5. Partition map and checksums¶
The Qualcomm UFS storage on this unit holds 6 LUNs (physical_partition_number 0–5) of 4096-byte sectors in an A/B slotted layout. This page is the verified partition map: every partition’s location, size, presence in the dump, and SHA256 checksum, cross-checked against the images on disk.
5.1. Storage and dump summary¶
Storage: Qualcomm UFS, 6 LUNs (physical_partition_number 0–5), 4096-byte sectors, A/B slotted.
Program entries parsed: 95 across 6 rawprogram XML files.
SHA256 verification: 106/106 OK, 0 mismatches (
shasum -a 256 -c SHA256SUMS, exit 0). This covers every image.bin, everygpt_*table, and each rawprogram XML.Only image not present:
lun0/userdata.bin(userdata, 12,977,651 sectors ≈ 49.5 GB) — referenced inrawprogram0.xmlbut excluded from the dump (not in SHA256SUMS). Everything else referenced by XML exists.No orphan images: every
.binon disk is accounted for by a rawprogram entry.A/B slots are mostly identical — see A/B pairs are mostly identical — with exceptions below. Slot selection itself is carried in GPT attribute bits, not in
misc— see Boot-control block (misc) and A/B slot selection.Blank (all-
0x00) partitions and what each would hold:Blank partitions
What they would hold
keystore,ssdcredential/secure-storage blobs; unprovisioned (
keystoreis re-confirmed byte-for-byte in Security and DRM userspace)apdp,spunvm,secdata,storsecanti-rollback/DP provisioning, SPU NV, MDTP secure data, secure-storage seed — none provisioned
mdtp_a/b,mdtpsecapp_a/bMobile Device Theft Protection image + data — MDTP disabled (Secure world and coprocessors (TZ, HYP, trustlets))
catefv,cateloader,catecontentfv,toolsfv,questdatafvmanufacturing / field-diagnostic UEFI FVs — empty on production
dip,limits-cdsp,cdtdevice-info provisioning, CDSP thermal limits, CDT (board identity — decoded in Platform state partitions: cdt, ddr, uefivarstore) — empty
fsc,fsgmodem filesystem cache/gold — no cellular provisioning
recovery_b,vbmeta_system_bslot-B recovery and vbmeta_system — not populated (see below)
splash(32.6 MB)boot/charging imagery — XBL disables splash-partition loading, see Splash partition; its zero-hash is unique to its size, so it is not in the shared zero-hash groups below
The near-blank state partitions —
misc(below),devinfo(AVB enforcement code path (LoadImageAndAuth / libavb)),ddr/uefivarstore(Platform state partitions: cdt, ddr, uefivarstore),frp(Security and DRM userspace) — carry a small amount of real structure and are documented on their own pages.Not blank, despite sitting next to blank ``fsg``/``fsc``:
modemst1/modemst2(LUN5) are 99.6% non-zero, real Qualcomm EFS2 modem-NV-store images — see ADSP and CDSP firmware.
5.2. Partition map by LUN¶
5.2.1. UFS LUN 0 — bulk/userspace (super, userdata, persist, metadata, config)¶
Label |
File |
Start sector |
Start byte |
Sectors |
Size |
On disk |
SHA256 (12) |
|---|---|---|---|---|---|---|---|
PrimaryGPT |
|
0 |
|
6 |
24 KB |
yes |
|
ssd |
|
6 |
|
2 |
8 KB |
yes |
|
persist |
|
8 |
|
8192 |
32.0 MB |
yes |
|
misc |
|
8200 |
|
256 |
1.0 MB |
yes |
|
keystore |
|
8456 |
|
128 |
512 KB |
yes |
|
frp |
|
8584 |
|
128 |
512 KB |
yes |
|
metadata |
|
8712 |
|
4096 |
16.0 MB |
yes |
|
rawdump |
|
12808 |
|
32768 |
128.0 MB |
