github OffchainLabs/prysm v7.2.0

4 hours ago

v7.2.0 - 2026-09-25

This release schedules the Gloas fork on the Sepolia testnet at epoch 353024 (October 6, 2026, 13:53:36 UTC). Sepolia operators are required to update to v7.2.0 before the fork, and must also run an execution client that supports the corresponding Amsterdam fork on Sepolia. Gloas is not yet scheduled for Hoodi or mainnet; operators of those networks are encouraged to update per their regular update cadence.

Sepolia gas limit: the Sepolia Gloas configuration published upstream on September 24 adds an EIP-8261 GAS_LIMIT_SCHEDULE entry that raises the network gas limit to 200M at the fork. That entry landed after this release was cut and is not included in v7.2.0, so validators on this release default to a 60M gas limit in their Gloas proposer preferences. Sepolia validators who want to propose with a 200M gas limit must set it explicitly at the option level: add "gas_limit": "200000000" to default_config (or to a key under proposer_config) in a version 2 proposer settings file loaded with --proposer-settings-file or --proposer-settings-url, or set it through the keymanager API with POST /eth/v1/validator/{pubkey}/gas_limit. An explicitly configured gas limit is honored as configured. Note that --suggested-gas-limit only applies to pre-Gloas mev-boost registrations and has no effect after the fork. A follow-up release will include the schedule.

Release highlights:

  • Gloas fork scheduled on Sepolia at epoch 353024 (October 6, 2026, 13:53:36 UTC). [PR]
  • Validator client support for Gloas builders: version 2 proposer settings, per-key builder configuration through the keymanager API, the Gloas builder REST endpoints, remote signing (web3signer) of Gloas blocks and a builder circuit breaker. --with-builder, --enable-builder and --suggested-gas-limit only produce legacy (pre-Gloas) mev-boost content and are deprecated.
  • Proposer settings loaded from --proposer-settings-file or --proposer-settings-url now reject unknown keys; review your proposer settings before updating. [PR]
  • Active-active REST validator client: with --enable-beacon-rest-api and several --beacon-rest-api-provider nodes, the validator client uses the best suited connected beacon node instead of failing over from a single active node. [PR]
  • Web3Signer public keys can be polled from the remote signer with --validators-external-signer-poll-interval, and keys are tracked per source. [PR]
  • The fast confirmation rule, behind the --enable-fast-confirmation flag. [PR]
  • The EF bootstrap nodes for mainnet, Sepolia and Hoodi are replaced with the NodeOps bootnode fleet. [PR]
  • Performance: SSZ marshalling and hash tree roots are now generated by methodical-ssz, hashtree is updated to v0.2.6, per-element hash tree roots of large SSZ lists are computed in parallel, and the state-diff (hdiff) path uses sparse validator diffs with less transient memory.
  • go-libp2p updated to v0.50.0. [PR]
  • Numerous bug fixes, including a checkpoint-synced node with --enable-state-diff and --beacon-db-pruning failing to restart, Electra attestation packing by marginal proposer reward, and beacon API endpoints returning the correct finalized flag and 404 instead of 500 for unknown states. See the Fixed section below.

