)
untriaged w/ owner -> assigned
Cc: pastarmovj@chromium.org gov...@chromium.org zmin@chromium.org georgesak@chromium.org
Krishna, can you see if we can reproduce this?

If yes, we should see when this change went live and mark as p0.

Comment 9 by gov...@chromium.org, Oct 17 2016

Cc: ligim...@chromium.org bustamante@chromium.org
+ bustamante@ on repro and prioritize as M54 is already in stable for Desktop.
Cc: ananthak@chromium.org
Per #2 this has been around since M51, if administrators have already adjusted to how the blacklist/whitelist rules work, changing that may have unintended consequences.

I reached out to our test folks to work on repro'ing it.
Labels: -M-54 M-55 ReleaseBlock-Stable
Making this is ReleaseBlock-Stable for M55 since it's been around for a while.
Cc: pbomm...@chromium.org nyerramilli@chromium.org ranjitkan@chromium.org
Assigning to few folks who can try a repro from TE. Meanwhile requesting yyefet@ to try a bisect since you already have the system setup. 

Instructions for bisecting.

https://sites.google.com/a/google.com/chrome-te/home/tools/bisect-builds
I have quickly checked this on my Windows 10 machine with Chrome version 55.0.2883.21(x64) everything works correctly, below are the steps which I have followed :

Steps Followed :
(1) Download and install Chrome ADM on windows 10
(2) Set "Configure extension installation blacklist" to *
(3) Set "Configure extension installation Whitelist" to lhpbckonakppajdgicbjdfokagjofnob
(4) Exit and relaunch Chrome
(5) Visit chrome://policy and make sure the policies has been set i.e., "ExtensionInstallBlacklist : * " and "ExtensionInstallWhitelist : lhpbckonakppajdgicbjdfokagjofnob"
(6) navigate to https://chrome.google.com/webstore/detail/visor/lhpbckonakppajdgicbjdfokagjofnob?hl=en
(7) try to manually install extension...   

Observed behavior :
Able to install the the extension which is being whitelisted.

Note : I am not sure it makes any difference w.r.t setting the policies on Windows 10 or Windows 2012 server and enforcing thtoughout the domain. Please correct me if I am wrong.

**** Bulk edit -  please ignore if not applicable ****

A friendly reminder that M55 Stable is launch is coming soon! Your bug is labelled as Stable ReleaseBlock, pls make sure to land the fix and get it merged into the release branch ASAP so it gets enough baking time in Beta (before Stable promotion). Thank you!
Labels: -ReleaseBlock-Stable
Status: WontFix (was: Assigned)
Yehuda & Royans,

Can you guys please confirm that this is an issue? I am removing release-block-stable  and marking as 'wontfix' as Prudhvi was able to confirm that everything is WAI yesterday.

Please re-open if you see other behavior.

Sign in to add a comment