http://treasurechest.i2p/setup.html
This jail contains only the necessary directories, mounted with restrictive permissions (read-only and disallowing executables wherever possible), and it also contains modified versions of key system files (like /etc/passwd and /etc/shadow, which are trimmed down to contain only the users which the service needs) the services and I2P all have their permissions tightly restricted with tailor-made mandatory access control policies (I use AppArmor, which is what my distribution of choice...