I've said this before but I'll write it now:
GOS could choose to store a fresh new profile and not make it accessible.
During an update, on reboot there could be a 30 second "getting things ready" screen/message period.
If the phone is locked with an update, the password could be required before reboot.
Duress password --> move fresh data partition to accessible with same duress password --> "getting things ready" & delete prior partition and start 3 pass clearing --> Boot fresh profile --> "Changes are complete!"
Upgrade --> Require locking phone and entering password once update is ready --> "getting things ready" & do update --> Boot update with same normal and duress profile --> "Changes are complete!"
It makes it much for defensible and more tham that, it becomes much much more expensive to illegally prosecute someone for exercising 1st ammendment rights to express their ideas in a different configuration of 1s and 0s.
Expenses matter. It requires much more time and expense to prove. It means cases settle for less time or win in cases of government overreach.
This is also a feature that may help in a wrench attack situation: was this a genuine update or was it a durress password? (Yes, there are counterarguments.)
Bullies come in all forms ith badges, wrenches, or even malware, and data protection is important. There is no reason to make this feature not put in a fresh profile and use the same messaging and process as an upgrade.