yes |
|
super |
|
45576 |
|
1572864 |
6.00 GB |
yes |
|
onyxconfig |
|
1618440 |
|
6144 |
24.0 MB |
yes |
|
userdata |
|
1624584 |
|
12977651 |
49.51 GB |
NO |
|
BackupGPT |
|
|
|
5 |
20 KB |
yes |
|
5.2.2. UFS LUN 1 — boot slot A firmware (xbl_a)¶
Label |
File |
Start sector |
Start byte |
Sectors |
Size |
On disk |
SHA256 (12) |
|---|---|---|---|---|---|---|---|
PrimaryGPT |
|
0 |
|
6 |
24 KB |
yes |
|
xbl_a |
|
6 |
|
896 |
3.5 MB |
yes |
|
xbl_config_a |
|
902 |
|
32 |
128 KB |
yes |
|
BackupGPT |
|
|
|
5 |
20 KB |
yes |
|
5.2.3. UFS LUN 2 — boot slot B firmware (xbl_b)¶
Label |
File |
Start sector |
Start byte |
Sectors |
Size |
On disk |
SHA256 (12) |
|---|---|---|---|---|---|---|---|
PrimaryGPT |
|
0 |
|
6 |
24 KB |
yes |
|
xbl_b |
|
6 |
|
896 |
3.5 MB |
yes |
|
xbl_config_b |
|
902 |
|
32 |
128 KB |
yes |
|
BackupGPT |
|
|
|
5 |
20 KB |
yes |
|
5.2.4. UFS LUN 3 — platform config (cdt, ddr)¶
Label |
File |
Start sector |
Start byte |
Sectors |
Size |
On disk |
SHA256 (12) |
|---|---|---|---|---|---|---|---|
PrimaryGPT |
|
0 |
|
6 |
24 KB |
yes |
|
ALIGN_TO_128K_1 |
|
6 |
|
26 |
104 KB |
yes |
|
cdt |
|
32 |
|
32 |
128 KB |
yes |
|
ddr |
|
64 |
|
256 |
1.0 MB |
yes |
|
BackupGPT |
|
|
|
5 |
20 KB |
yes |
|
5.2.5. UFS LUN 4 — main A/B firmware set (63 partitions)¶
Label |
File |
Start sector |
Start byte |
Sectors |
Size |
On disk |
SHA256 (12) |
|---|---|---|---|---|---|---|---|
PrimaryGPT |
|
0 |
|
6 |
24 KB |
yes |
|
aop_a |
|
6 |
|
128 |
512 KB |
yes |
|
tz_a |
|
134 |
|
1024 |
4.0 MB |
yes |
|
multiimgoem_a |
|
1158 |
|
8 |
32 KB |
yes |
|
hyp_a |
|
1166 |
|
128 |
512 KB |
yes |
|
modem_a |
|
1294 |
|
49920 |
195.0 MB |
yes |
|
bluetooth_a |
|
51214 |
|
256 |
1.0 MB |
yes |
|
mdtpsecapp_a |
|
51470 |
|
1024 |
4.0 MB |
yes |
|
mdtp_a |
|
52494 |
|
8192 |
32.0 MB |
yes |
|
abl_a |
|
60686 |
|
256 |
1.0 MB |
yes |
|
dsp_a |
|
60942 |
|
16384 |
64.0 MB |
yes |
|
keymaster_a |
|
77326 |
|
128 |
512 KB |
yes |
|
boot_a |
|
77454 |
|
24576 |
96.0 MB |
yes |
|
devcfg_a |
|
102030 |
|
32 |
128 KB |
yes |
|
qupfw_a |
|
102062 |
|
20 |
80 KB |
yes |
|
recovery_a |
|
102082 |
|
24576 |
96.0 MB |
yes |
|
vbmeta_system_a |
|
126658 |
|
16 |
64 KB |
yes |
|
vbmeta_a |
|
126674 |
|
16 |
64 KB |
yes |
|
dtbo_a |
|
126690 |
|
6144 |
24.0 MB |
yes |
|
imagefv_a |
|
132834 |
|
512 |
2.0 MB |
yes |
|
uefisecapp_a |
|
133346 |
|
512 |
2.0 MB |
yes |
|
core_nhlos_a |
|
133858 |
|
43520 |
170.0 MB |
yes |
|
featenabler_a |
|
177378 |
|
32 |
128 KB |
yes |
|
questdatafv |
|
177410 |
|
4096 |
16.0 MB |
yes |
|
aop_b |
|
181506 |
|
128 |
512 KB |
yes |
|
tz_b |
|
181634 |
|
1024 |
4.0 MB |
yes |
|
multiimgoem_b |
|
182658 |
|
8 |
32 KB |
yes |
|
hyp_b |
|
182666 |
|
128 |
512 KB |
yes |
|
modem_b |
|
182794 |
|
49920 |
195.0 MB |
yes |
|
bluetooth_b |
|
232714 |
|
256 |
1.0 MB |
yes |
|
mdtpsecapp_b |
|
232970 |
|
1024 |
4.0 MB |
yes |
|
mdtp_b |
|
233994 |
|
8192 |
32.0 MB |
yes |
|
abl_b |
|
242186 |
|
256 |
1.0 MB |
yes |
|
dsp_b |
|
242442 |
|
16384 |
64.0 MB |
yes |
|
keymaster_b |
|
258826 |
|
128 |
512 KB |
yes |
|
boot_b |
|
258954 |
|
24576 |
96.0 MB |
yes |
|
devcfg_b |
|
283530 |
|
32 |
128 KB |
yes |
|
qupfw_b |
|
283562 |
|
20 |
80 KB |
yes |
|
recovery_b |
|
283582 |
|
24576 |
96.0 MB |
yes |
|
vbmeta_system_b |
