> I think Flatpak can do this, but almost no one does it.
Flatpak can do it poorly. What I see is opening a file for read once gives the sandboxed app write access to that path name forever.