Selinux expert needed to show us how to confine a user to a single directory. That is, how to prevent the user read anything else in the system.