Results 2 comments of Russell Coker

@pebenito Does this need anything else?

What you could do (and what I have done with SE Linux policy) is to have bubblewrap run with access to do such things and then transition back to another...