Production-default image VM startup still takes about 2.67 seconds from cached public POST /vms/create through the first completed successful workload exec on the new Linux x86_64 KVM host.
Follow-up to #319 and phase 1 (#299) of the #289/#291 plan. The maintainer explicitly accepts a 3-second limit for the current work and requests this performance follow-up. Keep the remaining 13-phase plan moving; do not change RAM/CPU defaults or qualification requirements to meet a timing number.
Measured twice on clean integration source f3e4629878d637ad5fec762a2c963760d604bad7, with verified, source-matching producer assets and identical host binaries:
| Resources |
Create through first completed exec |
| Default 12 GiB / 4 CPU |
2.6747s, 2.6642s |
| Comparison 2 GiB / 2 CPU |
2.0075s, 2.0892s |
Default boot-stage logs report kernel startup 0.94s/0.92s, remaining guest setup 0.42s/0.41s, and first exec 0.181s/0.228s. The remaining create cost is approximately 1.13s/1.11s by subtraction; this is an arithmetic remainder, not a profiled attribution. Functional checks verified immutable kernel audit registration/rules, refusal to unlock auditing, public command history, an actual unique command audit record, and awaited session cleanup. This measurement report lacks the machine-doctor output; a corrected diagnostic is pending. It is not complete exact-source qualification evidence.
Start with guest/artifacts/capsem-init boot-stage instrumentation, crates/capsem-core/src/vm/config.rs, the KVM implementation in crates/capsem-core/src/hypervisor/kvm/, and the service/process create-to-ready handoff. Profile the remaining host admission/setup and workload-launch costs before selecting an optimization. Measure unchanged inputs twice, then compare candidate samples under the same host lease and verified asset cohort.
Acceptance: reduce default cached create-to-first-completed-exec time toward the original sub-2-second goal, without weakening asset verification, audit policy, readiness, ephemeral cleanup, production defaults, or existing deadlines. Run the owning runtime/installed-package gates and complete qualification on the final source; report exact paired samples and variation.
Production-default image VM startup still takes about 2.67 seconds from cached public
POST /vms/createthrough the first completed successful workload exec on the new Linux x86_64 KVM host.Follow-up to #319 and phase 1 (#299) of the #289/#291 plan. The maintainer explicitly accepts a 3-second limit for the current work and requests this performance follow-up. Keep the remaining 13-phase plan moving; do not change RAM/CPU defaults or qualification requirements to meet a timing number.
Measured twice on clean integration source
f3e4629878d637ad5fec762a2c963760d604bad7, with verified, source-matching producer assets and identical host binaries:Default boot-stage logs report kernel startup 0.94s/0.92s, remaining guest setup 0.42s/0.41s, and first exec 0.181s/0.228s. The remaining create cost is approximately 1.13s/1.11s by subtraction; this is an arithmetic remainder, not a profiled attribution. Functional checks verified immutable kernel audit registration/rules, refusal to unlock auditing, public command history, an actual unique command audit record, and awaited session cleanup. This measurement report lacks the machine-doctor output; a corrected diagnostic is pending. It is not complete exact-source qualification evidence.
Start with
guest/artifacts/capsem-initboot-stage instrumentation,crates/capsem-core/src/vm/config.rs, the KVM implementation incrates/capsem-core/src/hypervisor/kvm/, and the service/process create-to-ready handoff. Profile the remaining host admission/setup and workload-launch costs before selecting an optimization. Measure unchanged inputs twice, then compare candidate samples under the same host lease and verified asset cohort.Acceptance: reduce default cached create-to-first-completed-exec time toward the original sub-2-second goal, without weakening asset verification, audit policy, readiness, ephemeral cleanup, production defaults, or existing deadlines. Run the owning runtime/installed-package gates and complete qualification on the final source; report exact paired samples and variation.