Added

  • progressive merkleization of beacon state. [PR]
  • Support SSZ-encoded request bodies (Content-Type: application/octet-stream) for the POST /eth/v2/beacon/pool/attestations endpoint (Electra and later). [PR]
  • progressive merkleization for expected withdrawals. [PR]
  • progressive merkleization for builder pending withdrawals. [PR]
  • progressive merkleization for builders. [PR]
  • Log when sending FCU with payload attributes on late blocks and trigger an SSE event for the attributes. [PR]
  • Enforce Web3Signer users to set flags correctly on startup. [PR]
  • Add AttestationGloas. [PR]
  • Added IndexedAttestationGloas | AttesterSlashingGloas and replaced usage in codebase. [PR]
  • Cache the progressive Merkle tree for the Gloas beacon state and its validator/balance field tries, so a hash tree root after a small mutation recomputes only the affected subtrees. [PR]
  • version guards for beacon state progressive HTR. [PR]
  • Bash script for automating the version upgrade process. [PR]
  • Support the optional EIP-8261 GAS_LIMIT_SCHEDULE config as the epoch-based default and recommended maximum gas limit for gloas proposer preferences. [PR]
  • --builder-header-timeout: makes the builder getHeader timeout (BUILDER_PROPOSAL_DELAY_TOLERANCE, previously hardcoded to 1s) configurable. Must be greater than 0. Only effective up to the Fulu fork. [PR]
  • --disable-graffiti-client-append beacon node flag, to stop appending consensus and execution client version information to the block graffiti. [PR]
  • Record Gloas data column KZG proof verification time in the existing beacon_kzg_verification_data_column_batch_milliseconds histogram. [PR]
  • Accept SSZ (application/octet-stream) request bodies on POST /eth/v2/validator/aggregate_and_proofs. The body is decoded as the SSZ List[SignedAggregateAndProof], fork-versioned by the Eth-Consensus-Version header. [PR]
  • Expose CONFIRMATION_BYZANTINE_THRESHOLD, MAX_SIGNED_AGGREGATE_AND_PROOF_SIZE, MAX_ATTESTER_SLASHING_SIZE, MAX_DATA_COLUMN_SIDECAR_SIZE, MAX_PARTIAL_DATA_COLUMN_SIDECAR_SIZE and MAX_SIGNED_EXECUTION_PAYLOAD_BID_SIZE in the /eth/v1/config/spec beacon API endpoint. [PR]
  • execution_payload_value field and Eth-Execution-Payload-Value header in the produceBlockV4 response, per ethereum/beacon-APIs#631. [PR]
  • tools/genception, a GOPACKAGESDRIVER that answers go/packages queries from a Bazel-supplied package inventory, so code generators that load types through go/packages can run inside the Bazel sandbox. [PR]
  • Validator client: keys added through a keymanager reload are now held out of duties until a doppelganger check clears them (behind --enable-doppelganger). [PR]
  • Gloas builder circuit breaker: blacklist builders that win an auction but never reveal the payload. [PR]
  • The REST VC now submits POST /eth/v2/validator/aggregate_and_proofs with an SSZ request body, falling back to JSON when the beacon node rejects SSZ. [PR]
  • Add GET/POST/DELETE /eth/v1/validator/{pubkey}/builders keymanager endpoints for per-key builder configuration (keymanager-APIs #88). The endpoints respond 501 on networks without a scheduled gloas fork, where builder configuration cannot take effect. [PR]
  • Per-validator validator_failed_envelope_submissions metric counting failed self-build envelope submissions (omitted under --disable-account-metrics). [PR]
  • Prune the state-diff tree along with the rest of the historical data when --beacon-db-pruning is enabled. [PR]
  • --submit-blacklisted-builder-bids hidden feature flag to skip the builder circuit breaker check in SubmitSignedExecutionPayloadBid, so a blacklisted builder can still broadcast its bid for testing that peers do not propagate it. [PR]
  • Support POST on /eth/v4/validator/blocks/{slot} with a BuilderConfig body and return the winning builder in the Eth-Builder-Url response header, per beacon-APIs #630. [PR]
  • Add POST /eth/v1/validator/builder_preferences to forward per-builder preference entries to their builders. [PR]
  • Read the Eth-Builder-Url request header in the block publishing endpoints to submit the signed block to the winning builder. [PR]
  • Add --validators-external-signer-poll-interval (alias: --remote-signer-poll-interval) to periodically poll the public keys from the remote signer public-keys URL. Defaults to 0 (disabled). [PR]
  • Connect the REST validator client to the Gloas builder endpoints: block requests carry the BuilderConfig via POST, the Eth-Builder-Url header is read from block production and echoed on publish, and builder preferences are submitted to POST /eth/v1/validator/builder_preferences. [PR]
  • Validator client now supports remote signing (web3signer) of Gloas blocks and the new Gloas signing types: builder request auth, execution payload envelope, payload attestation message, and proposer preferences. [PR]
  • Add a fast_confirmation event topic to /eth/v1/events, emitted after every run of the fast confirmation rule. [PR]
  • Introduce progressiveStateSchema for gloas and later forks. [PR]
  • Reject execution payload bids whose block_hash equals their parent_block_hash, on gossip and in process_execution_payload_bid. [PR]
  • Add execution.WithRPCClientDialer option allowing an embedding process to supply the execution node RPC client (e.g. one backed by rpc.DialInProc) instead of dialing the configured HTTP endpoint. [PR]
  • Gloas: ignore proposer preferences whose proposal slot is before the fork. [PR]
  • Gloas: ignore an execution payload bid whose builder the parent's payload exits. [PR]
  • Implement the POST /eth/v1/beacon/states/{state_id}/builders beacon API endpoint (getStateBuilders), returning the Gloas builder registry filterable by builder IDs (pubkeys or indices) and statuses (pending, active, exited). [PR]
  • Add proof generation for Gloas states and progressive containers. [PR]
  • Gloas: add the dependent root check to proposer preferences gossip validation. [PR]
  • Log at debug level when a Gloas builder answers a bid request with no bid. [PR]
  • Add last payload at forkchoice setup. [PR]
  • Deliver payload-availability notifications to gRPC validator clients so PTC votes can be submitted before the deadline. Older beacon nodes retain deadline-based voting with an explicit compatibility warning. [PR]
  • Schedule the Gloas fork on Sepolia at epoch 353024 (2026-10-06 13:53:36 UTC). [PR]

