Skip to content

[r3.7] cl: align Gloas consensus and APIs with v1.7.0-beta.2 - #24386

Merged
yperbasis merged 2 commits into
release/3.7from
kewei/cherry-pick-23845-to-release-3.7
Sep 29, 2026
Merged

yperbasis merged 2 commits into
release/3.7from
kewei/cherry-pick-23845-to-release-3.7

Conversation

@domiwei

@domiwei domiwei commented Sep 29, 2026

Copy link
Copy Markdown
Member

Cherry-pick of #23845 to release/3.7.

r3.7-specific adaptations

## Summary

- emit each requested validator duty at most once per slot when the
validator occupies repeated PTC seats
- preserve distinct validators in one slot and the same validator duties
across different slots
- keep consensus PTC seat multiplicity unchanged outside the Beacon API
response

Fixes #24115

## Testing

- `go test ./cl/beacon/handler -run
"^TestPostPtcDutiesDeduplicatesRepeatedCommitteeSeats$" -count=1`
- `go test ./cl/beacon/handler -count=1`
- `make lint` (two clean runs)
- `make erigon integration`

The regression test was observed failing before the production fix with
16,384 duties instead of one distinct duty per validator and slot.
## Summary

Align Caplin's Gloas consensus behavior and Beacon/Builder APIs with
`consensus-specs` v1.7.0-beta.2, including the missing beta.0
prerequisites required to reach the beta.2 target correctly.

The branch was rebased onto current `main` at
`1ca363730a90ef2419d98f0150e1961d1eb27d84` and reduced from 51 changed
files to 37. Operational hardening that is not required for beta.2 has
moved to two stacked follow-ups.

## Main changes

- initialize anchor PTC votes as uncast and use the parent header slot
for payload settlement, attestation processing, and rewards
- enforce pre-Gloas boundaries for proposer preferences, PTC duties, and
payload attestations
- validate builder version/activity, parent-requested exits, equal
block/parent hashes, gossip timing, and the beta.2 voluntary-exit
wall-clock rule
- keep bounded parent builder-exit summaries so untrusted bid validation
does not perform unbounded disk I/O, with restart/eviction fallback
- serve canonical FULL execution-payload-envelope ranges with bounded
work and explicit unavailable-history behavior
- accept beta.2 invalid transition fixtures without `post.ssz_snappy`
and apply per-case fork config overlays
- pin and pass the official beta.2 mainnet Gloas fixture corpus

## Scope split

- #24279: chain-tip payload-envelope recovery, persisted
replay/revalidation, and checkpoint/P2P plumbing
- #24280: voluntary-exit admission, publication coalescing, eviction
identity, and finalized pruning

Both follow-ups remain stacked on this branch and need rebasing onto
this rewritten head before their next review.

## Latest main rebase

- Base: `1ca363730a90ef2419d98f0150e1961d1eb27d84`
- Head: `86f9315cdbaf3a00d2847352dbe54a0e2b6bd50a`

## Validation

- `go test ./cl/phase1/network/services ./cl/phase1/forkchoice
./cl/sentinel/handlers ./cl/beacon/handler -count=1`
- `go test -tags=spectest ./cl/spectest -run '^Test$/^mainnet$/^gloas$'
-count=1`
- focused race tests for PTC duties and execution-payload-envelope
ByRange handling
- `make lint` (two clean consecutive runs)
- `make erigon integration`
- adversarial review covered fork-direction symmetry, zero/nil/genesis
boundaries, stale or unavailable state, bounded untrusted work, cache
refresh after waits, REST/gossip error-classification boundaries, and
local-self-build ingress

The previous review's actionable failures and concurrency findings are
covered by focused regression tests. GitHub CI passes on head
`86f9315cdbaf3a00d2847352dbe54a0e2b6bd50a`.

## Devnet 11 experiment

The retained experiment used an older head with embedded Caplin and 15
active Lighthouse validator keys. Attestations and payload attestations
were observed, but no proposer duty occurred before the public endpoints
and discovered peers became unavailable. The beta.2 head has not been
redeployed to the stopped devnet.

## Residual risk and deferred work

- the cold envelope disk-read path permits only one active read;
acquisition waiters remain bounded by gossip validation concurrency,
while a permanently wedged storage call can retain the token until the
underlying API becomes cancellable
- full mandatory-range execution-envelope archival remains architectural
follow-up; pruned, inconsistent, or incompletely scanned history returns
`ResourceUnavailable`
- broader coordinated forkchoice ordering work tracked upstream in
`ethereum/consensus-specs#5563`, `ethereum/consensus-specs#5586`, and
`ethereum/consensus-specs#5125` remains outside this delta
@yperbasis
yperbasis added this pull request to the merge queue Sep 29, 2026
Merged via the queue into release/3.7 with commit 9f4266a Sep 29, 2026
140 checks passed
@yperbasis
yperbasis deleted the kewei/cherry-pick-23845-to-release-3.7 branch September 29, 2026 10:16
bloxster pushed a commit that referenced this pull request Oct 1, 2026
"The latest 3.7 release" is v3.7.0 today, which predates the
Glamsterdam/Gloas fixes the fork needs (#24386, #24441, #24474), so an
operator could follow the note and still run an incompatible version.

Both versions are historical, so they are declared with
llms-pinned-version: v3.7.0 is the current release on this branch and
v3.7.1 will be, and either literal would otherwise fail
test_nothing_in_the_sources_hardcodes_the_release.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants