"Is it OK to drop the leaf-net and unconfined components from the path? Currently, a confined scope relies on being able to create the final path component *itself* by calling mkdir(). So, assuming that ~/.local/share/unity-scopes/leaf-net exists, the scope will try to create ~/.local/share/unity-scopes/leaf-net/@{APP_PKG_NAME}."
No. This is important for isolation between scopes if we ever decide to support other scope templates to protect against certain types of attacks via differently versioned apps.
"Is it OK to drop the leaf-net and unconfined components from the path? Currently, a confined scope relies on being able to create the final path component *itself* by calling mkdir(). So, assuming that ~/.local/ share/unity- scopes/ leaf-net exists, the scope will try to create ~/.local/ share/unity- scopes/ leaf-net/ @{APP_PKG_ NAME}."
No. This is important for isolation between scopes if we ever decide to support other scope templates to protect against certain types of attacks via differently versioned apps.