Changed

  • E2E fork transition evaluators now poll GET /eth/v2/beacon/blocks/head over the beacon API instead of opening a gRPC StreamBlocksAltair stream, and share a single helper across all six forks. [PR]
  • Construct Web3Signer keymanager directly from its config instead of temporary in-memory wallet. [PR]
  • Reorg weak late blocks even on slot 31. [PR]
  • Allow builders to bid on multiple branches, deduplicate bids per (slot, parent_block_hash, parent_block_root) and only accept bids compatible with the head view. [PR]
  • Implement the active-active validator client: Using the --enable-beacon-rest-api flag, if multiple beacon nodes are provided in the --beacon-rest-api-provider flag, then the validator client will use the best suited connected beacon node to attest, participate in sync committees and propose blocks. This replaces the previous active-passive connection scheme, where only one beacon node was used at a time and the validator client failed over to another one only when the active node became unavailable. [PR]
  • Added proto/prysm/wrappers holding the hash-tree-root helpers that take concrete proto types, so encoding/ssz can shed its dependency on the generated proto packages. [PR]
  • Removed the proto-typed hash-tree-root helpers from encoding/ssz; proto/prysm/wrappers is now their only home and encoding/ssz no longer imports the generated proto packages. [PR]
  • Compute per-element hash tree roots in parallel for large SSZ lists, and read the feature config atomically instead of under a mutex. [PR]
  • optimize recomputeProgressiveOverlay hashing. [PR]
  • The REST VC now caches SSZ request-body support per beacon node host and endpoint for a day, so submissions to an endpoint that previously rejected SSZ skip straight to JSON instead of paying a failed SSZ round trip on every call. [PR]
  • Add v2 proposer settings ("version": 2) for configuring gloas builders; see the keymanager-APIs specification for the schema. [PR]
  • Proposer settings sources without a version are treated as version 2 when they contain v2 builder fields. [PR]
  • In v2 proposer settings, a nonempty builders list opts a key into mev-boost registration before the gloas fork, and an explicit empty list opts it out. [PR]
  • v1 builder settings are not migrated to v2: at the gloas fork fee recipients and graffiti carry over, while v1 builder content — including its gas limits — is dropped and replaced with defaults, with a warning. Gas limits apply post-fork only when explicitly set at the option level, so validators follow future chain-default gas limit increases unless they opt out. [PR]
  • The gas-limit keymanager API writes the option-level gas limit and no longer requires an enabled builder; deleting a gas limit unsets it (following the chain default) instead of pinning the current default value. Builder registration resolves fee recipients and participation independently, so a key with an enabled builder and only a default fee recipient now registers. [PR]
  • Setting a fee recipient, gas limit, or graffiti no longer snapshots default_config's builder settings onto that key; the key keeps following the default as it changes. [PR]
  • Renamed Gloas builder API request auth and preferences types to their unversioned spec names, and the bid request now requires the signed request auth body and always sends Date-Milliseconds and X-Timeout-Ms. [PR]
  • Block requests now carry resolved builder entries (url, auth, pubkeys, limits) instead of bare request auths, request auths sign the entry's auth data rather than its URL, and the beacon node routes builder requests by the entry url. [PR]
  • Rename the unreleased per-key builder keymanager endpoints from /eth/v1/validator/{pubkey}/builders to /eth/v1/validator/{pubkey}/builder_config, matching the merged keymanager-APIs #88 specification. [PR]
  • Builder bid selection enforces the per-entry limits and builder pubkey binding from the block request. [PR]
  • SSZ marshalling, unmarshalling and hash tree roots are now generated by methodical-ssz instead of fastssz. Generated code is emitted as a mainnet/minimal pair per target, driven by per-package *.yaml configs. [PR]
  • Both codegen paths (Bazel ssz_methodical and //build/gen) stamp the //go:build (!)minimal constraint via methodical's --go-build-constraint flag, making their output byte-identical; the drift check no longer masks build-constraint differences. [PR]
  • stream hdiff validator comparisons. [PR]
  • Gloas spec tests moved into their own mainnet/gloas and minimal/gloas packages, and download_spectests.bzl can now take spec test data from a local directory or tarball instead of downloading a release. [PR]
