I think people are unfairly downvoting this comment, but I do want to drill into your point (1) a bit. You're right that you can't really do a delta patch in NixOS. But I feel like that is so so so important these days with active supply chain attacks. I don't want a 200kb change to a core library that is "claimed" to be backward compatible to be able to make its way into my codebase. In an ideal world sure, there would be some way to prove that the update doesn't break anything and isn't malicious, and that is certainly possible for some limited subset (provers like Rocq, OS functionality like BSD Pledge, etc), but for now this is mostly based on trust.