@dalias I have no objection to sandboxing of this kind by default - it is a sensible default and should stay that way. However, there is _no way whatsoever_ I can see to allow this to work. I've tried blanket-enabling _every_ filesystem permission in Flatseal, and even adding /var/lib _manually_, and _still_ it fails.