Hi,
Found another interesting detail. net/tun is listed in /etc/udev/makedev.d/50-udev.nodes, which starts with this comment: # These device have to be created manually
I just didn't find who/what actually creates those, and using which permissions. Anyway, another clue in your puzzle.
HTH, Filipe