Landlock provides fine grained control over individuals files or directories, there are already other sandboxing software that does exactly this like the go written landrun
this will be very handy to control access to individual files easily instead of filtering syscalls with seccomp