Retaining ability to boot into RW_LEGACY after enroll

System Details

  • Device: MAGMA (Acer CB314-4h)
  • OS: ChromeOS + Linux
  • Firmware Type: RW_LEGACY
  • Firmware Version: Google_Magolor.13606.710.0 (11/08/2024)
  • Internal storage type: eMMC

Summary of the Issue

I’ve used MrChromebox’s script to install NixOS on my Chromebook, creating a separate EFI and root partition via RW_LEGACY. However, I will need to enroll the device, and I know there is the forced re-enrollment policy and the disable devmode policy. I’m wondering if I can set GBB flags to be able to keep accessing the NixOS installation. If this is not possible, would it still be possible to access the NixOS installation otherwise (maybe even booting from usb?)?

I can’t use UEFI full ROM, I need access to ChromeOS

If you force dev mode with gbb flags and then enroll the device, it will be stuck in an infinite boot loop

1 Like

Is there any other way to achieve the desired outcome?

I’ve come across a project called Modmium that can apparently modify device and user policies; I will try using it

I have managed to achieve more or less what I wanted with Modmium. Here’s how I did it:

  1. Have Modmium installed
  2. Backup ALL Chromebook user data
  3. Enable Devmode flag (this DELETES your user!)
  4. Reboot and mash ESC+Refresh+Power
  5. Switch to Devmode
  6. Boot from RW legacy that was previously created

For subsequent boots:

  1. Boot, and mash up/down arrow or you will be booted into ChromeOS which will turn off Devmode and be stuck at the logo (not the flag, just turning off Devmode)
  2. Boot into RW Legacy

To boot back into ChromeOS:

  1. Boot, and mash up/down arrow or you will be booted into ChromeOS which will turn off Devmode and be stuck at the logo (not the flag, just turning off Devmode)
  2. Choose switch back to secure mode

If you are stuck at the chromeOS logo, just do a Refresh+Power. If that doesn’t work, do ESC+Refresh+Power.

If after booting to ChromeOS, you cannot log in with your user, just Powerwash (ctrl+alt+shift+r). This will reset flags to your organization defaults but you can just remove them again