DroidBoot is an advanced, bare-metal x86 firmware bootloader that turns any Android smartphone (or USB storage device) into a universal, multi-OS boot medium for PCs and laptops.
You can download stock .iso files directly onto your phone (Kali Linux, Ubuntu, Windows, Alpine) and boot a dead or blank PC from your phone over a standard USB cableβwith 0 MB of the multi-gigabyte OS loaded into PC RAM.
graph TD
subgraph TheProblem["The Problem Today"]
P1["π» PC Bootloader / OS Crashes<br>β’ Blue Screen / Corrupted Grub<br>β’ Need emergency recovery"]
P2["β No Bootable USB Nearby<br>β’ Traditional tools (Rufus, Etcher, dd) require a working PC<br>β’ Flashing wipes your drive and holds only ONE OS"]
P3["π± Android Smartphone in Pocket<br>β’ 128 GB+ high-speed storage & USB-C<br>β’ But PCs CANNOT boot from Android phones!<br>β’ Android only exposes MTP (file transfer), not a bootable block device!"]
end
subgraph TheSolution["The DroidBoot Solution"]
S1["π DroidBoot Bare-Metal Engine<br>β’ Tiny bootloader on a micro-SD card or key<br>β’ Native bare-metal xHCI USB 3.0 driver"]
S2["β‘ Hardware-Level SCSI Emulation<br>β’ Rebinds phone's Linux USB gadget (ConfigFS)<br>β’ Phone acts as a physical USB CD-ROM / Flash Drive<br>β’ Streams 5 GB ISOs on-demand (0 MB RAM used!)"]
S3["π― Instant Multi-OS Booting<br>β’ Kali Linux Installer / Live<br>β’ Ubuntu with Persistent Data Overlay<br>β’ Alpine Linux & Windows 10/11"]
end
TheProblem ==> TheSolution
- The "Stranded with a Dead PC" Crisis: When your PC crashes while traveling or at home, you typically need another working PC to download an ISO and write it to a dedicated USB drive using tools like Rufus or Etcher. With DroidBoot, your phone is the installer drive.
- The "Single-Purpose Flashed USB" Waste: Standard bootable USB drives can only hold one flashed operating system at a time. If you want Ubuntu, Kali Linux, and Windows, you must carry three separate USB drives or constantly reformat.
- The Android MTP Barrier: Your smartphone has 128 GBβ256 GB+ of fast flash storage, but motherboards and BIOS firmware cannot boot from it because modern smartphones only expose the high-level Media Transfer Protocol (MTP) over USB, not low-level SCSI mass storage blocks.
- The "Out-of-RAM" Crash on Low-Spec Hardware: Network booting (PXE) or RAM disk loaders require buffering the entire 4 GBβ6 GB ISO into the PC's memory before booting, immediately crashing laptops with only 2 GB or 4 GB of RAM.
The Core MVP of DroidBoot is booting full operating systems directly from an Android phone (or USB storage) with zero manual ISO burning, zero wasted RAM, and isolated persistent storage for your settings.
flowchart TD
A["1. PC Powers On (Legacy BIOS / CSM)"] --> B["2. Boots DroidBoot from SD Card Reader<br>β’ Stage 1 (MBR) β Stage 2 (Bootstrap) β Stage 3 (C Kernel)"]
B --> C["3. Initializes Bare-Metal xHCI USB 3.0 Driver Stack"]
C --> D["4. Probes USB Ports & Communicates with Phone"]
D --> E1["Rooted Phone / UMS Mode<br>(ConfigFS Gadget Controller)"]
D --> E2["Non-Rooted Phone / MTP Mode<br>(Universal PTP Initiator)"]
E1 --> F1["Direct Block Access Mode (0 MB in RAM!)<br>β’ ADB dynamically binds LUN 0 to selected ISO<br>β’ ADB dynamically binds LUN 1 to persistent data overlay<br>β’ Streams vmlinuz + initramfs into memory<br>β’ Rest of 5 GB OS streams on-demand over USB wire"]
E2 --> F2["In-RAM Streaming Mode (No Root Required)<br>β’ Traverses phone storage via PTP datasets<br>β’ Streams ISO chunks into high RAM cache (0x10000000)<br>β’ Deploys mBFT ACPI table at 0x000E0000 for Alpine"]
F1 & F2 --> G["5. Interactive VGA Boot Menu (TUI)<br>β’ Live countdown, arrow-key navigation, cmdline editor"]
G --> H1["Linux 32-bit Boot Protocol Engine<br>β’ Prepares Zero Page (boot_params at 0x00090000)<br>β’ Collision-free initramfs boundary placement<br>β’ Hands off execution directly to Linux Kernel!"]
