Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 3 additions & 6 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -3,18 +3,18 @@ module github.com/ethpandaops/buildoor
go 1.25.7

require (
github.com/attestantio/go-builder-client v0.0.0-00010101000000-000000000000
github.com/attestantio/go-eth2-client v0.27.1
github.com/ethereum/go-ethereum v1.17.3
github.com/ethpandaops/go-eth2-client v0.1.3
github.com/ethpandaops/service-authenticatoor v0.0.1
github.com/glebarez/go-sqlite v1.22.0
github.com/goccy/go-yaml v1.19.2
github.com/golang-jwt/jwt/v5 v5.3.1
github.com/gorilla/mux v1.8.1
github.com/herumi/bls-eth-go-binary v1.37.0
github.com/holiman/uint256 v1.3.2
github.com/jmoiron/sqlx v1.4.0
github.com/pk910/dynamic-ssz v1.3.2-0.20260505131440-111bcb265c8f
github.com/pkg/errors v0.9.1
github.com/pressly/goose/v3 v3.27.1
github.com/prometheus/client_golang v1.23.2
github.com/rs/zerolog v1.35.1
Expand Down Expand Up @@ -60,7 +60,6 @@ require (
github.com/go-openapi/spec v0.21.0 // indirect
github.com/go-openapi/swag v0.23.0 // indirect
github.com/go-viper/mapstructure/v2 v2.4.0 // indirect
github.com/goccy/go-yaml v1.19.2 // indirect
github.com/gofrs/flock v0.12.1 // indirect
github.com/golang/snappy v1.0.0 // indirect
github.com/google/uuid v1.6.0 // indirect
Expand All @@ -83,12 +82,10 @@ require (
github.com/pion/transport/v2 v2.2.10 // indirect
github.com/pion/transport/v3 v3.0.7 // indirect
github.com/pk910/hashtree-bindings v0.1.0 // indirect
github.com/pkg/errors v0.9.1 // indirect
github.com/pmezard/go-difflib v1.0.0 // indirect
github.com/prometheus/client_model v0.6.2 // indirect
github.com/prometheus/common v0.66.1 // indirect
github.com/prometheus/procfs v0.20.1 // indirect
github.com/prysmaticlabs/go-bitfield v0.0.0-20240618144021-706c95b2dd15 // indirect
github.com/r3labs/sse/v2 v2.10.0 // indirect
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
github.com/sagikazarmark/locafero v0.11.0 // indirect
Expand Down Expand Up @@ -126,4 +123,4 @@ require (
modernc.org/sqlite v1.49.1 // indirect
)

