To be clear, what I put in my previous post is without any sandboxing. So, the KVM sandbox has at least a pretty serious amount of setup-breakdown overhead. How it would affect execution performance outside of that is unknown, but say a process per tab web browser sandboxed in this manner would introduce a fair bit of a delay in opening a new tab if processes aren't sharing a sandbox...