Add 30-Second Request Timeout to Subsquid Indexer Client - #164
Conversation
### Description This pull request addresses a medium-severity network reliability finding in `quantus-cli` identified during the Quantus workspace security audit (**FM-11**). Previously, `SubsquidClient::new` instantiated `reqwest::Client` using default settings without an explicit request timeout. Because reqwest has no default timeout, a stalled or non-responsive Subsquid GraphQL indexer endpoint would block calling tasks indefinitely, locking reward-collection and privacy-preserving transfer query CLI operations without recovery paths or errors. ### Key Changes & Remediations #### Bound Indexer HTTP Transport (FM-11 - `src/subsquid/client.rs`) * **Configured Request Timeout:** Configured `Client::builder().timeout(std::time::Duration::from_secs(30))` during `SubsquidClient` initialization. * **Consistency Across Clients:** Aligns the HTTP indexer timeout contract with the 30-second timeout already utilized by the WebSocket chain client. * **Graceful Degradation:** Ensures network interruptions and hung indexer connections fail-fast with a typed error rather than blocking the CLI indefinitely. ### How to Review 1. Inspect `SubsquidClient::new` in `src/subsquid/client.rs` to verify that `Client::builder().timeout(...)` is configured with a 30-second duration. 2. Verify existing unit tests (`test_transfer_query_params_builder`, pagination tests) continue to pass without timeout disruptions.
|
I think this has the wrong formatting, use our formatter then the code changes will look clean |
|
Thanks @n13. The line endings/formatting noise has been cleaned up using the project's |
|
@magqqgq could you apply our formatter please? Then the changes will be more obvious. |
|
basically you have to check the exact thing used in the CI and apply it We should put this in a contribution guide |
CI rustfmt (nightly-2026-08-31) requires newline_style = Unix.
|
Applied the CI formatter on this branch. For future PRs, match the format job in rustup toolchain install nightly-2026-08-31 --profile minimal --component rustfmt
cargo +nightly-2026-08-31 fmt --all
taplo format --config taplo.tomlThat nightly pin matters: To verify the same way CI does: cargo +nightly-2026-08-31 fmt --all -- --check
taplo format --check --config taplo.toml
|
n13
left a comment
There was a problem hiding this comment.
Reviewer model: GPT-6 Sol
APPROVE — No blocking findings at 941df477f40526e8d37e7e401dad643e1533c913. The 30-second timeout in src/subsquid/client.rs:58 covers each Subsquid HTTP request through response-body completion; existing error handling propagates transport failures to callers.
Validation: git diff --check and cargo +nightly-2026-08-31 fmt --all -- --check passed. SKIP_CIRCUIT_BUILD=1 cargo test --locked --no-default-features --lib subsquid::client::tests passed all four focused tests.
CI at review time: formatting, security audit, analysis, and both build/test jobs passed; examples were pending. The separate dependency-cooldown job failed on the age of locked crates, though this PR changes neither dependencies nor Cargo.lock. That check needs resolution before merge.
Description
This pull request addresses a medium-severity network reliability finding in
quantus-cliidentified during the Quantus workspace security audit (FM-11).Previously,
SubsquidClient::newinstantiatedreqwest::Clientusing default settings without an explicit request timeout. Because reqwest has no default timeout, a stalled or non-responsive Subsquid GraphQL indexer endpoint would block calling tasks indefinitely, locking reward-collection and privacy-preserving transfer query CLI operations without recovery paths or errors.Key Changes & Remediations
Bound Indexer HTTP Transport (FM-11 -
src/subsquid/client.rs)Client::builder().timeout(std::time::Duration::from_secs(30))duringSubsquidClientinitialization.How to Review
SubsquidClient::newinsrc/subsquid/client.rsto verify thatClient::builder().timeout(...)is configured with a 30-second duration.test_transfer_query_params_builder, pagination tests) continue to pass without timeout disruptions.