Repository navigation
Add Gloas fork support - #231
Conversation
Fixes checkpoint sync for bal-devnet-2 by switching from pk910/go-eth2-client (missing SlotNumber) to qu0b/go-eth2-client eip7928 branch which includes both BlockAccessList (EIP-7928) and SlotNumber (EIP-7843) in the Gloas ExecutionPayload types. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Update the go-eth2-client dependency to include the new ptc_window field in the gloas BeaconState, required for consensus-specs v1.7.0-alpha.4 compatibility. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Update go-eth2-client for consensus-specs alpha.4
- Remove unused nolint:gosec directives in download.go - Preallocate peers slice with capacity in default.go - Add missing whitespace in root.go Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Replaces the pk910 replace directive with a direct dependency on github.com/ethpandaops/go-eth2-client v0.0.1, and updates all imports from github.com/attestantio/go-eth2-client to the ethpandaops fork. Bumps ethpandaops/beacon to a pseudo-version that also uses the ethpandaops fork (pending ethpandaops/beacon#70). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…hpandaops-v0.0.1 chore(deps): migrate to ethpandaops/go-eth2-client v0.0.1
….1.0 chore(deps): bump ethpandaops/go-eth2-client to v0.1.0
…ains When the finalized epoch is smaller than historical_epoch_count (e.g. on a freshly started devnet or kurtosis enclave), the previous expression `latestSlot - SlotsPerEpoch*HistoricalEpochCount` underflows uint64 and produces a value near 2^64, so the loop never executes and the /checkpointz/v1/beacon/slots endpoint returns an empty list — leaving the UI's historical checkpoints table blank until the chain has produced HistoricalEpochCount epochs. Clamp the lower bound at 0 so we return every available finalized epoch-boundary slot, regardless of chain age. Same fix as #241 but targeted at release/gloas so gloas devnets can pick it up without waiting for a master merge.
…ts-underflow-gloas fix(gloas): prevent uint64 underflow in ListFinalizedSlots on short-lived chains
….1.5 chore(deps): bump ethpandaops/go-eth2-client to v0.1.5
downloadAndStoreBeaconState fetched the state by slot and stored whatever came back under the block's state root. A node that is behind can answer a by-slot state request with a state from a different chain view (e.g. its stale head dialed forward through empty slots, as lodestar and lighthouse do) instead of erroring; checkpointz would then serve that state at /eth/v2/debug/beacon/states/finalized and checkpoint-syncing clients fail with a state root mismatch against block.state_root. Ask the node for the exact state root committed to in the block instead. A node that doesn't have that state errors and the serving loop retries with another node; no root comparison or extra round-trip needed, and callers can verify the returned state themselves if they want to. Teku in pruned storage mode currently 404s by-root lookups for finalized states (Consensys-Incorporated/teku#11087 fixes this); such a node is skipped like any other node that can't serve the state. Observed on glamsterdam-devnet-7 with a lodestar upstream whose head was ~15k slots behind: it returned a fabricated state for the finalized checkpoint slot instead of erroring. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017K6pyDaSgX2FcLtQ1qQ8Vu
golangci-lint (latest, currently v2.12.2) flags 25 goconst issues on every PR run, all pre-existing on the base branch: repeated log field and metric label literals, throwaway test case names, and string literals where the eth.ID constants already exist. Constant-ify the repeated literals, name the test cases descriptively, and use the existing ID constants in NewStateIdentifier and the ID mapping tests. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
gcr.io/prysmaticlabs/prysm/beacon-chain:latest froze at v5.3.2 (built 2025-04-14) when prysm moved to OffchainLabs. That pre-fulu build cannot decode current fulu states, so both prysm integration jobs die at checkpoint-sync with "invalid ssz encoding" on every network. gcr.io/offchainlabs/prysm/beacon-chain:latest tracks current releases (v7.1.8, built 2026-08-01). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…root fix(beacon): fetch beacon state by root instead of slot
There was a problem hiding this comment.
