Is your criticism here that there's no point in invoking bwrap directly when you could instead implement the same things that bwrap implements?
I'd much rather a system call bwrap than re-implement bwrap, because bwrap has already been extensively tested.