replace github.com/attestantio/go-builder-client => github.com/bharath-123/go-builder-client v0.0.0-20260614061206-3d327877ba19
tool github.com/pk910/dynamic-ssz/dynssz-gen
6 changes: 0 additions & 6 deletions go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -19,12 +19,8 @@ github.com/StackExchange/wmi v1.2.1 h1:VIkavFPXSjcnS+O8yTq7NI32k0R5Aj+v39y29VYDO
github.com/StackExchange/wmi v1.2.1/go.mod h1:rcmrprowKIVzvc+NUiLncP2uuArMWLCbu9SBzvHz7e8=
github.com/VictoriaMetrics/fastcache v1.13.0 h1:AW4mheMR5Vd9FkAPUv+NH6Nhw+fmbTMGMsNAoA/+4G0=
github.com/VictoriaMetrics/fastcache v1.13.0/go.mod h1:hHXhl4DA2fTL2HTZDJFXWgW0LNjo6B+4aj2Wmng3TjU=
github.com/attestantio/go-eth2-client v0.27.1 h1:g7bm+gG/p+gfzYdEuxuAepVWYb8EO+2KojV5/Lo2BxM=
github.com/attestantio/go-eth2-client v0.27.1/go.mod h1:fvULSL9WtNskkOB4i+Yyr6BKpNHXvmpGZj9969fCrfY=
github.com/beorn7/perks v1.0.1 h1:VlbKKnNfV8bJzeqoa4cOKqO6bYr3WgKZxO8Z16+hsOM=
github.com/beorn7/perks v1.0.1/go.mod h1:G2ZrVWU2WbWT9wwq4/hrbKbnv/1ERSJQ0ibhJ6rlkpw=
github.com/bharath-123/go-builder-client v0.0.0-20260614061206-3d327877ba19 h1:nlEc90bi1ObfWrGS+3xvFxu44Gxv/gQZIolzdydkfMY=
github.com/bharath-123/go-builder-client v0.0.0-20260614061206-3d327877ba19/go.mod h1:DUKOrPS+kfquqoUh5rbCoZempShC4NiSxKv2VrTlbZs=
github.com/bits-and-blooms/bitset v1.20.0 h1:2F+rfL86jE2d/bmw7OhqUg2Sj/1rURkBn3MdfoPyRVU=
github.com/bits-and-blooms/bitset v1.20.0/go.mod h1:7hO7Gc7Pp1vODcmWvKMRA9BNmbv6a/7QIWpPxHddWR8=
github.com/casbin/govaluate v1.10.0 h1:ffGw51/hYH3w3rZcxO/KcaUIDOLP84w7nsidMVgaDG0=
Expand Down Expand Up @@ -227,8 +223,6 @@ github.com/prometheus/common v0.66.1 h1:h5E0h5/Y8niHc5DlaLlWLArTQI7tMrsfQjHV+d9Z
github.com/prometheus/common v0.66.1/go.mod h1:gcaUsgf3KfRSwHY4dIMXLPV0K/Wg1oZ8+SbZk/HH/dA=
github.com/prometheus/procfs v0.20.1 h1:XwbrGOIplXW/AU3YhIhLODXMJYyC1isLFfYCsTEycfc=
github.com/prometheus/procfs v0.20.1/go.mod h1:o9EMBZGRyvDrSPH1RqdxhojkuXstoe4UlK79eF5TGGo=
github.com/prysmaticlabs/go-bitfield v0.0.0-20240618144021-706c95b2dd15 h1:lC8kiphgdOBTcbTvo8MwkvpKjO0SlAgjv4xIK5FGJ94=
github.com/prysmaticlabs/go-bitfield v0.0.0-20240618144021-706c95b2dd15/go.mod h1:8svFBIKKu31YriBG/pNizo9N0Jr9i5PQ+dFkxWg3x5k=
github.com/prysmaticlabs/gohashtree v0.0.4-beta h1:H/EbCuXPeTV3lpKeXGPpEV9gsUpkqOOVnWapUyeWro4=
github.com/prysmaticlabs/gohashtree v0.0.4-beta/go.mod h1:BFdtALS+Ffhg3lGQIHv9HDWuHS8cTvHZzrHWxwOtGOs=
github.com/r3labs/sse/v2 v2.10.0 h1:hFEkLLFY4LDifoHdiCN/LlGBAdVJYsANaLqNYa1l/v0=
Expand Down
22 changes: 8 additions & 14 deletions pkg/builderapi/builder_preferences_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -8,19 +8,13 @@ import (
"net/http/httptest"
"testing"

buildergloas "github.com/attestantio/go-builder-client/api/gloas"
// attphase0 is the attestantio phase0 used by go-builder-client's builder-API
// types. Buildoor uses ethpandaops/go-eth2-client everywhere; this import exists
// ONLY so tests can populate buildergloas struct fields (Slot/Gwei/Signature),
// which are attestantio-typed. Production code converts at the boundary and never
// imports attestantio. Prefer ethpandaops/go-eth2-client outside of this.
attphase0 "github.com/attestantio/go-eth2-client/spec/phase0"
"github.com/ethpandaops/go-eth2-client/spec/phase0"
"github.com/sirupsen/logrus"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"

gloasauth "github.com/ethpandaops/buildoor/pkg/builderapi/gloas"
gloastypes "github.com/ethpandaops/buildoor/pkg/builderapi/gloas/types"
"github.com/ethpandaops/buildoor/pkg/config"
"github.com/ethpandaops/buildoor/pkg/signer"
)
Expand All @@ -44,9 +38,9 @@ func signBuilderPrefsRequest(
) []byte {
t.Helper()

auth := &buildergloas.RequestAuthV1{
auth := &gloastypes.RequestAuthV1{
Data: []byte(builderURL),
Slot: attphase0.Slot(slot),
Slot: slot,
}
root, err := auth.HashTreeRoot()
require.NoError(t, err)
Expand All @@ -55,11 +49,11 @@ func signBuilderPrefsRequest(
sig, err := s.SignWithDomain(phase0.Root(root), domain)
require.NoError(t, err)

req := &buildergloas.BuilderPreferencesRequestV1{
Preferences: &buildergloas.BuilderPreferencesV1{MaxExecutionPayment: attphase0.Gwei(maxPayment)},
Auth: &buildergloas.SignedRequestAuthV1{
req := &gloastypes.BuilderPreferencesRequestV1{
Preferences: &gloastypes.BuilderPreferencesV1{MaxExecutionPayment: maxPayment},
Auth: &gloastypes.SignedRequestAuthV1{
Message: auth,
Signature: attphase0.BLSSignature(sig),
Signature: sig,
},
}
body, err := json.Marshal(req)
Expand Down Expand Up @@ -140,7 +134,7 @@ func TestSubmitBuilderPreferences_SuccessSSZ(t *testing.T) {

