macOS 10.13 Beta3: fdesetup remove doesn't update preboot (user still able to login to FV2)

Originator:armin.praher
Number:rdar://33423544 Date Originated:July 20 2017, 11:27 AM
Status:Open Resolved:No
Product:macOS Product Version:10.13 Beta 3
Classification:Bug Reproducible:Always
 
Summary:
After removing a user from filevault2 using fdesetup remove -user, the user is still able to login to FV2 until diskutil apfs updatePreboot / is run


Steps to Reproduce:
1. fdesetup enable
2. create a new user from System Preferences (user is added to FV2)
3. Reboot to FV2 preboot, see the newly added user
4. Login with any user
5. fdesetup remove -user previouslyaddeduser
6. Reboot to FV2 preboot, notice the user is still in the list and able to boot
7. diskutil apfs updatePreboot /
8. Reboot to FV2 preboot, the user is gone now

Expected Results:
The user is removed after running fdesetup remove

Actual Results:
The user is still present in FV2

Version:
macOS 10.13 (17A306f)

Comments


Please note: Reports posted here will not necessarily be seen by Apple. All problems should be submitted at bugreport.apple.com before they are posted here. Please only post information for Radars that you have filed yourself, and please do not include Apple confidential information in your posts. Thank you!