Can't run the simplest ping script

Yeah, ping is typically setuid so requires ‘capability setuid’ in the apparmor profile. Both are allowed by network-observe (or network-control). See Executing ping within a snap