Really? So a program can access (and modify!) the state of all of its users?
Do you realize how easy it would be to trick my Firefox instance into reading (and even modifying) the state of another user, and even running other code on behalf of another user, given that it would have privileges to do so?
If I understand correctly your proposal, you basically just converted almost every single application bug into a privilege escalation bug.
Not to mention that how do you even define what the same "app" is?
Is Firefox 28 the same app as Firefox 45? And if so, can a user install his own Firefox (like you currently can on NixOS and even other OSes)?
Also, how would you backup all of your own per-user state, given that every app can decide to manage it differently (i.e. storing it in different files and/or directories inside their own per-app directory, or perhaps even in a single per-app database which you wouldn't have access to).
Look, I'm not trying to grill you, I just think you haven't thought this through (but again, I'm happy to be proven wrong).
> This is unrealistic. On the want majority of computers an app will only be run by 1 user. Focusing on handling multiple users is a more special case and is a distraction from the point I'm trying to make.
What does this even mean? We're talking about user-specific state. So there's different state for each user, which means there are multiple users, by definition!
So how is focusing on multiple users a distraction? It's the whole point...
As I mentioned, on NixOS, the system-wide mutable state is already stored on /var/lib/<app>, which is what you are (redundantly) proposing. So we're just arguing about how to handle user-specific state, nothing else.