OS image
An OS image is one immutable EROFS filesystem containing a complete userspace. This specification defines its representation and contents independently of the machinery that constructs, stores or launches it.
Representation and identity
The bytes of the image are exactly the EROFS filesystem bytes. It is not an archive, disk layout, partition image or wrapper containing another root filesystem. .os is the conventional extension; the name and storage location are not identity.
flowchart LR
Bytes["Exact EROFS bytes"] --> Filesystem["Read-only userspace filesystem"]
Changing filesystem bytes produces a different image. Integrity records, signatures and publication metadata are external; they must not be encoded by wrapping or changing the image. Surrounding storage padding is not part of the image.
Contents
The image MUST contain executable /sbin/axisd as its initial userspace entry point. It may contain application software, configuration, libraries, executables and firmware intended for userspace consumption.
It MUST NOT contain a kernel, initramfs, boot loader, partition table, machine-specific boot assets or a host-side launcher. Machine-specific support must not be inserted solely to make one machine configuration work. Required writable state cannot reside in the immutable image.
Use and compatibility
The filesystem must be usable directly and read-only as /. A compatible consumer cannot require unpacking, conversion, copying into another filesystem, modification or repackaging first. Identical image bytes may be used on several compatible machines.
Compatibility means that the consumer can provide the machine architecture, executable ABI, kernel facilities and external runtime support required by the contained userspace. This file defines no generic compatibility solver or authorization protocol. A claim of compatibility needs evidence outside the image; byte validity alone is insufficient.
Conformance
A conforming image is valid EROFS, contains the required entry executable and immutable userspace, excludes boot-specific machinery and supports direct read-only root use. These properties do not prove that it has been launched successfully.