Update for various changes recently checked in to kern_jail.c.
We might consider only enabling this by default on amd64 to match what we've done with 'options KERN_TLS' in GENERIC.
Don't forget a manpage.
Manually pasted reduced-context diff to work around Phabricator's UTF-8-centric views
Hmph. Phabricator does not support ISO-8859-1 (their docs say so explicitly) so it balks on these files and treats them as binary. That's going to be fun. Anyway, here's the diff:
Rebase against shiny new repo