Repository navigation
feat(beacon): score gossipsub peers with lighthouse's parameters - #656
Draft
MegaRedHand wants to merge 3 commits into
Draft
MegaRedHand wants to merge 3 commits into
MegaRedHand wants to merge 3 commits into
Conversation
The beacon wire had no way to push out peers that send invalid messages, break IWANT promises or cannot keep up: gossipsub kept exchanging with all of them, and the connection cap was the only bound on bad peers. The parameters are lighthouse's, ported formula for formula. Teku, Lodestar and Grandine run the same ones, so a score means here what it means on most of mainnet. Two deviations: - Mesh-delivery scoring (P3) is off while the head lags the wall clock by more than four slots, and back on only after an epoch within that. Lighthouse joins these topics only once synced. This node subscribes at startup and, while catching up, ignores every aggregate voting for a block it has not imported; a mesh peer credited with no aggregates scores below the graylist, so a restart would graylist the whole aggregate mesh for our own lag. SyncStatus cannot be the gate: its network-stall rule reported synced through a 98-slot catch-up on the mainnet follower. - Peers below the graylist are disconnected every 10 s. Gossipsub alone only ignores them, and they keep a connection slot. Columns, sync committee contributions and BLS changes stay unscored. This node ignores every contribution and change for lack of a consumer, so P3 there would penalize the mesh for a gap that is ours.
MegaRedHand
added a commit
that referenced
this pull request
Oct 2, 2026
…-636-638-gloas-live The scoring refresh names the dynamic topics for the digest current at each slot, so on this branch's runtime fork schedule they follow a switch within a slot; the docs say what does not follow (exit and slashing parameters, old-digest weights).
4 tasks
MegaRedHand
added a commit
that referenced
this pull request
Oct 5, 2026
…36-638-gloas-live Brings gloas validator duties (produceBlockV4, envelope publication, PTC duties and payload attestations, gloas attestation data and aggregates, VC gloas support) onto the deployment branch, keeping every behavior of #626, #633, #636, #638, #646, #647-#652, #656, #658-#660 and the sync-committee and liveness endpoints. Conflict resolutions keep both sides: the attestation pool stays in Store (tmp) while the payload attestation pool is threaded through P2P and the RPC handles (feature); the aggregate endpoints keep tmp's liveness recording and attesting indices and add the feature's fork-header check and gloas pooling; the VC tests and fake execution client serve both fulu blobs and gloas V6. Semantic fixes: a. POST /eth/v2/beacon/blocks (gloas) calls publish_beacon_block(block, Vec::new()): gloas columns travel with the envelope. RecordingNetwork implements publish_beacon_block(block, sidecars) and both new methods. b. produceBlockV4 appends client versions to the graffiti exactly like produceBlockV3 (graffiti::execution_client_version run alongside the payload build, with_client_versions, Extension<OwnVersion>) and logs it. c. Attestation data, aggregate_attestation keep require_execution_client and require_validated for gloas slots; payload_attestation_data now applies the same two rules (503 without an execution client, or when the voted block's payload is unvalidated). d. Proposer duties v1 and v2 serve gloas epochs from a fulu or gloas state's proposer_lookahead; nothing refuses gloas any more; v2 keeps its dependent root. e. The VC's per-validator ProposerSettings apply to gloas proposals (graffiti in the BlockRequest, fee recipient compared with the bid's); a test pins the graffiti. VC tests updated to the ProposerSettings constructors. f. gloas production reads the attestation pool from Store and calls the stf with the ActiveBalanceCache the perf work added; fulu production and pack_operations are untouched (gloas blocks carry no pooled operations). g. Chain events are emitted by the chain actor only, so nothing on the RPC publish paths needed to move; gloas imports reach it unchanged. h. Cargo.lock unchanged; cargo check --locked passes.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
The beacon wire had no gossipsub peer scoring (
// TODO: set peer scoring params). Gossipsub kept exchanging with every peer, including ones that send invalid messages, break IWANT promises or cannot keep up, and the connection cap was the only bound on bad peers.Slow peers are the visible case on the followers. The mainnet follower logged 96k gossipsub
Send Queue fullwarnings in 22 h, from only 8 peers (one of them 60k). The Hoodi follower currently logs about 5000 a minute, almost all from 2 peers. Without scoring, nothing penalizes or drops those peers.Changes
p2p/src/beacon/scoring.rs(new)gossipsub_scoring_parameters.rs, ported formula for formula: thresholds, peer score parameters, and per-topic parameters forbeacon_block,beacon_aggregate_and_proof, all 64beacon_attestation_{n}subnets, exits and slashings.MeshDeliveryGate(the P3 sync gate below). Unit tests for the derived parameters against lighthouse's values.p2p/src/lib.rsRefreshPeerScoring, first run at startup) from the head's current-epoch shuffling and sends them to the swarm.p2p/src/swarm_adapter.rsSwarmCommand::SetTopicScoreParams. On the existing 10 s tick, peers below the graylist are disconnected and peers are counted by score band.storage/src/committee_cache.rs,types/beacon/committees.rsCommitteeCache::head_current_committeesreads the pinned head's current-epoch shuffling (never builds one), andEpochCommittees::active_validator_counttakes the count from its length, so the refresh needs no registry scan.lean_gossipsub_peers_by_score{band},lean_gossipsub_score_disconnects_total,lean_gossipsub_mesh_delivery_scoring.beacon_wire.md"Peer scoring" section;metrics.md.Design decisions
mesh_nis ours (8), not lighthouse's 5. It only enters the first-message-delivery cap.SyncStatus. On the mainnet followerSyncStatusreportedsyncedthrough a 10-minute catch-up up to 98 slots behind: its network-stall rule reads a lagging freshest-imported block as a stalled network.retain_score(100 epochs) after it leaves, so one that reconnects comes back graylisted and is dropped again on the next pass.Ignores every contribution and change (no consumer), and a delivery is only credited once accepted, so P3 there would penalize the mesh for a gap that is ours. Only Prysm scores columns.Not in this PR
remove_topic_weight_except).SyncStatusduring beacon catch-up.Testing
Run on the branch after merging
beacon-chain-integration(125dce1).cargo clippy --workspace --all-targets --profile release-fast -- -D warningscargo fmt --all --checkcargo test --profile release-fast -p ethlambda-p2p --libcargo test --profile release-fast -p ethlambda-storage --libThe beacon spec suites were not run: the only state-transition change makes
committee_count_per_slotpublic, and fork choice is untouched.