// Build the same signed request as the JSON path, but submit it SSZ-encoded.
jsonBody := signBuilderPrefsRequest(t, blsSigner, testBuilderURL, 100, 5_000_000_000, gfv)
var prefsReq buildergloas.BuilderPreferencesRequestV1
var prefsReq gloastypes.BuilderPreferencesRequestV1
require.NoError(t, json.Unmarshal(jsonBody, &prefsReq))
sszBody, err := prefsReq.MarshalSSZ()
require.NoError(t, err)
Expand Down
10 changes: 5 additions & 5 deletions pkg/builderapi/encoding.go
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ import (
"fmt"
"strings"

buildergloas "github.com/attestantio/go-builder-client/api/gloas"
gloastypes "github.com/ethpandaops/buildoor/pkg/builderapi/gloas/types"
)

// Wire formats accepted on Gloas builder-API request bodies. The builder-spec
Expand All @@ -33,8 +33,8 @@ func normalizeContentType(ct string) string {
// by contentType. The Content-Type must be set explicitly to one of the two
// supported media types; an empty or unrecognized type returns
// errUnsupportedContentType (which handlers map to 415).
func parseSignedRequestAuth(data []byte, contentType string) (*buildergloas.SignedRequestAuthV1, error) {
var v buildergloas.SignedRequestAuthV1
func parseSignedRequestAuth(data []byte, contentType string) (*gloastypes.SignedRequestAuthV1, error) {
var v gloastypes.SignedRequestAuthV1
switch normalizeContentType(contentType) {
case contentTypeSSZ:
if err := v.UnmarshalSSZ(data); err != nil {
Expand All @@ -53,8 +53,8 @@ func parseSignedRequestAuth(data []byte, contentType string) (*buildergloas.Sign
// parseBuilderPreferencesRequest decodes a BuilderPreferencesRequestV1 from JSON
// or SSZ selected by contentType, following the same rules as
// parseSignedRequestAuth.
func parseBuilderPreferencesRequest(data []byte, contentType string) (*buildergloas.BuilderPreferencesRequestV1, error) {
var v buildergloas.BuilderPreferencesRequestV1
func parseBuilderPreferencesRequest(data []byte, contentType string) (*gloastypes.BuilderPreferencesRequestV1, error) {
var v gloastypes.BuilderPreferencesRequestV1
switch normalizeContentType(contentType) {
case contentTypeSSZ:
if err := v.UnmarshalSSZ(data); err != nil {
Expand Down
21 changes: 10 additions & 11 deletions pkg/builderapi/encoding_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -4,19 +4,18 @@ import (
"encoding/json"
"testing"

buildergloas "github.com/attestantio/go-builder-client/api/gloas"
// attphase0 is the attestantio phase0 used by go-builder-client's builder-API
// types; imported here ONLY to populate buildergloas struct fields in tests.
attphase0 "github.com/attestantio/go-eth2-client/spec/phase0"
"github.com/ethpandaops/go-eth2-client/spec/phase0"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"

gloastypes "github.com/ethpandaops/buildoor/pkg/builderapi/gloas/types"
)

func sampleSignedRequestAuth() *buildergloas.SignedRequestAuthV1 {
var sig attphase0.BLSSignature
func sampleSignedRequestAuth() *gloastypes.SignedRequestAuthV1 {
var sig phase0.BLSSignature
sig[0] = 0xaa
return &buildergloas.SignedRequestAuthV1{
Message: &buildergloas.RequestAuthV1{Data: []byte("https://builder.example.com"), Slot: 42},
return &gloastypes.SignedRequestAuthV1{
Message: &gloastypes.RequestAuthV1{Data: []byte("https://builder.example.com"), Slot: 42},
Signature: sig,
}
}
Expand All @@ -38,7 +37,7 @@ func TestParseSignedRequestAuth_JSONAndSSZRoundTrip(t *testing.T) {
fromJSONParam, err := parseSignedRequestAuth(jsonBody, "application/json; charset=utf-8")
require.NoError(t, err)