|
308158 |
|
16 |
64 KB |
yes |
|
vbmeta_b |
|
308174 |
|
16 |
64 KB |
yes |
|
dtbo_b |
|
308190 |
|
6144 |
24.0 MB |
yes |
|
featenabler_b |
|
314334 |
|
32 |
128 KB |
yes |
|
imagefv_b |
|
314366 |
|
512 |
2.0 MB |
yes |
|
uefisecapp_b |
|
314878 |
|
512 |
2.0 MB |
yes |
|
core_nhlos_b |
|
315390 |
|
43520 |
170.0 MB |
yes |
|
devinfo |
|
358910 |
|
1 |
4 KB |
yes |
|
dip |
|
358911 |
|
256 |
1.0 MB |
yes |
|
apdp |
|
359167 |
|
64 |
256 KB |
yes |
|
spunvm |
|
359231 |
|
2048 |
8.0 MB |
yes |
|
splash |
|
361279 |
|
8356 |
32.6 MB |
yes |
|
limits |
|
369635 |
|
1 |
4 KB |
yes |
|
limits-cdsp |
|
369636 |
|
1 |
4 KB |
yes |
|
toolsfv |
|
369637 |
|
256 |
1.0 MB |
yes |
|
logfs |
|
369893 |
|
2048 |
8.0 MB |
yes |
|
cateloader |
|
371941 |
|
512 |
2.0 MB |
yes |
|
logdump |
|
372453 |
|
16384 |
64.0 MB |
yes |
|
storsec |
|
388837 |
|
32 |
128 KB |
yes |
|
uefivarstore |
|
388869 |
|
128 |
512 KB |
yes |
|
secdata |
|
388997 |
|
7 |
28 KB |
yes |
|
catefv |
|
389004 |
|
128 |
512 KB |
yes |
|
catecontentfv |
|
389132 |
|
256 |
1.0 MB |
yes |
|
BackupGPT |
|
|
|
5 |
20 KB |
yes |
|
5.2.6. UFS LUN 5 — modem NV storage (modemst/fsg/fsc)¶
Label |
File |
Start sector |
Start byte |
Sectors |
Size |
On disk |
SHA256 (12) |
|---|---|---|---|---|---|---|---|
PrimaryGPT |
|
0 |
|
6 |
24 KB |
yes |
|
ALIGN_TO_128K_2 |
|
6 |
|
26 |
104 KB |
yes |
|
modemst1 |
|
32 |
|
640 |
2.5 MB |
yes |
|
modemst2 |
|
672 |
|
640 |
2.5 MB |
yes |
|
fsg |
|
1312 |
|
640 |
2.5 MB |
yes |
|
fsc |
|
1952 |
|
32 |
128 KB |
yes |
|
BackupGPT |
|
|
|
5 |
20 KB |
yes |
|
5.3. Duplicate-hash groups (byte-identical images)¶
A/B pairs proving both slots hold the same image, plus blank partitions sharing an all-zero hash.
SHA256 (12) |
Files |
Note |
|---|---|---|
|
|
blank / all-0x00 |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
blank / all-0x00 |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
A/B slots identical |
|
|
|
|
|
blank / all-0x00 |
5.4. A/B pairs are mostly identical — with exceptions¶
Most _a/_b firmware pairs are byte-identical (one shared SHA-256,
per the duplicate-hash groups above): xbl, xbl_config, boot,
tz, abl, vbmeta, dtbo, modem all match across slots. The
exceptions are the partitions whose slot B is blank: recovery_b
(slot A is a full 100 MB image) and vbmeta_system_b (slot A populated).
So the general “both slots equal” picture holds for the core firmware but
not for recovery or vbmeta_system.
5.5. Boot-control block (misc) and A/B slot selection¶
misc.bin (LUN0, 1 MB) is the standard Android/Qualcomm bootloader
message block. On this unit it is idle:
command[0:32],status[32:64],recovery[64:...]— all empty (no pending “boot-recovery” / “bootonce-bootloader” command).The AOSP A/B
bootloader_control(magicBCAB) is not present inmisc— there is no_a/_bsuffix or slot struct anywhere in it. Slot state lives in the GPT instead (below).A single ~15-byte record sits at
0x8000(02 b0 0a 74 56 …) — vendor/OTA bookkeeping, not the AOSP slot struct.
So the classic “write a command to misc and reboot to recovery” path
exists (the fields are there and ABL’s RESET_PARAM/recovery handling
reads them — Physical keys: power, volume, and the boot-mode dispatcher), but slot selection does not go
through misc here.