  • Validator client now forces stateless block production (Gloas and later) when it is configured with several beacon nodes, since only the node that built a block can reveal its execution payload. An explicit --stateless=false is ignored in this setup with a warning. [PR]
  • Move out compression mechanism from locked section of state diff cache getter/setter. [PR]
  • Validator client now submits Gloas builder preferences on the same schedule as proposer preferences — once per upcoming proposal slot instead of every slot, with re-pushes on restart, beacon host switch, and duty change. [PR]
  • Per-URL builder clients no longer follow HTTP redirects, per the beacon-APIs builder URL requirements. [PR]
  • An empty SSZ request body on the proposer preferences and payload attestation endpoints now returns No data submitted instead of an SSZ list-size error. [PR]
  • Per-index decode failure messages are no longer prefixed per endpoint: SSZ failures read could not decode SSZ message: …, JSON failures carry the converter error alone. [PR]
  • Use ReadOnlyBeaconState when it's enough (handleEpochBoundary / PtcLookupState / GetAttestationData). [PR]
  • Use read-only states in caches (CheckpointStateCache & SyncCommitteeHeadStateCache). [PR]
  • Use read-only states in validator duties RPC. [PR]
  • The config spec key DOMAIN_REQUEST_AUTH is now DOMAIN_BUILDER_REQUEST_AUTH, in both the /eth/v1/config/spec response and custom config YAML files. [PR]
  • Serve next-epoch attestation target states from the head state instead of running an epoch transition under the forkchoice lock. [PR]
  • Web3Signer public keys are now tracked per source (flag, public-keys URL, key file) with the validating set as their union, so one source can no longer overwrite another's keys. [PR]
  • GET /eth/v1/remotekeys marks keys owned by the key file as deletable instead of read-only. [PR]
  • POST /eth/v1/remotekeys returns error instead of imported when --validators-external-signer-key-file is not set, since the keys would not be persisted. [PR]
  • DELETE /eth/v1/remotekeys removes matching key-file entries even when the key is still provided by the flag or public-keys URL, and returns error explaining that the key continues validating through that source. Existing deployments should remove stale flag or URL keys copied into their key file by earlier versions. [PR]
  • --validators-external-signer-key-file no longer has the flag and URL keys written into it at startup. Those keys still validate, they are just owned by their own source instead of being adopted by the file across a restart. [PR]
  • --validators-external-signer-poll-interval is no longer ignored when a key file is configured. A poll now only replaces the URL's own keys, so it can run alongside the key file watcher. [PR]
  • Store epoch-precompute validators and Altair attestation deltas as value slices ([]precompute.Validator, []altair.AttDelta) instead of slices of per-validator heap-allocated pointers, eliminating roughly two heap objects per validator per epoch transition. [PR]
  • Wait-for-activation retries now wait for the next beacon node health probe to report healthy, replacing the linear backoff sleep of up to 60 seconds. [PR]
  • POST /eth/v1/validator/{pubkey}/graffiti now responds with 202 Accepted instead of 200 OK. [PR]
  • The validator client now warns at startup when per-key proposer settings saved in the validator DB (including changes made through the keymanager API) are replaced by the configured --proposer-settings-file/--proposer-settings-url, listing the dropped and overridden keys. [PR]
  • Bound every length-prefixed collection count in hdiff decoding before allocation, so a corrupt diff returns an error instead of panicking. [PR]
  • Check malformed snappy compression before decompressing via DecodedLen, so decoder doesn't allocate implausibly excessive memory. [PR]
  • Replace the EF bootstrap nodes for mainnet, sepolia and hoodi with the NodeOps bootnode fleet. [PR]
  • Proposer settings loaded from --proposer-settings-file or --proposer-settings-url now reject unknown keys, the internal builders_set marker, and version values above 2 instead of silently ignoring them. A misspelled key such as fee_recipent used to fall back to the default fee recipient without any log; it is now a startup error. The legacy v1 relays key is still accepted and ignored. [PR]
  • Changed ApplyValidatorsDiff to use sparse per-index updates rather than rebuilding the whole registry. [PR]
  • Update hashtree to v0.2.6. [PR]

