changing cpuset of jail from inside of jail - is it feature?

Miroslav Lachman 000.fbsd at
Tue Apr 21 22:40:49 UTC 2009

I am running system FreeBSD 7.1-STABLE amd64 GENERIC (Wed Feb 11 
09:56:08 CET 2009) hosting few jails.
The machine has dual core CPU and some jails are set to run only on one 
core (core 0 in this example):

     host# cpuset -l 0 -j 25

As I tested today, root user inside the jail can change this by the same 
command as I am doing it from the host system:

    injail# cpuset -l 0,1 -j 25

And from now, jail with JID 25 is running on both cores.

Is it expected behavior of cpuset to allow user inside the jail change 
cpuset of the jail itself or is it a bug?

It seems to me as undesirable.

Miroslav Lachman

More information about the freebsd-stable mailing list