Android系统防止从非预期/已升级分区启动的技术问询
Great question—this digs into the core of Android's A/B (Seamless) System Updates, a feature that redefined OTA upgrades starting with Nougat. Let’s break down your questions one by one:
How does the system avoid booting from the original partition?
When you start an OTA update, the system first validates the update package’s integrity to confirm it’s unmodified and official. Once cleared, it writes the new system files to the inactive (secondary) partition.
After the write finishes successfully, the system updates a boot partition selector flag that tells the bootloader which partition to use on the next reboot. The bootloader reads this flag during startup and boots the newly updated partition instead of the original one.
There’s also a safety net: if the new partition fails to boot properly (like crashing on first start), the bootloader will automatically roll back to the original partition after a set number of failed attempts. This stops your device from getting bricked if the update goes sideways.
Where is the boot partition decision stored?
The exact spot varies a bit by manufacturer, but here are the most common locations:
miscpartition: A small, dedicated partition for boot-related flags and metadata. The active slot suffix (e.g.,_afor primary,_bfor secondary) is often stored here in a specific field.- Bootloader internal storage: Some devices keep this flag in a non-volatile memory region inside the bootloader itself (like Qualcomm’s ABOOT or Samsung’s BL).
- EF Variables: On Android devices using UEFI bootloaders (less common), this info might live in EFI variables.
If you have a rooted device, you can check the current active slot with this command:
bootctl get-current-slot
How is this information protected from attackers?
Android uses multiple security layers to block tampering with the boot partition selector:
- Locked Bootloader (BL Lock): When enabled, the bootloader only accepts official, signed updates. Any attempt to modify the boot flag without a valid manufacturer signature gets rejected.
- Signed Update Packages: OTAs are signed with the manufacturer’s private key. The system will only apply an update if the signature checks out, so attackers can’t push malicious updates that switch the boot flag.
- Restricted Storage Access: The
miscpartition or bootloader storage holding the boot flag is locked down—only trusted system processes (like the update service or recovery mode) have write permission. - Hardware-Level Security: High-end devices use a Hardware Security Module (HSM) or Trusted Execution Environment (TEE) to store critical boot metadata. These modules are isolated from the main OS, making software-based tampering way harder.
- Boot Verification: Before booting, the bootloader checks the integrity of the selected system partition. If the partition has been modified (say, an attacker tries to switch to a malicious one), the bootloader will refuse to start it and may trigger a rollback.
内容的提问来源于stack exchange,提问作者stflow