Deprecated

  • --with-builder generates legacy (pre-gloas) mev-boost builder settings, which are discontinued at the gloas fork; the command now warns when the flag is used. [PR]
  • --enable-builder and --suggested-gas-limit produce only legacy (pre-gloas) content: they still drive mev-boost registrations before the fork, but never override v2 proposer settings or the gas limit schedule, and warn that they have no effect after gloas. An explicitly configured gas limit below the scheduled network gas limit is honored with a once-per-epoch warning. [PR]

Removed

  • Removed the validator client's StreamBlocksAltair implementations (beacon-api polling shim and grpc-api passthrough). The method was not part of validator/client/iface and had no callers. [PR]
  • Removed BeaconBlockConverter and its mock from validator/client/beacon-api. Its four ConvertREST*BlockToProto methods were only reachable from StreamBlocksAltair. [PR]
  • Removed beacon_block_proto_helpers.go. Ten of its fourteen helpers died with the converter; the rest duplicated structs.Attestation.ToConsensus(), which the two aggregate-selection call sites now use directly. [PR]
  • Removed the unused reference counter on the validator pubkey to index map. [PR]
  • Remove the active-passive connection scheme in the REST validator client, in favor of the new active-active connection scheme. [PR]
  • Removed the 39-method iface.Validator interface and its hand-written testutil.FakeValidator double. The runner, service and health monitor now take the concrete *validator, and validator/rpc declares the 7-method ValidatorService interface it actually consumes. [PR]
  • Remove the unused relays field from the builder config; a settings file that still contains it is unaffected. [PR]
  • The GET variant of /eth/v4/validator/blocks/{slot}: per the beacon-APIs spec the produce request is POST-only and always carries a BuilderConfig body. [PR]
  • Removed the unused SetProposerSettings from the validator RPC ValidatorService interface, ValidatorService, and validator; all writers go through UpdateProposerSettings. [PR]
  • Removed the hidden --disable-progressive-ssz feature flag. Gloas (EIP-7688) mandates progressive merkleization and the generated SSZ code never honored the flag, so toggling it only produced roots matching neither the spec nor the bounded build. [PR]
  • Removed the --//tools:disable_progressive_merkleization Bazel flag. SSZ_PROGRESSIVE=0 make gen ssz remains the single codegen escape hatch for the bounded merkleization form. [PR]
  • Removed the dead eth1-driven pre-genesis chain-start path from the execution service (ProcessChainStart, ChainStartFetcher, statefeed.ChainStarted, IsValidGenesisState) and reserved its ETH1ChainData/ChainStartData proto fields; the genesis state is always loaded before services start since #15470. [PR]

