semi-immutable

Immutable where it helps, mutable where it matters. A sealed system image, a writable volume beside it, and an update you can always walk back.

Fully immutable systems are safe and rigid: you cannot change anything, so you cannot break anything, and you also cannot fix anything. Fully mutable systems are the opposite — infinitely adjustable, and no two of them are alike after a year. DivisionOS splits the difference along a line that actually means something.

Two halves, one line

The image
A sealed read-only filesystem holding the system and its defaults. Never written to while running.
The volume
Your accounts, your settings, your programs and your files. Written to constantly.

Where the two overlap, the image supplies the default and the volume supplies your change. Defaults ship in the image only — they are never copied onto the volume — so a default that improves in an update reaches you, instead of being masked forever by a stale copy of the old one.

Updates move a pointer

An update does not edit the running system. It writes a second image beside the first and moves a pointer to it. The previous image is still there, still complete, still bootable. If the new one fails, the loader falls back after two attempts.

So the cost of a bad update is a reboot — not a recovery drive, not a rescue shell, and not an evening.

Installing leaves you an exit

The installer writes to a drive you pick and does not touch the one you booted from. Whatever happens to the new install, the old one is one boot-menu entry away.

  • Nothing writes to the system half while the system is running.
  • Two complete images on disk, either of them bootable.
  • Your half is yours — it is never overwritten by an update.