The jailer creates the cgroup dir <cgroup_base>/<parent>/<id>, writes the current pid to .../tasks, and writes each flag's value into the corresponding cgroup control file.
Known gotchas
cpuset (and other controllers) must be mounted at /sys/fs/cgroup/<controller>; the jailer parses /proc/mounts to find where each controller lives.
Folder creation is skipped silently if the path already exists; values are still written, so reuse of the same parent is fine but per-id dirs should be unique.
Keep VCPU count, memory, and cpuset in agreement with the guest's expected topology to avoid performance surprises.
Give your agent this knowledge — and 18,100+ more routes
One MCP install gives any agent live access to the full route map across 6,000+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?