Most of your comment it's bullshit. Containers are not for security, but for convencience and task separation/isolation to avoid the overhead of a vm. eBPF will expose you further more, not less. Also, how can flatpak secure you against a ~/.profile script run at login or an ~/.xprofile one?