For my own clarity as I had confusion around this:
https://grapheneos.org/features#auto-reboot
Auto reboot
GrapheneOS provides an auto-reboot feature which reboots locked devices after a set period of time to put data at rest. A countdown timer is started each time the device is locked, and the device will reboot if a successful unlock doesn't occur before the timer reaches zero. Unlocking any profile cancels the timer, not just the Owner profile.
The timer is set to 18 hours by default, but can be set to values between 10 minutes and 72 hours, or turned off.
This feature doesn't apply when the device is in "Before First Unlock" state, meaning that it will not lead to the device continuously rebooting, as data is already at rest.
The feature is implemented in the init process, preventing it from being bypassed through system process crashes since an init crash causes a kernel panic which leads to a reboot.
As far as what is available in BFU state and not, I'll leave to people here who are MUCH smarter than I am on this. However, I'm pretty sure you can prevent the phone from ever going into BFU state unless you manually reboot if you wanted to (for anyone curious):
- Under
Settings >> Security & Privacy >> Exploit protection >> Auto reboot you can change the length of time before the phone gets put into BFU state.
- Under
Settings >> System >> System updates >> Automatic reboot you can turn off if it is on to prevent the phone going into BFU state after an update.
Side tangent (and actual reasoning for responding): Thank you for linking to KeepAlive, I'm very interested in this. Is automatic reboots to force BFU the only thing stopping the KeepAlive app from working on GOS? If so, I might give that app a try as I've been using Snug for the past 2 years (for reasons not pertaining to this discussion but I will gladly answer if asked). I really enjoy using the free version of Snug, but like how KeepAlive seems to implement a similar thing better.