I would configure mailman with permanent write access to the mailbox area

That's what I with my sandbox right now

With systemd or firejail it's quite easy to do this sort of thing on linux.