Fixed

  • Don't block Gloas block import on missing data column sidecars. DA is checked on the payload envelope. [PR]
  • Stop downscoring and disconnecting honest peers when a data column sidecar response references a block the node does not hold locally (a forked/behind node would otherwise self-isolate); recovery fetches now request columns by root. [PR]
  • Include the underlying error in the genesis provider failed warning log, so failures such as a misconfigured checkpoint sync URL are visible instead of surfacing later as a generic genesis state has not been initialized error. [PR]
  • Validator monitor: use continue instead of break when skipping validators with no recorded performance, so a single validator without data no longer suppresses the "Aggregated performance since launch" log for all other monitored validators. [PR]
  • Sync committee aggregators now filter pool messages by the root they voted for instead of current head. [PR]
  • Redact beacon node endpoints in validator client health check and event stream logs. [PR]
  • Fix p2p_topic_peer_count rendering data column sidecar topics with an unfilled format verb (data_column_sidecar_%!d(MISSING)) instead of the column subnet index. [PR]
  • Fixed a checkpoint-synced beacon node using --enable-state-diff and --beacon-db-pruning failing to restart with state-diff database corrupted. [PR]
  • Weak subjectivity checkpoint verification now requires the root to be in the finalized canonical chain instead of accepting any stored block in the epoch's slot range. [PR]
  • Mark validator, balance and builder state fields dirty even when the enclosing setter returns early with an error. [PR]
  • Validator client (post-Gloas split duties only): fixed a regression where fetching next-epoch duties at the epoch boundary blocked duty performance (attestations/proposals); next-epoch duties are now fetched in the background. [PR]
  • REST VC now falls back to JSON on 415 Unsupported Media Type — the code a beacon node actually returns when it rejects an SSZ request body — instead of on 406 Not Acceptable. [PR]
  • REST VC's SSZ publish requests now send Accept: application/json. Publish endpoints never produce SSZ response bodies, so preferring application/octet-stream was spec-noise that could draw a spurious 406 from servers with naive Accept/q-value parsing. [PR]
  • Derive SECONDS_PER_SLOT from SLOT_DURATION_MS (and vice versa) when a chain config file sets only one of them, and reject a file that sets both to contradictory values. [PR]
  • Recover initial sync when the head is on a bad fork by exploring alternative branches below the network finalized slot and fetching payload envelopes for the recovered branch. [PR]
  • Validator client: keys the beacon node cannot evaluate yet (e.g. deposits pending) no longer block startup or pass unchecked; they are held out of duties and re-checked once per epoch until they can be evaluated (behind --enable-doppelganger). [PR]
  • Validator client: an epoch with no eligible validating keys no longer leaves the duty schedule uninitialized, which previously produced a role-lookup error log every slot. [PR]
  • Validator client (REST): a doppelganger check whose keys are all absent from the beacon state now returns cleanly instead of failing on the liveness request, matching the gRPC path (behind --enable-doppelganger). [PR]
  • Reject gossip blocks whose slot is not higher than their parent's slot. [PR]
  • Gate builder payment weight on the attester having no prior participation flags to prevent double-counting under target equivocation. [PR]
  • Fix the minimal slashing protection database decoding unset builder settings fields as explicit zero values; both validator DB backends now read the same stored settings identically. [PR]
  • Remove the remaining Eth1 bridge deposit transition from Fulu as per consensus-specs#4704. [PR]
  • Use the Gloas attestation deadline (ATTESTATION_DUE_BPS_GLOAS) for fork choice block timeliness after the Gloas fork. [PR]
  • Cold state migration no longer builds a state-diff boundary state from a block that was reorged out. Neither the db nor the epoch boundary state cache drops a block that merely lost fork choice, so a boundary slot whose nearest populated slot held only an orphan, or whose cache entry named a reorged sibling, replayed that orphan into the persisted state. [PR]
  • PTC attestations are now produced during the first two epochs. The shuffling check compared a dependent root that falls back to the origin block root against one that reports the zero root until the first finalization, so it never matched before epoch 2. [PR]
  • Fixed beacon node endpoints such as the default 127.0.0.1:4000 being logged as [invalid endpoint] in validator client failover logs. [PR]
  • Execution payload envelope publishing now selects the beacon node's precomputed data column sidecars by envelope root, and reuses them when the locally built envelope is published with blob data, skipping redundant verification and recomputation. [PR]
  • Validator client now records the proposal log and metrics for an accepted Gloas block even when the follow-up envelope publish fails. [PR]
  • Gossip blocks building on the empty parent are no longer rejected when the parent's revealed payload was invalid, only blocks whose bid builds on the invalid payload are rejected. [PR]
