Call unveil(2) in combination with unlink(2) and chroot(2).Use umount(8) to check that the mountpoint leaks no vnode.