I had a look at some other distributions, and noticed in <URL: https://github.com/getsolus/packages/tree/main/packages/o/opensnitch/ > that solus uses a opensnitch group for socket access. Perhaps an idea for Debian too? There are some patches there, I it would be even better if these could be upstreamed first, to ensure consistent behaviour across all Linux distributions.
-- Happy hacking Petter Reinholdtsen