Summary
While a sandbox is idle (no client connected, nothing running in it), the in-sandbox openshell-sandbox process stays busy. Its openshell-orphan-reaper thread wakes about 890 times per second and its main thread about 100 times per second. One idle sandbox costs about 2 % of a CPU core, which is roughly 30 times the cost of the gateway alone.
Environment
- OpenShell v0.1.1, installed at user level
- Podman compute driver (rootless Podman 5.4.2)
- Debian 13, Linux kernel 6.18, AMD Ryzen AI (x86_64)
- One sandbox (
demo, default workspace, base image nvcr.io/nvidia/base/ubuntu:24.04), created and then left idle
Measurements
I sampled cgroup cpu.stat and memory.current every 30 s for 10 minutes with no client connected:
| State |
CPU |
Memory |
| Gateway alone, no sandbox |
0.07 % of one core (about 2.7 s per hour) |
15 MB cgroup, flat |
| Gateway + one idle sandbox |
gateway 0.14 %, supervisor 0.10 %, sandbox 1.94 %, total 2.2 % of one core (about 78 s per hour) |
gateway 60 MB, supervisor 44 MB, sandbox 20 MB |
I measured wakeups from the per-thread voluntary_ctxt_switches and nonvoluntary_ctxt_switches in /proc/<pid>/task/<tid>/status, over the same window:
openshell-orphan-reaper thread in openshell-sandbox: about 890 per second
- main thread of
openshell-sandbox: about 100 per second
- gateway (all tokio workers together): about 25 per second
Expected
An idle sandbox should cost close to nothing between events. managed_children.rs appears to sleep 50 ms per loop iteration, which would be about 20 wakeups per second, so the observed rate suggests the sleep is not taking effect (or something else wakes the thread at millisecond scale). Waiting on SIGCHLD, a pidfd, or waitpid without polling would avoid the periodic wakeups altogether.
Impact
On a workstation that keeps a sandbox around between uses, this is a steady power and CPU cost. For now I stop the sandbox when it is not in use.
I'm happy to collect more data (for example perf trace, or strace -f -c on the reaper thread) if that would help.
Written with Claude Code.
Summary
While a sandbox is idle (no client connected, nothing running in it), the in-sandbox
openshell-sandboxprocess stays busy. Itsopenshell-orphan-reaperthread wakes about 890 times per second and its main thread about 100 times per second. One idle sandbox costs about 2 % of a CPU core, which is roughly 30 times the cost of the gateway alone.Environment
demo, default workspace, base imagenvcr.io/nvidia/base/ubuntu:24.04), created and then left idleMeasurements
I sampled cgroup
cpu.statandmemory.currentevery 30 s for 10 minutes with no client connected:I measured wakeups from the per-thread
voluntary_ctxt_switchesandnonvoluntary_ctxt_switchesin/proc/<pid>/task/<tid>/status, over the same window:openshell-orphan-reaperthread inopenshell-sandbox: about 890 per secondopenshell-sandbox: about 100 per secondExpected
An idle sandbox should cost close to nothing between events.
managed_children.rsappears to sleep 50 ms per loop iteration, which would be about 20 wakeups per second, so the observed rate suggests the sleep is not taking effect (or something else wakes the thread at millisecond scale). Waiting onSIGCHLD, apidfd, orwaitpidwithout polling would avoid the periodic wakeups altogether.Impact
On a workstation that keeps a sandbox around between uses, this is a steady power and CPU cost. For now I stop the sandbox when it is not in use.
I'm happy to collect more data (for example
perf trace, orstrace -f -con the reaper thread) if that would help.Written with Claude Code.