Clone this repo:
  1. 113bd7b [Invalidation] Add FM registration token upload request by Artem Sumaneev · 6 days ago main master
  2. d61cc3c CertProv: Add certificate_provisioning_process_id proto field by Michael Ershov · 7 days ago
  3. 272d9a2 Migrate TODOs referencing old crbug IDs to the new issue tracker IDs by Alison Gale · 5 weeks ago
  4. 682cbc6 Add DeviceExtensionsSystemLogEnabled policy by Maria Petrisor · 7 weeks ago
  5. bb64887 [AutoReload] Add policy definition for idp login auto reload feature by Aya El Gendy · 8 weeks ago

About //components/policy/proto

This directory contains proto definitions for communication with the device management server.

User policies

There are two protocol buffers defining the messages for user policies - chrome_settings.proto and cloud_policy.proto. Both files are auto-generated by the script from policy_templates.json, which in turn is auto-generated from the individual policy yaml files in policy_definitions. This is all done as part of building Chrome.

The reason there are two files is a compromise between readability and performance.

  • chrome_settings.proto

    This file lists all non-device policies including comments containing their detailed descriptions. Additionally every policy in this file has a distinct message type. For example, this is the message for the HomepageLocation policy:

    message HomepageLocationProto {
      optional PolicyOptions policy_options = 1;
      optional string HomepageLocation = 2;
  • cloud_policy.proto

    This file is generated for each target platform and it therefore contains only the policy messages that a certain platform supports. Additionally each field uses a generic type defined in policy_common_definitions.proto. For example this is the message for any string policy:

    message StringPolicyProto {
      optional PolicyOptions policy_options = 1;
      optional string value = 2;

The client code for each platform uses the more compact cloud_policy.proto to parse the policy blobs it receives from the device management server. On the other hand, the device management server needs to know of all the policies that exist for all the platforms, therefore chrome_settings.proto is what the server code uses.

The two files are compatible and when the messages are serialized their binary content is equivalent. CloudPolicyProtoTest.VerifyProtobufEquivalence browser test makes sure that no regressions are introduced here.