Skip to content

Add Gloas fork support - #231

Merged
samcm merged 35 commits into
masterfrom
release/gloas
Sep 24, 2026
Merged

samcm merged 35 commits into
masterfrom
release/gloas

Conversation

@qu0b

@qu0b qu0b commented Jan 2, 2026

Copy link
Copy Markdown
Member

No description provided.

@qu0b
qu0b requested a review from samcm as a code owner January 2, 2026 11:01
Comment thread pkg/beacon/download.go Outdated
qu0b and others added 10 commits January 12, 2026 13:41
Fixes checkpoint sync for bal-devnet-2 by switching from pk910/go-eth2-client
(missing SlotNumber) to qu0b/go-eth2-client eip7928 branch which includes
both BlockAccessList (EIP-7928) and SlotNumber (EIP-7843) in the Gloas
ExecutionPayload types.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Update the go-eth2-client dependency to include the new ptc_window
field in the gloas BeaconState, required for consensus-specs
v1.7.0-alpha.4 compatibility.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Update go-eth2-client for consensus-specs alpha.4
- Remove unused nolint:gosec directives in download.go
- Preallocate peers slice with capacity in default.go
- Add missing whitespace in root.go

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Replaces the pk910 replace directive with a direct dependency on
github.com/ethpandaops/go-eth2-client v0.0.1, and updates all imports
from github.com/attestantio/go-eth2-client to the ethpandaops fork.

Bumps ethpandaops/beacon to a pseudo-version that also uses the
ethpandaops fork (pending ethpandaops/beacon#70).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…hpandaops-v0.0.1

chore(deps): migrate to ethpandaops/go-eth2-client v0.0.1
….1.0

chore(deps): bump ethpandaops/go-eth2-client to v0.1.0
…ains

When the finalized epoch is smaller than historical_epoch_count (e.g. on a
freshly started devnet or kurtosis enclave), the previous expression
`latestSlot - SlotsPerEpoch*HistoricalEpochCount` underflows uint64 and
produces a value near 2^64, so the loop never executes and the
/checkpointz/v1/beacon/slots endpoint returns an empty list — leaving the
UI's historical checkpoints table blank until the chain has produced
HistoricalEpochCount epochs.

Clamp the lower bound at 0 so we return every available finalized
epoch-boundary slot, regardless of chain age.

Same fix as #241 but targeted at release/gloas so gloas devnets can pick
it up without waiting for a master merge.
…ts-underflow-gloas

fix(gloas): prevent uint64 underflow in ListFinalizedSlots on short-lived chains
….1.5

chore(deps): bump ethpandaops/go-eth2-client to v0.1.5
qu0b and others added 4 commits August 12, 2026 09:01
downloadAndStoreBeaconState fetched the state by slot and stored
whatever came back under the block's state root. A node that is
behind can answer a by-slot state request with a state from a
different chain view (e.g. its stale head dialed forward through
empty slots, as lodestar and lighthouse do) instead of erroring;
checkpointz would then serve that state at
/eth/v2/debug/beacon/states/finalized and checkpoint-syncing clients
fail with a state root mismatch against block.state_root.

Ask the node for the exact state root committed to in the block
instead. A node that doesn't have that state errors and the serving
loop retries with another node; no root comparison or extra
round-trip needed, and callers can verify the returned state
themselves if they want to.

Teku in pruned storage mode currently 404s by-root lookups for
finalized states (Consensys-Incorporated/teku#11087 fixes this); such a node is
skipped like any other node that can't serve the state.

Observed on glamsterdam-devnet-7 with a lodestar upstream whose head
was ~15k slots behind: it returned a fabricated state for the
finalized checkpoint slot instead of erroring.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017K6pyDaSgX2FcLtQ1qQ8Vu
golangci-lint (latest, currently v2.12.2) flags 25 goconst issues on
every PR run, all pre-existing on the base branch: repeated log field
and metric label literals, throwaway test case names, and string
literals where the eth.ID constants already exist. Constant-ify the
repeated literals, name the test cases descriptively, and use the
existing ID constants in NewStateIdentifier and the ID mapping tests.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
gcr.io/prysmaticlabs/prysm/beacon-chain:latest froze at v5.3.2 (built
2025-04-14) when prysm moved to OffchainLabs. That pre-fulu build
cannot decode current fulu states, so both prysm integration jobs die
at checkpoint-sync with "invalid ssz encoding" on every network.
gcr.io/offchainlabs/prysm/beacon-chain:latest tracks current releases
(v7.1.8, built 2026-08-01).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…root

fix(beacon): fetch beacon state by root instead of slot

@redpandabot redpandabot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PR migrates checkpointz from attestantio/go-eth2-client to the ethpandaops fork (v0.1.6) plus companion bumps (beacon, dynamic-ssz) to add Gloas fork support across the SSZ encoder and web UI, with a few genuine bugfixes folded in (ListFinalizedSlots uint64 underflow, negative-slot rejection, state fetch by root). I verified every new module version exists and is OSV-clean (the geth bump even resolves GHSA-2gjw-fg97-vg3r), and confirmed against the fork's real source and the beacon library that the Gloas cases and the by-root state fetch are consistent and valid. Overall a clean, well-scoped change.