  • Return 404 instead of 500 when a state ID cannot be resolved to a state root on GET /eth/v1/beacon/states/{state_id}/root and POST /prysm/v1/beacon/states/{state_id}/query (e.g. no block at the requested slot, slot in the future, missing genesis/finalized/justified block). An unparseable state ID on those endpoints now returns 400 instead of 500. [PR]
  • Return 404 instead of 500 on every state-fetching endpoint when the requested slot is in the future. [PR]
  • Include the underlying reason in the State not found error message so callers can tell a skipped slot from a pruned one. [PR]
  • Bounded the payload envelope wait on missing data columns in the by-root recovery and pending envelope paths, and fetch missing columns before requesting the envelope. [PR]
  • fix sync committee duties for validators that exit during an active sync committee period. [PR]
  • Report the correct finalized flag on the state-based beacon API endpoints (/eth/v1/beacon/states/{state_id}/root, /fork, /randao, /committees, /sync_committees, /finality_checkpoints, /validators, /validator_balances, /validator_identities, /pending_consolidations, /pending_deposits, /pending_partial_withdrawals, /proposer_lookahead, /eth/v2/debug/beacon/states/{state_id} and /prysm/v1/beacon/states/{state_id}/validator_count). [PR]
  • fixed an oversight where a larger slice is retained in state diff cache than needed. [PR]
  • Advance the cold-state migration cursor even when the epoch boundary cache has no state for the finalized root, so migration keeps progressing on freshly started nodes and during long non-finalization. [PR]
  • Accept skip_randao_verification with an empty value (?skip_randao_verification) in /eth/v3/validator/blocks/{slot} and /eth/v4/validator/blocks/{slot}, as specified by the Beacon API; =true is still accepted. [PR]
  • Verify a bid's gas limit against the payload identified by bid.parent_block_hash instead of the parent block's own payload, so bids that build on the parent's parent payload (empty parent) are no longer rejected with "bid gas limit is incompatible with parent and target". [PR]
  • Persist the execution payload envelope before emitting the execution_payload_available event so that GET /eth/v1/beacon/execution_payload_envelopes/{block_id} no longer returns 404 for consumers reacting to the event; the envelope is removed again if execution validation fails. [PR]
  • Set BUILDER_WITHDRAWAL_PREFIX to 0xB0. [PR]
  • Release the read lock on the no-keys early return in the remote web3signer keymanager's DeletePublicKeys, which previously deadlocked all subsequent key updates. [PR]
  • A JSON null element in a beacon REST list submission (attestations, aggregates, proposer preferences, payload attestations) no longer panics the handler and drops the connection; it is reported as a per-index failure. [PR]
  • POST /eth/v2/beacon/pool/attestations now reports per-index failures against the submitted list instead of a compacted one, so a request mixing bad and good attestations no longer labels every failure index: 0. [PR]
  • Skip the blocking data availability wait when importing a slot whose gossip window has closed, so a node whose head has fallen behind can catch up instead of stalling a full slot duration per block. [PR]
  • Drain pending Gloas data columns before the pending payload envelope in the pending blocks queue, so the envelope's availability check sees the columns already gossiped for that root. [PR]
  • Fix a data race in the REST validator client: the attester and proposer duty fetches for an epoch ran concurrently but assigned the same err variable, so one goroutine could observe the other's error. This could report a proposer failure as an attester failure, or drop an attester error and then panic on the nil response. [PR]
  • Reduced transient memory usage when hdiff saves a beacon state against its anchor. [PR]
  • Builder entries loaded from proposer settings files, URLs, or the validator database are now checked against the spec size and format limits at startup; invalid entries are dropped with a warning instead of failing block production requests. [PR]
  • Serialize local keymanager account store mutations to fix a data race between keystore file reloads and keymanager API imports/deletions. [PR]
  • Initialize the keymanager once per validator runner instead of on every beacon-node connection retry, which leaked a key watcher goroutine (web3signer URL poller or wallet/file watcher) and a duplicate accounts-changed subscription per retry. (fixes #17426). [PR]
  • WaitForActivation no longer recurses on every retry and epoch, which kept its tracing span open and grew the stack for the whole wait. [PR]
  • Extended the REST validator client's payload attestation data read window past the PTC due mark, so the read no longer ends at the instant the beacon node finalizes the data. [PR]
  • --suggested-fee-recipient is now applied as the default fee recipient when --proposer-settings-file/--proposer-settings-url is also set but the settings source has no default_config; previously the flag was silently dropped and validators not listed in the file were registered with the burn address. [PR]
  • Fix GetValidatorQueue sorting the activation and exit queues by queue position instead of validator index, which returned misordered ActivationPublicKeys, ActivationValidatorIndices, ExitPublicKeys and ExitValidatorIndices. [PR]
  • Attach the execution service's RPC client only after chain ID validation succeeds, so a failed reconnection attempt no longer replaces a working client with a closed one or leaks the previous client. [PR]
