Skip to content

feat: route WebSockets through proxies, speed up hot paths, refresh docs - #29

Merged
SebastianBoehler merged 3 commits into
mainfrom
feat/network-routing-perf-docs
Oct 6, 2026
Merged

SebastianBoehler merged 3 commits into
mainfrom
feat/network-routing-perf-docs

Conversation

@SebastianBoehler

Copy link
Copy Markdown
Owner

Problem

  • Only REST honored set_proxy. Market, user, and JSON-RPC WebSockets always connected directly, because IXWebSocket has no proxy support.
  • The market-data and signing hot paths spent most of their time on avoidable copies and allocations.
  • The README was long and hard to scan, and contributor tooling (build.sh) was stale.

Changes

Networking (feat(network))

  • A routed WebSocketClient connects through a loopback relay that forwards each connection over a libcurl CONNECT_ONLY session. WebSockets get the same HTTP, HTTPS, and SOCKS proxies and TLS verification as REST.
  • set_default_network_route() routes every SDK transport, including internal ones.
  • New interface_name option binds to VPN interfaces.
  • Routes fail closed: no silent direct fallback.
  • check_geoblock() / ClobClient::get_geoblock_status() query Polymarket's eligibility endpoint through the configured route.
  • The docs note that Polymarket's Terms of Use prohibit using proxies or VPNs to get around geographic restrictions.

Performance (perf), best of 7, Release, Apple M4 Max:

Workload Before After
100-level book parse + apply 53.7 us 28.7 us
2-change price_change 5.8 us 3.4 us
V2 order signing 27.1 us 15.6 us

Neg-risk metadata is now cached for the client's lifetime, which removes a periodic round trip from the order path.

Docs (docs)

  • New README with a centered header and badges.
  • Guides: docs/networking.md, docs/migration.md, docs/polygon-indexing.md.
  • AGENTS.md gains a repository map; CLAUDE.md imports it.
  • Added SECURITY.md and CODEOWNERS.
  • build.sh is now a one-command build and offline test run.

Compatibility

HttpClientOptions and WebSocketOptions gained trailing fields, so consumers must rebuild. This suggests v3.1.0. No source changes are needed.

Validation

  • Local macOS Release: 51/51 offline tests pass, including the new test_network_routing and test_package_consumer.
  • scripts/quality.py origin/main passes: clang-format, clang-tidy, Prettier.
  • The routing test was mutation-checked. Ignoring the route fails 13 checks; removing the connect abort makes disconnect hang about 10 s.
  • New parser and signer edge cases also pass on the old code, which shows the behavior is preserved.
  • README C++ snippets compile against the headers.
  • Live check, read-only and run once: a wss:// market subscription through a local CONNECT proxy received real book data, and the geoblock check went through the proxy.
  • Not run locally: Linux and Debug builds. CI covers them.

Follow-ups worth considering:

  • An HttpClient handle pool, since requests on one client are serialized.
  • Heartbeat skipping, so the keep-alive ping doesn't delay orders.
  • Tick-size refresh-ahead.
  • Enable private vulnerability reporting so the SECURITY.md link works.

🤖 Generated with Claude Code

SebastianBoehler and others added 3 commits October 6, 2026 19:46
IXWebSocket cannot use proxies, so market, user, and JSON-RPC WebSockets
connected directly even when REST used a proxy. A routed WebSocketClient
now connects through a loopback relay that forwards each connection over
a libcurl CONNECT_ONLY session, so WebSockets get the same HTTP, HTTPS,
and SOCKS proxy support and TLS verification as REST.

- Add NetworkRoute and set_default_network_route() to route every SDK
  transport, including the ones PositionClient, OrderbookManager,
  UserStream, and the JSON-RPC clients create internally.
- Add interface binding (HttpClientOptions/WebSocketOptions
  interface_name) for VPN tunnel interfaces.
- Routes fail closed: an unreachable or rejecting proxy fails the
  connection instead of falling back to a direct route.
- Drop the dead CURLOPT_PROXYTYPE branch: a socks5:// scheme already
  selects local DNS, contrary to its comment. Docs recommend socks5h://.
- Add check_geoblock() and ClobClient::get_geoblock_status(), which query
  Polymarket's eligibility endpoint through the configured route.

HttpClientOptions and WebSocketOptions gained trailing fields; consumers
must rebuild against the new headers.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Market data:
- Parse each frame once without deep-copying the JSON DOM.
- Read price and size strings by reference instead of copying them
  before conversion; strtod keeps std::stod's grammar and range errors.
- Emit snapshots already in book order and detect duplicate prices with
  a sort instead of a hash set per side.
- Gate the arbitrage check on prices before copying market identifiers.

Order path:
- Encode decimal uint256 values without per-digit allocations.
- Hex-encode with a lookup table instead of stringstream.
- Compute the constant POLY_1271 type hashes and suffix once.
- Cache neg-risk metadata for the client's lifetime. A token's neg-risk
  flag is fixed at market creation, so the 5-minute TTL only added a
  round trip to the order path.

Benchmarks now use real-length IDs and price_change traffic. Best of 7,
Release, Apple M4 Max: 100-level book 53.7 to 28.7 us, price_change 5.8
to 3.4 us, V2 signing 27.1 to 15.6 us.

New tests cover malformed numbers and changes, unsorted duplicate prices,
77-digit and uint256-boundary token IDs against their hex forms.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Rewrite the README with a centered header, badges, a compiling quick
  start, feature and example tables, performance numbers, and a docs
  index. Move migration notes and Polygon indexing details into
  docs/migration.md and docs/polygon-indexing.md.
- Add a repository map and networking and benchmark references to
  AGENTS.md, and CLAUDE.md that imports it for Claude Code.
- Add SECURITY.md, CODEOWNERS, and a network route field in the bug
  report template.
- Turn build.sh into a one-command configure, build, and offline test
  run that works with the bash 3.2 shipped on macOS.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@SebastianBoehler
SebastianBoehler merged commit 7c4ae7e into main Oct 6, 2026
4 checks passed
@SebastianBoehler
SebastianBoehler deleted the feat/network-routing-perf-docs branch October 6, 2026 17:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant