Press the power button and your OS appears like magic. In between, a small but critical program called the bootloader decides what actually starts. If you've ever dual-booted Linux, fought a "Secure Boot state unsupported" error, or wondered what GRUB really does — this is for you.
This is an adapted version of the full guide on Techixia: What Is a Bootloader? The Complete 2026 Guide to the Boot Chain, Secure Boot, and How Your Device Starts
The 30-second answer
A bootloader is a small program that runs before your operating system. Its job: find the OS kernel on disk, load it into memory, and hand over control. On BIOS systems it lives in the MBR; on modern UEFI systems it lives in the EFI system partition.
The boot chain, step by step
- Power on → firmware (BIOS/UEFI) — initializes hardware, runs POST.
- Firmware → bootloader — UEFI reads the EFI partition and launches the bootloader (e.g. GRUB, Windows Boot Manager).
- Bootloader → kernel — the bootloader locates the kernel image, loads it into RAM, and passes boot parameters.
-
Kernel → init — the kernel mounts the root filesystem and starts PID 1 (
systemdon most Linux distros,smss.exeon Windows).
Break any link in this chain and you get a black screen — which is why bootloader errors feel so dramatic.
GRUB vs Windows Boot Manager vs the rest
| Bootloader | Where you'll meet it |
|---|---|
| GRUB 2 | Most Linux distros, dual-boot setups |
| Windows Boot Manager | Any Windows 10/11 install |
| systemd-boot | Lightweight UEFI-only option (Arch, Fedora) |
| U-Boot | Embedded devices, Raspberry Pi, routers |
Secure Boot, explained simply
Secure Boot is a UEFI feature that only allows bootloaders signed with a trusted key to run. It exists to stop rootkits from hijacking the boot process. Practical consequences for developers:
- Installing some Linux distros requires disabling Secure Boot first (or using a signed shim — Ubuntu and Fedora ship one).
- The infamous "Secure Boot state unsupported" error usually means your disk is MBR-partitioned or your firmware is in legacy/CSM mode. Converting to GPT + enabling UEFI fixes it without reinstalling Windows.
- On a dual-boot machine, keep a live USB handy. One wrong GRUB reinstall and Windows won't start.
Check your own boot setup
On Linux, see whether you booted via UEFI or legacy BIOS:
# If this directory exists, you booted in UEFI mode
ls /sys/firmware/efi
# Show your boot entries
efibootmgr -v
On Windows (admin PowerShell), check Secure Boot state:
Confirm-SecureBootUEFI
3 bootloader problems devs hit most
-
GRUB rescue prompt after a Windows update — Windows rewrote the EFI boot order. Boot a live USB and reinstall GRUB, or reorder entries with
efibootmgr. - "No bootable device" on a new SSD — the drive is initialized as MBR on a UEFI-only system. Re-initialize as GPT and reinstall the bootloader.
- Linux installer can't see the disk — Intel RST/RAID mode hides NVMe drives from the installer. Switch SATA mode to AHCI in firmware settings (back up BitLocker keys first).
Want the full walkthrough?
The complete guide on Techixia covers the full boot chain in depth, every Secure Boot error and fix, and how each device type (PC, phone, embedded) boots differently.
Originally published on techixia.com — practical tech how-tos on Windows, security, and privacy.
Top comments (0)