I do wonder if some future Nix-variant which based around sandboxing first could make life easier.
Nix seems to have to put lots of work into handling programs that expect to find to find /bin/bash. An alternative would be to put programs in custom sandboxes, where /bin/bash is found exactly where they expect to find it.