Dylanger: nah, we have: 1) kernel partition 2) /boot partition 3) / (root) partition let's assume root is encrypted. device boots from kernel partition, then mounts /boot and unpacks secondary ramdisk, and using utils from there lets unlock root partition