PR migrates checkpointz from attestantio/go-eth2-client to the ethpandaops fork (v0.1.6) plus companion bumps (beacon, dynamic-ssz) to add Gloas fork support across the SSZ encoder and web UI, with a few genuine bugfixes folded in (ListFinalizedSlots uint64 underflow, negative-slot rejection, state fetch by root). I verified every new module version exists and is OSV-clean (the geth bump even resolves GHSA-2gjw-fg97-vg3r), and confirmed against the fork's real source and the beacon library that the Gloas cases and the by-root state fetch are consistent and valid. Overall a clean, well-scoped change.
Reviewed 38 changed file(s) @ fb651aed — no blocking issues found.
"The road to hell is paved with v2 rewrites."
…244) The historical-checkpoints table flags the row currently being served by the checkpointz instance. It did this by comparing each row's epoch against `status.data.finality.finalized.epoch`. Two issues: 1. The slots list is built from `d.head` (majority-decided finality), but the status's `finality.finalized` is `d.servingBundle` (the last fully-downloaded bundle). When bundle downloads lag — e.g. after an upstream blip or on short-lived devnets — `d.head` advances while `d.servingBundle` stays behind, so the slots list contains rows for epochs that don't yet have a serving bundle. The flag then either appears on a non-top row with no explanation or disappears entirely until the bundle catches up. 2. Epoch-only comparison is ambiguous in principle (two different roots can share the same finalized epoch across restarts / reorgs, however rare post-finality). Matching by block root is the semantically correct signal: "which row's bundle is the one we're serving". Prefer matching by `slot.block_root === status.finality.finalized.root` and fall back to the old epoch-based comparison for rows whose block_root hasn't been populated yet.
Replaces the untagged side-branch pseudo-version with the tagged release. v0.69.0 already targets the ethpandaops go-eth2-client fork; MVS keeps go-eth2-client at v0.1.6 and dynamic-ssz at v1.3.2.
Clears GHSA-mh2q-q3fh-2475 (baggage extraction DoS) in the indirect otel modules.
There was a problem hiding this comment.
Summary
This PR switches the beacon client dependency from attestantio/go-eth2-client to the ethpandaops fork, bumps the beacon library and dynamic-ssz, and adds Gloas cases to the SSZ encoder and web types, plus a few fixes (state fetch by state root, slot underflow clamp, negative-slot rejection). The code changes are clean and I verified the library APIs they rely on; the one real problem is the otel bump landing on a vulnerable version.
Issues
- 🔴
go.mod:68— otel bumped to v1.41.0, which is in GO-2026-5158's affected range — see the thread on that line
Reviewed @ 77d86d17
"The road to hell is paved with v2 rewrites."
| go.opentelemetry.io/otel/metric v1.16.0 // indirect | ||
| go.opentelemetry.io/otel/trace v1.16.0 // indirect | ||
| go.opentelemetry.io/auto/sdk v1.2.1 // indirect | ||
| go.opentelemetry.io/otel v1.41.0 // indirect |
There was a problem hiding this comment.
🔴 otel bumped to v1.41.0, which is in GO-2026-5158's affected range
OSV reports GO-2026-5158 (CVE-2026-41178, baggage parsing doesn't cap raw header length) affects go.opentelemetry.io/otel v1.41.0, fixed in v1.42.0. Likely not reachable here (the vulnerable symbols live in otel/baggage, and I verified the only module importing otel in this graph, ethpandaops/go-eth2-client v0.1.6, imports only otel/otel/trace), but since 1.42.0 is a trivial bump there is no reason to pin the one affected version.
v1.41.0 is inside GO-2026-5158's range; v1.44.0+ clears both it and GO-2026-5506.
There was a problem hiding this comment.
Adds Gloas fork support by swapping to the ethpandaops go-eth2-client fork (verified Gloas types, HTTP decode, SSZ/JSON codecs and fork ordering all exist in v0.1.6/v0.69.0), extends the SSZ encoder with Gloas cases, fixes a uint64 underflow in ListFinalizedSlots for short chains, and switches state fetching to state-root IDs. All checks — OSV on the new deps, caller tracing, and cross-referencing the dependency source — came back clean; no real problems found.
Reviewed 34 changed file(s) @ 484d509d — no blocking issues found.
"The road to hell is paved with v2 rewrites."
No description provided.