  • Add missing BeaconStateGloas case to saveStatesEfficientInternal so Gloas states can be saved when --enable-historical-state-representation is enabled. [PR]
  • Validator client now keeps slashing protection records up to date for keys added while it is running, instead of only at startup. [PR]
  • Return the confirmed block's payload hash as the safe execution block hash even when it is zero (pre-merge, genesis in spec tests) instead of falling back to the unrealized justified hash. [PR]
  • Gloas: when no full ancestor is left in forkchoice, resolve the payload a block builds on to the tree root's bid parent_block_hash instead of zero. [PR]
  • Fixed a nil-pointer panic in the backfill worker pool when retrying a batch whose blob/column sync construction failed after block verification (e.g. a CustodyGroupCount error in newColumnSync). [PR]
  • Encode the SSZ response of GET /eth/v1/debug/beacon/data_column_sidecars/{block_id} as an SSZ list of variable-size elements (4-byte offsets followed by the elements) instead of plain concatenation, per beacon-APIs#633. [PR]
  • Regenerate attestation pre-states one at a time so competing targets no longer load full states concurrently. [PR]
  • Keep Gloas builder API connections warm between proposals so bid requests reuse an established TLS session. [PR]
  • Fork-choice spectests decode attester_slashing steps as AttesterSlashingElectra from Electra on, and the spectest chain service is given the slashing, voluntary exit and BLS-to-execution pools that blocks prune after a slashing is inserted. [PR]
  • Make initial-sync retry and peer polling waits cancellable so shutdown does not wait for the polling interval. [PR]
  • Cache certain pending deposit signatures pre Gloas fork. [PR]
  • Remove the quadratic is_pending_validator rescan from the Gloas fork upgrade. [PR]
  • Stop rescanning the builder registry from index 0 on every insert during the Gloas fork upgrade. [PR]
  • Fixed a nil-pointer panic in backfill's batch.columnsNeeded for batches with no column work (all blocks pre-Fulu or outside the column retention window): the wrapper called the promoted (*columnBatch).needed on the nil embedded columnBatch instead of the guarded (*columnSync).columnsNeeded. [PR]
  • Pack Electra attestations by marginal proposer reward. The proposer used to score each candidate on-chain aggregate against the pre-block state in isolation and then take the best MAX_ATTESTATIONS_ELECTRA, which filled blocks with aggregates whose votes were already counted by an earlier attestation in the same block, or by an already-imported block. Candidates are now picked by what they add on top of the ones already picked, and packing stops once nothing left adds a vote. [PR]
  • Serialize the builder version field as a decimal string in beacon API responses, matching the spec's Uint8 type, instead of a hex string. [PR]
  • Accept beacon API POST requests with an empty body and no Content-Type header instead of rejecting them with 415 Unsupported Media Type, so endpoints with an optional request body work with e.g. curl -X POST. [PR]
  • Derive the justified and finalized checkpoint epoch persisted by SaveOrigin from the origin state slot instead of the origin block slot, so checkpoint sync records the correct epoch when the checkpoint epoch's first slot is empty. [PR]
  • PTC members now request the payload attestation data again at the payload attestation deadline when the first request comes back before it. [PR]
  • Cancel background sidecar parent-block and payload-envelope requests when the sync service stops, and stop retrying canceled requests. [PR]
  • Apply the response timeout to the complete parent-block and payload-envelope response reads for each attempt, preserving retries when an individual request times out. [PR]
  • Fork choice: skip equivocating (slashed) validators when crediting parked payload-present votes to a newly inserted Gloas full payload node. [PR]
  • Cancel gossip publishing promptly while waiting for topic peers. [PR]
  • Builder client errors for an unexpected HTTP status now report the received and expected statuses instead of claiming a 200 was not received. [PR]
  • Keep the last known good peer chain state when a status message fails validation. [PR]
  • Serve available Gloas payload envelopes by root even when they predate the serving node's finalized epoch. [PR]
  • Report the beacon node's own error instead of context deadline exceeded when a retrying REST request runs out of time. Callers can now tell an expected response such as 204 No Content from a real failure, rather than logging both as errors. [PR]
  • Fixed clientstats metrics scraping compatibility with newer Prometheus dependencies. [PR]
  • Fix Gloas checkpoint sync stalling and repeatedly downscoring peers when the checkpoint origin's payload is withheld. Preserve the origin's data columns when its payload is revealed so forward sync can process it. [PR]
  • Validate execution payload envelopes against the latest block header slot so a checkpoint state advanced through empty slots accepts its origin envelope. [PR]
  • Report which execution block is missing instead of missing required field 'parentHash' when the execution client returns null during Gloas payload reconstruction. [PR]
  • Cap queued self-built execution payload envelopes at one per valid proposer per slot. [PR]

Don't miss a new prysm release

NewReleases is sending notifications on new releases.