Actually you don't have to redefine the filesystem hierarchy like gobolinux do. This fall into what "linuxapps" are about (use containers, nor chroots).
But let the screening "security panels" for those containers be the most basic possible, or you'll have severe cases of "confused deputy" on your hands, and a flush of protests, because for most being "barred" by security is worst than a crashing app (those "containers" could have "capabilities" on the style or EROS OS, let the user choose most of the permissions, only emit the proper warnings... most of them will choose not really secure options in any case lol... but who cares ? its their responsibility clearly stated in the licenses)
OTHO nix approach is also very good, something worth to look into.
>But honestly, the distribution guys are all totally incompetent, since they had 20 years to do these blatantly obvious changes and did nothing, so I wouldn't put much trust in them.