Axis / Build System / OS
OS
An OS constructs an immutable operating-system image from a composed filesystem tree and caller-supplied root policy. It owns policy validation, external compatibility evidence, image construction and verified image reuse.
Source and concrete API: os.go.
Properties
-
OS:ImageConfigandPolicy. -
Policy: required directories, executable initialization path and whether device nodes are rejected. Validation does not repair an incomplete root. -
ImageConfig: identity, storage, image-construction capabilities, job allocation, observation and an optional lazy availability check. -
Obligation: provider binding, selected provider evidence, version constraints and configuration contributions originating in the installed dependency closure.
Behavior
New stores explicit configuration and policy without executing work. Requirements prepends a caller-selected baseline dependency to an authored requirement list; no distribution namespace is hard-coded.
Policy.Validate rejects roots that violate the supplied policy. Obligations collects compatibility requests originating in the installed closure, excluding requests made only by unrelated support consumers. A recorded provider name is evidence, not a permanent machine binding.
OS.Build validates its input tree and verifies cached image bytes before reuse. On a miss it acquires execution lazily, creates deterministic EROFS and checks the result before publication. EROFS writes and verifies image bytes through an already owned execution capability.
Image identity
The implementation fixes ordering, ownership, timestamps, filesystem identity and compression policy as declared inputs. Wall-clock time, random host state and directory enumeration order cannot change the result. Root contents, construction implementation, execution image and EROFS parameters define reuse.
The output is exactly the filesystem image, with no metadata wrapper. Compatibility records remain separate from payload bytes. Recording requirements does not prove that a future runtime satisfies them. Runtime validation and selection policy belong to the caller.
Boundary
The supplied policy determines whether a root conforms to a particular distribution. This package does not choose a baseline dependency, an initialization executable or a destination machine. It cannot claim boot acceptance merely because image construction and filesystem verification succeeded.