New issue
Advanced search Search tips

Issue 889893 link

Starred by 3 users

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug



Sign in to add a comment

[chromad] Devices booted from Developer mode unexpectedly - NO policy blocking dev mode

Project Member Reported by alu...@chromium.org, Sep 27

Issue description

Chrome OS Version: 69


What steps will reproduce the problem?
-Put device in DEV mode and install test image
- Login get to Chromad Chromebox
-Reboot
- See boot message "Developer mode is disabled on this device by system policy"

What is the expected result?   DEV mode working

What happens instead?  Developer mode blocked, device is wiped.


LOGS:  See crbug.com/887232 where we collected data in DEV before it rebooted to verified mode.


 
IMG_20180925_160451.jpg
2.9 MB View Download
Screenshot 2018-09-27 at 7.11.04 AM.png
13.4 KB View Download
This issue was reported by customer and debug auth_policy enabled for logging are in  crbug.com/887232.  

I was able to reproduce this internally on my device with chromadm-lab domain. Have never configured the policy.

Do we need any specific logs? Is this expected for a TEST build image?


I don't think we do anything special for dev mode on AD devices.
Are you sure DeviceBlockDevmode is not set?
If it's not set on any GPO - this is a bug. Could you check the same case with cloud management?
Cc: emaxx@chromium.org rsorokin@chromium.org igorcov@chromium.org
Labels: Enterprise-Triaged
aluong@: Does this issue happen only with Active Directory managed devices?
Owner: rsorokin@chromium.org
Status: Assigned (was: Untriaged)
Cc: ljusten@chromium.org
Labels: -Pri-3 Pri-1
Owner: aghuie@chromium.org
Apparently we use DevBlockMode setting from the cloud policy. Which I guess is enabled because FRE is enabled? How should we handle it?
Issue 893300 has been merged into this issue.
Cc: sinhak@chromium.org
 Issue 907455  has been merged into this issue.
I thought FRE was disabled on all production domains?
Just to confirm with folks on this thread. This is not with a customer's production domain right? 

It looks like this is tied to chromadm-lab domain only? Any chance FRE was enabled on this domain for testing?
Project Member

Comment 11 by bugdroid1@chromium.org, Dec 7

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/5e0cf7a00cbfd603110566ea6754f2db68e6e40b

commit 5e0cf7a00cbfd603110566ea6754f2db68e6e40b
Author: Roman Sorokin <rsorokin@chromium.org>
Date: Fri Dec 07 13:34:27 2018

Mark DeviceBlockDevmode support by google_cloud only

Active Directory devices apply the setting that come from device
cloud policy.

BUG=chromium:889893

Change-Id: I0738f35dfdad56042c388699f811b43f3a530501
Reviewed-on: https://chromium-review.googlesource.com/c/1365595
Commit-Queue: Roman Sorokin <rsorokin@chromium.org>
Reviewed-by: Lutz Justen <ljusten@chromium.org>
Cr-Commit-Position: refs/heads/master@{#614681}
[modify] https://crrev.com/5e0cf7a00cbfd603110566ea6754f2db68e6e40b/components/policy/resources/policy_templates.json

Hi customer using chrome active directory is reporting this today Chrome 72. Policy from AD was set to no block dev mode, however it didn't work. Customer also deprovisioned in ChromAD cloud console as well. 

Workaround that was successful:
Wipe device
Sign in with personal Gmail account
Wipe device
Set DEV mode

Result: no more messages saying ""Developer mode is disabled on this device by system policy"


Policy from AD does nothing. It depends on policy from cloud during enrollment

Sign in to add a comment