bug(vm-driver): VM sandbox cold start stalls ~5 s repeatedly on "Waiting for VM supervisor"
Los mantenedores suelen responder en 1 día
Ya se ha fusionado un pull request relacionado.
- #4282 de @benoitf — fusionado
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 82/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- rust
- Área
- infrastructure
Línea de trabajo
Empieza con crates/openshell-driver-vm/runtime/pins.env y comprueba cómo el runtime de la VM fija libkrun. Actualiza el pin a una release que contenga el fix de conexión rechazada de upstream, luego crea una sandbox de VM usando el paso de reproducción reportado. Hecho significa que el runtime usa la release corregida y la creación de la sandbox ya no se detiene durante aproximadamente cinco segundos mientras espera al supervisor de la VM.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Note: I have observed the behaviour, but due to lacking Rust knowledge and the codebase in general I have instructed Claude Opus 5.5 to use the skills in this repo and analyze for potential cause of the 5s wait. "Analysis by Claude" is added where the statements are from Claude, and I have verified the parts I am able to (commit references etc).
User Story
I use OpenShell for running ephemeral sandboxes. I directly encountered repeatedly a 5 second wait on "Waiting for VM supervisor". I need sandboxes to become ready without this wait, so that they start faster and the task can be done quicker.
⠐ Starting sandbox... Waiting for VM supervisor (0s)
⠐ Starting sandbox... Waiting for VM supervisor (5s)
Problem Statement
Analysis by Claude:
VM sandbox startup can stall for about 5 seconds while the host waits to reach the guest over the boundary control connection.
The VM driver maps its boundary control port with krun_add_vsock_port2(..., listen=true). libkrun accepts the host-side Unix socket connection immediately, before anything in the guest listens on that port. In libkrun v1.19.4 and earlier, when the guest refuses that connection, libkrun keeps the host socket open until its reaper reclaims it 5 s later. connect_boundary_with_retry in openshell-sandbox-backend therefore blocks for that window instead of retrying every 25 ms.
Upstream fixed this in libkrun/libkrun@d2d8dd6 ("virtio/vsock: remove refused connections without waiting for the reaper"), first released in v1.19.5 (upstream issue containers/libkrun#684). OpenShell pins libkrun v1.19.4 in crates/openshell-driver-vm/runtime/pins.env.
Impact / Why This Matters
Analysis by Claude:
Every VM sandbox whose host-side probe reaches the control socket before the guest is listening pays up to ~5 s of extra startup time. The delay dominates cold start for short-lived sandboxes. There is no workaround in OpenShell configuration. Upstream measured time to first round trip after VM start at 5338 ms before the fix and 415 ms after, with a blocking probe.
Acceptance Criteria
- The VM driver runtime is built with a libkrun release that contains libkrun/libkrun@d2d8dd6. (1.19.5 or 1.19.6 atm)
- VM sandbox creation no longer includes a ~5 s stall
Reproduction Steps
openshell sandbox create --name sandbox
Created sandbox: sandbox
✓ Sandbox allocated (0s)
✓ Image pulled (512 MB) (0s)
⠤ Starting sandbox... Waiting for VM supervisor (5s)
Suggested UX (if applicable)
No response
Environment
- OpenShell: openshell 0.1.2
- OS: macOS 26.6.2 (Apple silicon)
- OpenShell deployment mode and runtime: local gateway, VM compute driver (libkrun v1.19.4)
Logs
Created sandbox: sandbox
✓ Sandbox allocated (0s)
✓ Image pulled (512 MB) (0s)
⠤ Starting sandbox... Waiting for VM supervisor (5s)
- Lenguaje dominante
- Rust
- Estrellas
- 15.4k
- Forks
- 1.7k
- Merge medio
- 1 d 21 h
- PR fusionados (30 d)
- 363
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de NVIDIA/OpenShell
-
docs: document workspace and provider label capabilitiesPosiblemente ocupada @johntmyers la tomó hace 2 días. Abiertoarea:docs
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
NVIDIA/OpenShell#4250 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
bug(driver-mxc): test helper fails to compile after gateway-name argumentPosiblemente ocupada @feloy la tomó hace 4 días. Abiertostate:triage-needed
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
bug: install.sh ignores XDG_CONFIG_HOME for the local gateway configPosiblemente ocupada @fede-kamel la tomó hace 7 días. Abiertoarea:cli os:linux os:macos state:validated
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
NVIDIA/OpenShell#4042 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
state:triage-needed
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
NVIDIA/OpenShell#3995 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
OCSF shorthand renders Unknown and Other severities as [INFO]Posiblemente ocupada @ericcurtin la tomó hace 8 días. Abiertostate:triage-needed
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día
Todos los issues de NVIDIA/OpenShell
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 75/100
element-hq/lk-jwt-service#248 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
pact-foundation/pact-cli#154 ·
Los mantenedores suelen responder en 3 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
antithesishq/bombadil#361 ·
Los mantenedores suelen responder en 1 día
-
test(executor_l0): assert execute() TaskOutcome, not only bus events / 断言 execute() 返回的 TaskOutcomeAbiertotype:debt
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
skaiy/wild_agentos#425 ·
Los mantenedores suelen responder en 1 día