bug(vm-driver): VM sandbox cold start stalls ~5 s repeatedly on "Waiting for VM supervisor"
Mantenedores costumam responder em até 1 dia
Avaliação
- Dificuldade
- 2/5
- Tempo estimado
- 1-3 horas
- Facilidade para iniciantes
- 82/100
- Tipo de issue
- Bug
- Clareza
- Claramente especificada
- Status de atividade
- Ativa
- Stack de tecnologia
- rust
- Domínio
- infrastructure
Direção de pesquisa
Comece com crates/openshell-driver-vm/runtime/pins.env e verifique como o runtime da VM fixa o pin do libkrun. Atualize o pin para uma release que contenha o fix de conexão recusada do upstream, depois crie uma sandbox de VM usando o passo de reprodução informado. Concluído significa que o runtime usa a release corrigida e a criação da sandbox não trava mais por cerca de cinco segundos enquanto espera o supervisor da VM.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
User Story
I use OpenShell for running ephemeral sandboxes. I directly encountered repeatedly a 5 second wait on "Waiting for VM supervisor". I need sandboxes to become ready without this wait, so that they start faster and the task can be done quicker.
⠐ Starting sandbox... Waiting for VM supervisor (0s)
⠐ Starting sandbox... Waiting for VM supervisor (5s)
Problem Statement
Analysis by Claude:
VM sandbox startup can stall for about 5 seconds while the host waits to reach the guest over the boundary control connection.
The VM driver maps its boundary control port with krun_add_vsock_port2(..., listen=true). libkrun accepts the host-side Unix socket connection immediately, before anything in the guest listens on that port. In libkrun v1.19.4 and earlier, when the guest refuses that connection, libkrun keeps the host socket open until its reaper reclaims it 5 s later. connect_boundary_with_retry in openshell-sandbox-backend therefore blocks for that window instead of retrying every 25 ms.
Upstream fixed this in libkrun/libkrun@d2d8dd6 ("virtio/vsock: remove refused connections without waiting for the reaper"), first released in v1.19.5 (upstream issue containers/libkrun#684). OpenShell pins libkrun v1.19.4 in crates/openshell-driver-vm/runtime/pins.env.
Impact / Why This Matters
Analysis by Claude:
Every VM sandbox whose host-side probe reaches the control socket before the guest is listening pays up to ~5 s of extra startup time. The delay dominates cold start for short-lived sandboxes. There is no workaround in OpenShell configuration. Upstream measured time to first round trip after VM start at 5338 ms before the fix and 415 ms after, with a blocking probe.
Acceptance Criteria
- The VM driver runtime is built with a libkrun release that contains libkrun/libkrun@d2d8dd6. (1.19.5 or 1.19.6 atm)
- VM sandbox creation no longer includes a ~5 s stall
Reproduction Steps
openshell sandbox create --name sandbox
Created sandbox: sandbox
✓ Sandbox allocated (0s)
✓ Image pulled (512 MB) (0s)
⠤ Starting sandbox... Waiting for VM supervisor (5s)
Suggested UX (if applicable)
No response
Environment
- OpenShell: openshell 0.1.2
- OS: macOS 26.6.2 (Apple silicon)
- OpenShell deployment mode and runtime: local gateway, VM compute driver (libkrun v1.19.4)
Logs
Created sandbox: sandbox
✓ Sandbox allocated (0s)
✓ Image pulled (512 MB) (0s)
⠤ Starting sandbox... Waiting for VM supervisor (5s)
- Linguagem predominante
- Rust
- Estrelas
- 13.2k
- Forks
- 1.6k
- Merge médio
- 1d 19h
- PRs com merge (30d)
- 343
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Tem um modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de NVIDIA/OpenShell
-
docs: document workspace and provider label capabilitiesTalvez já em andamento Um pull request vinculado a esta issue está aberto ou já foi mesclado. Abertaarea:docs
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
Mantenedores costumam responder em até 1 dia
-
Sandbox-side proposal audit (CONFIG:PROPOSED and /wait decisions) names only the first endpointAbertastate:triage-needed
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
Mantenedores costumam responder em até 1 dia
-
bug(driver-mxc): test helper fails to compile after gateway-name argumentTalvez já em andamento @feloy assumiu há 2 dias. Abertastate:triage-needed
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 88/100
Mantenedores costumam responder em até 1 dia
-
bug: install.sh ignores XDG_CONFIG_HOME for the local gateway configTalvez já em andamento @fede-kamel assumiu há 6 dias. Abertaarea:cli os:linux os:macos state:validated
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
NVIDIA/OpenShell#4042 · 2 comentários ·
Mantenedores costumam responder em até 1 dia
-
state:triage-needed
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
NVIDIA/OpenShell#3995 · 2 comentários ·
Mantenedores costumam responder em até 1 dia
Todas as issues de NVIDIA/OpenShell
Issues semelhantes
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
Mantenedores costumam responder em até 4 dias
-
Update dusk-bls12_381 to 0.16Talvez já em andamento @HDauven assumiu hoje. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
googlefonts/fontquant#43 ·
-
bot:ai-assisted status:untriaged
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
midnightntwrk/midnight-zk#561 ·
Mantenedores costumam responder em até 2 dias
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 74/100
rubys/roundhouse#571 ·
Mantenedores costumam responder em até 1 dia