Returns the uninstall package for os. Ordering mirrors the install path's
fail-closed shape: validate the OS (400, before any fetch, so a client error can never arrive
disguised as a 503) → derive env (503) → fetch the published object (503) → audit → 200.
<br><b>`os` is REQUIRED and has no default.</b> There is no channel here to inherit one from,
and choosing the wrong language is the single packaging error that passes every output guard and
still breaks every device: a PowerShell body under `/bin/sh` round-trips cleanly and stays
under every size cap. A 400 asking for `os` costs one round-trip; a silent default costs a
fleet.