PixelUpdater icon

PixelUpdater

v0.210guide

Android A/B OTA updater app for rooted Pixels

★237 stars
•System Environment•by PixelUpdater•GPL-3.0•Updated Jan 22, 2026
Platforms:
✓ Magisk

Overview

Pixel Updater is an open-source, systemless OTA utility developed specifically for rooted Google Pixel devices. Traditionally, applying monthly Google security updates on a rooted Pixel involved tedious manual steps: pausing the update, downloading full factory or OTA images to a computer, manually patching the init_boot or boot partition via Magisk, and flashing through fastboot.

Pixel Updater automates this entire lifecycle on-device. Operating as a privileged system application paired with Magisk boot hooks, it interfaces directly with Android’s native update_engine daemon. It checks for official Google OTA packages, streams and verifies partition payloads into the inactive A/B slot, automatically applies Magisk root to the new slot, and prompts you to reboot seamlessly.

Prerequisites & Compatibility

  • Hardware: Official Google Pixel devices (Pixel 6 series, Pixel 7 series, Pixel 8 series, Pixel 9 series, and newer).
  • Android Version: Android 13 or higher.
  • Root Solution: Magisk. KernelSU and APatch are currently unsupported because Pixel Updater specifically relies on Magisk’s slot patching integration.

Incompatibility Notice

Pixel Updater is built around Google’s official Pixel OTA distribution infrastructure and metadata schemas. Flashing this module on devices from other manufacturers (such as Samsung, Xiaomi, or OnePlus) will fail and will not receive updates.

Technical Architecture & Security Model

To interact with Android’s low-level update_engine without creating system security vulnerabilities, Pixel Updater implements a least-privilege architecture:

  1. Custom SELinux Domain: During early boot (post-fs-data.sh), a native binary (pixelupdater_selinux) creates a dedicated SELinux domain called pixelupdater_app based on the restricted untrusted_app profile, rather than using broad priv_app permissions.
  2. Context Association: The module binds package com.github.pixelupdater.pixelupdater to pixelupdater_app in /dev/selinux/apex_seapp_contexts.
  3. Payload Verification: Before passing the update to update_engine, Pixel Updater downloads metadata.pb and payload_metadata.bin to verify header checksums, device fingerprint compatibility, and security patch timestamps. This ensures that incompatible images or accidental downgrades (which could trigger AVB rollback index bricking) are blocked.

Installation & Workflow

  1. Flash the PixelUpdater-*-release.zip package via Magisk and reboot.
  2. Launch the Pixel Updater application from your app drawer.
  3. Tap Check for updates to poll Google’s official update servers.
  4. When an update is detected, press Install. Pixel Updater will stream the payload to the inactive slot, verify partition checksums, and patch Magisk root into the new slot.
  5. Once complete, tap the notification or app button to reboot into your updated system.

Diagnostic Logs & Debug Menu

Pixel Updater includes built-in logging and debugging capabilities:

  • Enable Debug Mode: Long-press the version number inside the app settings to reveal hidden toggles.
  • Reverting an Update: If an update was installed but you have not yet rebooted, enable debug mode and select Revert completed update to cancel the bootloader slot switch.
  • Log Locations:
    • Operational logs (check.log, install.log, revert.log, crash.log) reside in:
      /sdcard/Android/com.github.pixelupdater.pixelupdater/files/
    • Early-boot SELinux policy modification logs are saved to:
      /data/local/tmp/pixelupdater_selinux.log
    • To trace live update_engine operations from your PC:
      adb logcat '*:S' update_engine