G --> H2["Real-Mode Chainloader (Windows / BSD)<br>β’ Configures optical SCSI emulation (cdrom=1)<br>β’ Drops CPU back to 16-bit Real Mode via bios_thunk.S<br>β’ Hands off execution to bootmgr!"]
H1 --> I1["π§ Running Linux (Kali Linux, Ubuntu Casper, Alpine)"]
H2 --> I2["πͺ Running Windows Setup (Streams install.wim on-demand)"]
DroidBoot cleanly separates the Boot Mechanism from the Media Storage Vault:
graph LR
subgraph HostPC["Target PC / Laptop"]
BIOS["Legacy BIOS (Boot Drive 0x80)"]
XHCI["xHCI USB 3.0 Controller"]
end
subgraph Port1["USB Port A: The Boot Key"]
READER["USB Card Reader"]
SD["Micro-SD Card (boot.img)<br>β’ Stage 1, Stage 2, Stage 3 Kernel<br>β’ Persistent Diagnostic Logs (BOOTLOG.TXT)"]
end
subgraph Port2["USB Port B: The Media Vault"]
PHONE["Android Smartphone (whyred / Redmi Note 5 Pro)<br>β’ /sdcard/Download/*.iso<br>β’ /sdcard/BootManager/persistence/*.casper-rw<br>β’ ConfigFS Dynamic Multi-LUN Gadget"]
end
BIOS -->|Boots from| READER
READER --- SD
XHCI -->|Enumerates| READER
XHCI -->|Streams Data from| PHONE
- LUN 0 (Target OS ISO): When you select an OS in the boot menu, the phone binds
lun.0to that specific ISO in under 1 second. - LUN 1 (Persistent User Overlay): Automatically binds that distribution's matching
.casper-rwext4 overlay disk so your files, browser tabs, and packages persist across reboots.
| Distribution / OS | Version Tested | Boot Strategy | Status |
|---|---|---|---|
| Kali Linux | 2026.2-installer-amd64.iso |
Direct Block Access (UMS) / Linux 32-bit Protocol | VERIFIED (100% Pass) |
| Ubuntu Desktop | 26.04.1-desktop-amd64.iso |
Direct Block Access (Casper Live + Persistence) | VERIFIED (100% Pass) |
| Alpine Linux | alpine-standard-3.24.2-x86_64.iso |
In-RAM Staging (mBFT Table + phram) | VERIFIED (100% Pass) |
| Arch Linux / Fedora | Generic Live ISOs | Direct Block Access via Rock Ridge Parser | SUPPORTED |
| Microsoft Windows | Windows 10 / Windows 11 | Real-Mode VBR Chainloading (cdrom=1 SCSI Optical) |
PLANNED (Phase 18) |
All in-depth technical specifications and guides are located in the docs/ directory:
| Document | Description |
|---|---|
| ARCHITECTURE.md | Deep technical specifications, hardware driver stack, and Mermaid flowcharts. |
| DEVELOPER_GUIDE.md | Contributor reference, bare-metal coding constraints, and diagnostic workflows. |
| ADDING_NEW_OS.md | Step-by-step developer tutorial: How to add support for any new Linux distro or Windows. |
| MEMORY_MAP.md | Physical memory layout (0x0000_0000 to 4 GiB) and collision-free initrd boundaries. |
| BOOT_IMAGE_FORMAT.md | Exact on-disk sector layout (LBA 0 to 2048+) and raw persistent log structures. |
| PROJECT_STATUS.md | Subsystem verification matrix and development roadmap (Phases 0 through 18). |
| TESTING.md | QEMU automated regression test harness, QMP hotplugging, and physical phone passthrough. |
| THIRD_PARTY.md | Upstream open-source components and licensing tracking. |
- Assembler: NASM (>= 2.15)
- Compiler: GCC with 32-bit multilib (
gcc -m32) - Linker: GNU
ld -m elf_i386 - Python: Python 3.8+
- Emulator: QEMU (
qemu-system-x86_64)
# Build complete boot.img using cross-platform Python orchestrator:
python build.py
# Or using GNU Makefile:
make# Run full 7-phase automated headless regression test suite:
python test.py
# Run specific distro test:
python test.py --suite kali # Test Kali Linux 2026.2 Installer UMS Block Boot
python test.py --suite persistence # Test Dynamic Multi-Profile Persistence
python test.py --suite ram # Test In-RAM Alpine Linux Boot
# Launch interactive desktop QEMU session:
python tools/run_qemu.py --mode kali
# Passthrough physical Android phone connected via USB to QEMU:
python tools/test_physical_phone_qemu.pyThis project is licensed under the MIT License β see the LICENSE file for details. Third-party components retain their respective permissive open-source licenses as documented in docs/THIRD_PARTY.md.