Repository navigation
feat(api): shared upstream client with request deadline and distinct outage reporting - #601
Merged
Merged
Conversation
… bounded jittered retries
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Deployment failed for project playground with the following error: Learn More: https://vercel.com/salazarsebas?upgradeToPro=build-rate-limit |
|
Deployment failed for project lumenwipe with the following error: Learn More: https://vercel.com/salazarsebas?upgradeToPro=build-rate-limit |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
#451 adds one shared upstream read client (
lib/stellar/upstream-client.ts) and moveshorizonGetandhorizonPaginateonto it.Retry-Afteris honored in seconds and HTTP-date form, capped at 5 s, and a hostile value falls back to the jittered backoff.UpstreamError(rate_limited,timeout,unavailable,bad_response) with plain messages that carry no status code, URL or host. 400, 410 and other 4xx arebad_responseand are not retried.sendTransaction,getTransactionandpollTransactionare not on that list: they pass through untouched, are called once by the client, and are never abandoned by the deadline.domain-errors.ts(503service_unavailable, or 502provider_response_unusableforbad_response) and through the account controller. No new error codes. OpenAPI annotations andopenapi.jsonare updated.#452 moves path finding and the sponsorship reader onto the client and reports outages distinctly.
fetchConversionPathreturnsroute | none | unavailable.noneis only an answered empty market or an unroutable input. Because the result is a discriminated object, the compiler rejects any call site that used it as a path.unavailableis rethrown as the typed 503, neverAssetRouteLostError(409quote_drifted). The paths endpoint answers 503 instead of{ path: null }.incomplete, and per-owner concurrency drops from 10 to 2 once a 429 has been seen.fetchConversionPathno longer leaks its timer on throw.assessConversions(no production caller) reportspriceSourceUnavailable.Why
A retried Horizon read could take about 43 s, a paginated read multiplied that per page, and the sponsorship scan, direct-read fallback and RPC calls each had their own budget. The worst case exceeded the proxy's 55 s limit, so users saw a generic 504. A transient 5xx or 429 on path finding returned
null, indistinguishable from an illiquid asset, and one transient failure in sponsorship blocked closes that would otherwise succeed.Tests
New:
upstream-client,rpc-deadline,path-finding,price-source-unavailable, plus additions tohorizon-http,domain-errorsandsponsorship-io. Existing tests were adapted where they asserted raw status codes or URLs in messages, or the oldnullpath result.mainat import.Invariants checked
unavailableis a distinct type at every path-finding call site, and a test per call-site family covers plan, build and the paths endpoint.sendTransaction, and the deadline never abandons it. The existingTRY_AGAIN_LATERloop insubmit.tsis unchanged and out of scope.docs/reference/logging-and-privacy.mdx. A test asserts the exact log payload.Risks
Closes #451
Closes #452