Reviewed 38 changed file(s) @ fb651aed — no blocking issues found.
"The road to hell is paved with v2 rewrites."

redpandabot[bot]

This comment was marked as outdated.

barnabasbusa and others added 3 commits September 24, 2026 15:26
…244)

The historical-checkpoints table flags the row currently being served by
the checkpointz instance. It did this by comparing each row's epoch
against `status.data.finality.finalized.epoch`.

Two issues:

1. The slots list is built from `d.head` (majority-decided finality), but
   the status's `finality.finalized` is `d.servingBundle` (the last
   fully-downloaded bundle). When bundle downloads lag — e.g. after an
   upstream blip or on short-lived devnets — `d.head` advances while
   `d.servingBundle` stays behind, so the slots list contains rows for
   epochs that don't yet have a serving bundle. The flag then either
   appears on a non-top row with no explanation or disappears entirely
   until the bundle catches up.
2. Epoch-only comparison is ambiguous in principle (two different roots
   can share the same finalized epoch across restarts / reorgs, however
   rare post-finality). Matching by block root is the semantically
   correct signal: "which row's bundle is the one we're serving".

Prefer matching by `slot.block_root === status.finality.finalized.root`
and fall back to the old epoch-based comparison for rows whose
block_root hasn't been populated yet.
Replaces the untagged side-branch pseudo-version with the tagged release.
v0.69.0 already targets the ethpandaops go-eth2-client fork; MVS keeps
go-eth2-client at v0.1.6 and dynamic-ssz at v1.3.2.
Clears GHSA-mh2q-q3fh-2475 (baggage extraction DoS) in the indirect otel modules.

@redpandabot redpandabot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary

This PR switches the beacon client dependency from attestantio/go-eth2-client to the ethpandaops fork, bumps the beacon library and dynamic-ssz, and adds Gloas cases to the SSZ encoder and web types, plus a few fixes (state fetch by state root, slot underflow clamp, negative-slot rejection). The code changes are clean and I verified the library APIs they rely on; the one real problem is the otel bump landing on a vulnerable version.

Issues

  • 🔴 go.mod:68 — otel bumped to v1.41.0, which is in GO-2026-5158's affected range — see the thread on that line

Reviewed @ 77d86d17
"The road to hell is paved with v2 rewrites."

Comment thread go.mod Outdated
go.opentelemetry.io/otel/metric v1.16.0 // indirect
go.opentelemetry.io/otel/trace v1.16.0 // indirect
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
go.opentelemetry.io/otel v1.41.0 // indirect

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 otel bumped to v1.41.0, which is in GO-2026-5158's affected range

OSV reports GO-2026-5158 (CVE-2026-41178, baggage parsing doesn't cap raw header length) affects go.opentelemetry.io/otel v1.41.0, fixed in v1.42.0. Likely not reachable here (the vulnerable symbols live in otel/baggage, and I verified the only module importing otel in this graph, ethpandaops/go-eth2-client v0.1.6, imports only otel/otel/trace), but since 1.42.0 is a trivial bump there is no reason to pin the one affected version.

v1.41.0 is inside GO-2026-5158's range; v1.44.0+ clears both it and GO-2026-5506.

@redpandabot redpandabot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Adds Gloas fork support by swapping to the ethpandaops go-eth2-client fork (verified Gloas types, HTTP decode, SSZ/JSON codecs and fork ordering all exist in v0.1.6/v0.69.0), extends the SSZ encoder with Gloas cases, fixes a uint64 underflow in ListFinalizedSlots for short chains, and switches state fetching to state-root IDs. All checks — OSV on the new deps, caller tracing, and cross-referencing the dependency source — came back clean; no real problems found.


Reviewed 34 changed file(s) @ 484d509d — no blocking issues found.
"The road to hell is paved with v2 rewrites."

@samcm
samcm merged commit 23edd3c into master Sep 24, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants