I’ve used MrChromebox’s script to install NixOS on my Chromebook, creating a separate EFI and root partition via RW_LEGACY. However, I will need to enroll the device, and I know there is the forced re-enrollment policy and the disable devmode policy. I’m wondering if I can set GBB flags to be able to keep accessing the NixOS installation. If this is not possible, would it still be possible to access the NixOS installation otherwise (maybe even booting from usb?)?
I can’t use UEFI full ROM, I need access to ChromeOS
I have managed to achieve more or less what I wanted with Modmium. Here’s how I did it:
Have Modmium installed
Backup ALL Chromebook user data
Enable Devmode flag (this DELETES your user!)
Reboot and mash ESC+Refresh+Power
Switch to Devmode
Boot from RW legacy that was previously created
For subsequent boots:
Boot, and mash up/down arrow or you will be booted into ChromeOS which will turn off Devmode and be stuck at the logo (not the flag, just turning off Devmode)
Boot into RW Legacy
To boot back into ChromeOS:
Boot, and mash up/down arrow or you will be booted into ChromeOS which will turn off Devmode and be stuck at the logo (not the flag, just turning off Devmode)
Choose switch back to secure mode
If you are stuck at the chromeOS logo, just do a Refresh+Power. If that doesn’t work, do ESC+Refresh+Power.
If after booting to ChromeOS, you cannot log in with your user, just Powerwash (ctrl+alt+shift+r). This will reset flags to your organization defaults but you can just remove them again