Boot
Boot is the transition from machine startup to an initial userspace process with a selected immutable root filesystem. Its inputs are the selected image bytes, the machine’s boot platform and an explicit selection policy. Its output is the process-entry state defined here.
A boot platform means the firmware, kernel, loaders, storage access and optional early userspace supplied for one machine configuration. A root image means the exact selected EROFS byte sequence. These local input descriptions do not prescribe how either input was constructed.
Entry and paths
The boot platform must start a compatible Linux kernel and locate the selected root image. It may use direct kernel root mounting or optional early userspace. Both paths converge on a read-only root and execution of /sbin/axisd as PID 1.
flowchart LR
Firmware["Firmware / loader"] --> Kernel["Linux kernel"]
Kernel --> Root["Selected EROFS mounted read-only at /"]
Root --> Entry["/sbin/axisd, PID 1"]
class Entry program
flowchart LR
Kernel["Linux kernel"] --> Early["Early userspace, PID 1"]
Early --> Root["Selected EROFS mounted read-only at /"]
Root --> Entry["exec /sbin/axisd, preserving PID 1"]
class Early,Entry program
Prerequisites
Functionality required before early userspace starts must already be available to the kernel. Later modules, firmware, block mappings and drivers may be provided by early userspace when that path is explicitly used. No prerequisite may depend on a file that exists only inside the still-inaccessible root image.
Kernel command-line data, device-tree data, early firmware and initramfs contents are platform inputs. They are not inserted into the selected image. No particular firmware API, boot loader or early-userspace implementation is mandated.
Discovery and mounting
The selection policy identifies the image for this attempt. Physical or virtual storage and block mappings may expose it, but must present its exact bytes. Device names, partition identifiers and extent layouts are external discovery information.
The selected EROFS filesystem becomes / read-only. It MUST NOT be unpacked, copied into a replacement filesystem, converted, wrapped or modified. Early userspace may verify or expose the image without altering it. A platform capable of direct mounting need not introduce early userspace.
Process handoff
Once the root is established, /sbin/axisd must start as PID 1. If early userspace occupies PID 1, it replaces itself with that executable rather than spawning a child. Without early userspace the kernel may execute it directly. No other process belonging to the selected userspace starts before this entry point.
Responsibilities after process entry are outside Boot. Inherited runtime mounts may be present; their eventual consumer determines whether they satisfy its required semantics.
Failure
A boot attempt fails when its selected image cannot be located, accessed, verified when required, mounted according to this contract or used to start the entry executable. It cannot silently substitute an unrelated mutable root.
An explicit fallback or recovery policy may select another image in a distinct attempt. It must not modify the image that failed. Starting the entry process is the completion boundary; it is not proof of service readiness.