This is a slotted device, but the active-slot / retry / success
bookkeeping is carried in the GPT partition-entry attribute field (the
top 16 bits of the 8-byte attributes), exactly as ABL’s
PartitionTableUpdate.h defines:
Field |
Bit(s) |
Meaning |
|---|---|---|
|
48–49 |
2-bit slot priority (0–3); highest wins |
|
50 |
slot is the active/selected one |
|
51–53 |
3-bit remaining boot attempts (0–7) |
|
54 |
slot booted successfully at least once |
|
55 |
slot must not be tried |
|
60 |
partition is read-only (immutable firmware) |
Decoded live from gpt_main4.bin:
Partition |
Attributes |
Decode |
|---|---|---|
|
|
prio=3 active=1 retry=6 success=1 — the live, healthy slot |
|
|
prio=0 inactive — dormant/empty slot |
|
|
active=1 success=1 ro=1 — immutable firmware, slot A |
|
|
active=1 success=1 ro=0 — updatable, slot A |
firmware |
|
inactive, |
This “inactive, ro=1” pattern holds for modem_b, bluetooth_b,
mdtpsecapp_b, mdtp_b, abl_b, dsp_b and keymaster_b, but
it is not a universal rule: tz_b, hyp_b, aop_b and
multiimgoem_b all read 0x0000000000000000 — inactive with no
ro bit set at all — even though these are populated, byte-identical
firmware (per the previous section, which lists tz as byte-identical
across slots). So a firmware-B slot being populated does not guarantee its
GPT entry carries ro=1.
The selection rule XBL/ABL implement: among a partition’s slots, pick the
highest PRIORITY that is not UNBOOTABLE and has retry > 0;
decrement retry per attempt; the OS sets SUCCESS once it confirms a
good boot. The READONLY bit (60) cleanly separates the immutable
firmware (xbl, tz, aop, modem, abl, dsp,
keymaster, vbmeta — ro=1 on their _a slots) from the
mutable partitions (boot, recovery, dtbo, devcfg,
qupfw, hyp, xbl_config — ro=0); this divides less cleanly on
the _b slots (above). A bootloader that replaces
ABL must honour these bits (or deliberately ignore slots and boot _a
unconditionally, which is valid on a single-active-slot unit like this
one).
5.6. GPT type / unique / disk GUIDs¶
Extracted directly from the gpt_main{0..5}.bin tables (not the rawprogram
XML, which carries only labels/offsets). Two structural facts matter for a
bootloader that resolves partitions by type GUID rather than by name:
Every
_aslot partition on LUN4 carries a distinct type GUID; every_bslot partition shares one placeholder type GUID77036cd4-03d5-42bb-8ed1-37e5a88baa34. So a type-GUID lookup uniquely identifies_apartitions but cannot distinguish_bpartitions from one another — name-based lookup (as stock ABL uses) has no such asymmetry.Per-LUN disk GUIDs: present (one random UUID per LUN, standard GPT disk identity) but not reproduced here — each is unique per physical unit (generated at factory flash time), unlike the type GUIDs below which are fixed by the firmware build and identical across every unit.
Boot-chain _a type GUIDs (LUN1/LUN4), the ones a replacement loader would key
on:
Partition |
Type GUID |
|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
The remaining partitions’ type/unique GUIDs are reproducible from the
gpt_main*.bin tables (standard GPT: 92-byte header at the second block,
128-byte entries following; 4096-byte sectors on this unit).
5.7. Provenance¶
- Source:
../_READONLY/rawprogram[0-5].xml(Qualcomm firehose flash descriptors) and the images on disk;../_READONLY/SHA256SUMS;../_READONLY/lun[0-5]/gpt_main*.bin(GPT type/unique/disk GUIDs).- Method:
Parse
rawprogram[0-5].xmlinto 95 program entries; cross-check everyfilename=against files on disk (1 missing: userdata; 0 orphans); runshasum -a 256 -c SHA256SUMSover all ~13 GB (106/106 OK); verify blank partitions with a distinct-byte-value scan (single value0x00); GPT attribute bits decoded perQcomModulePkg/Include/Library/ PartitionTableUpdate.h.- Cross-refs:
Splash partition (blank splash partition), Security and DRM userspace (persist/metadata/keystore/frp content), ADSP and CDSP firmware (modemst1/2 content), Platform state partitions: cdt, ddr, uefivarstore (cdt/ddr/uefivarstore), AVB enforcement code path (LoadImageAndAuth / libavb) (devinfo lock state), Physical keys: power, volume, and the boot-mode dispatcher (misc/RESET_PARAM recovery path).