The revision D26537 introduced a new devfs rule devfsrules_jail_vnet. It includes rule devfsrules_jail which include other rules. Unfortunately devfs could not recursively parse the action include and thus devfsrules_jail_vnet will expose all nodes.
Obtained from: Gijs Peskens <gijs@peskens.net>
PR: 255660