Mount this app's per-user settings — a private ~/.config-style filesystem, auto-provisioned for the signed-in user and isolated to THIS app (the host chroots it; a different app can never name it). Read/write config files through the returned mount. Rejects with a SpaceError (auth-required) when signed out. Capability: baseline settings:app.