Got it. Firejail is a solution, yay.
So, to run bash in the way that I wanted:
Code:
firejail --noprofile --nonewprivs --net=none \
--read-only=/ --read-write=/tmp --read-write=`pwd` \
bash
Order may matter: I have the read-write bits occur *after* specifying the entire file system read-only.
Firejail seems to like absolute paths, so that is why I used `pwd` instead of . for the current directory. This may not be necessary?