

And a user of Ubuntu only has access to the functions that Canonical has provided.
That is not at all accurate.
Administrator access to Windows is not at all comparable to root access on Linux. Windows “root” access is held solely by Microsoft, and granted only to Microsoft employees and contractors. They are the only ones with the capability of changing Microsoft’s binary blobs.
Canonical doesn’t restrict root access. Everyone who installs Ubuntu has root access by default.
Suppose Canonical adds this capability to Ubuntu. Suppose I take an Ubuntu install, and remove this capability. Who is the provider of the resulting OS, Canonical, or me? Obviously, I am responsible for the changes; I am obviously the OS Provider in this scenario.
What I am saying is that I was the OS provider before I made the changes.
Let’s remember that the law distinguishes between the OS and Applications running on that OS. They require that the signalling apparatus be included in the OS. Technologically, the distinction between OS and Application is somewhat arbitrary. For commercial OSes, it’s pretty simple: The OS is what Microsoft declares to be part of “Windows” is the OS; everything else is an application.
Suppose Microsoft refuses to include this signaling apparatus. The end user cannot modify Windows, so does not become liable as the “OS Provider”. The user can bolt on the functionality as an application, but cannot make it part of the OS. Microsoft is the one facing the fines under this law.
For FOSS software, the end user’s root access gives them the ability to add this signaling capability to the OS running on their machines, even if Canonical refuses to distribute a compliant OS. The user’s ability to make their own OS compliant with California law makes them the party liable for non-compliance.
By allowing the end user to change it instead of locking it down, they are not making a good faith effort to comply, and they lose their liability protection. To maintain their immunity, at the very least they will need to prohibit Californians from disabling the feature.
Canonical is prohibited from adding comparable terms.
How is iOS any different from Windows here?
Again, to maintain their immunity under this law, they would have to prohibit me from doing this in their licensing agreement. My violation is what protects Microsoft. I would, indeed, be the OS provider in that scenario.
But in the scenario you describe, I’m not the end user.
Neither Canonical nor I can include the same restrictive terms in our OS offerings. We can simply inform our users that the OS is not California compliant. Our users become their own OS Providers as soon as they decide to use them in California.