for _, got := range []*buildergloas.SignedRequestAuthV1{fromJSON, fromSSZ, fromJSONParam} {
for _, got := range []*gloastypes.SignedRequestAuthV1{fromJSON, fromSSZ, fromJSONParam} {
require.NotNil(t, got.Message)
assert.Equal(t, orig.Message.Slot, got.Message.Slot)
assert.Equal(t, orig.Message.Data, got.Message.Data)
Expand Down Expand Up @@ -66,8 +65,8 @@ func TestParseSignedRequestAuth_Errors(t *testing.T) {
}

func TestParseBuilderPreferencesRequest_SSZRoundTrip(t *testing.T) {
orig := &buildergloas.BuilderPreferencesRequestV1{
Preferences: &buildergloas.BuilderPreferencesV1{MaxExecutionPayment: 5_000_000_000},
orig := &gloastypes.BuilderPreferencesRequestV1{
Preferences: &gloastypes.BuilderPreferencesV1{MaxExecutionPayment: 5_000_000_000},
Auth: sampleSignedRequestAuth(),
}

Expand Down
4 changes: 2 additions & 2 deletions pkg/builderapi/gloas/auth.go
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,9 @@ import (
"errors"
"fmt"

buildergloas "github.com/attestantio/go-builder-client/api/gloas"
"github.com/ethpandaops/go-eth2-client/spec/phase0"

gloastypes "github.com/ethpandaops/buildoor/pkg/builderapi/gloas/types"
"github.com/ethpandaops/buildoor/pkg/signer"
)

Expand Down Expand Up @@ -36,7 +36,7 @@ var (
//
// Returns nil on success, or one of the package's sentinel errors on failure.
func VerifyRequestAuth(
signed *buildergloas.SignedRequestAuthV1,
signed *gloastypes.SignedRequestAuthV1,
validatorPubkey phase0.BLSPubKey,
genesisForkVersion phase0.Version,
) error {
Expand Down
36 changes: 15 additions & 21 deletions pkg/builderapi/gloas/auth_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -4,17 +4,11 @@ import (
"strings"
"testing"

buildergloas "github.com/attestantio/go-builder-client/api/gloas"
// attphase0 is the attestantio phase0 used by go-builder-client's builder-API
// types. Buildoor uses ethpandaops/go-eth2-client everywhere; this import exists
// ONLY so tests can populate buildergloas struct fields (Slot/Signature), which
// are attestantio-typed. Production code converts at the boundary and never
// imports attestantio. Prefer ethpandaops/go-eth2-client outside of this.
attphase0 "github.com/attestantio/go-eth2-client/spec/phase0"
"github.com/ethpandaops/go-eth2-client/spec/phase0"
"github.com/stretchr/testify/require"

"github.com/ethpandaops/buildoor/pkg/builderapi/gloas"
gloastypes "github.com/ethpandaops/buildoor/pkg/builderapi/gloas/types"
"github.com/ethpandaops/buildoor/pkg/signer"
)

Expand All @@ -34,12 +28,12 @@ func signRequestAuth(
builderURL []byte,
slot phase0.Slot,
genesisForkVersion phase0.Version,
) *buildergloas.SignedRequestAuthV1 {
) *gloastypes.SignedRequestAuthV1 {
t.Helper()

msg := &buildergloas.RequestAuthV1{
msg := &gloastypes.RequestAuthV1{
Data: builderURL,
Slot: attphase0.Slot(slot),
Slot: slot,
}

root, err := msg.HashTreeRoot()
Expand All @@ -50,9 +44,9 @@ func signRequestAuth(
sig, err := s.SignWithDomain(root, domain)
require.NoError(t, err)

return &buildergloas.SignedRequestAuthV1{
return &gloastypes.SignedRequestAuthV1{
Message: msg,
Signature: attphase0.BLSSignature(sig),
Signature: sig,
}
}

Expand All @@ -67,7 +61,7 @@ func TestRequestAuth_SSZRoundTripAndSign(t *testing.T) {

genesisForkVersion := phase0.Version{}

msg := &buildergloas.RequestAuthV1{
msg := &gloastypes.RequestAuthV1{
Data: []byte(testBuilderURL),
Slot: 1234,
}
Expand All @@ -78,7 +72,7 @@ func TestRequestAuth_SSZRoundTripAndSign(t *testing.T) {
require.NotEmpty(t, encoded)

// Unmarshal from SSZ into a fresh value.
decoded := &buildergloas.RequestAuthV1{}
decoded := &gloastypes.RequestAuthV1{}
require.NoError(t, decoded.UnmarshalSSZ(encoded))

// The decoded value must match the original.
Expand All @@ -97,9 +91,9 @@ func TestRequestAuth_SSZRoundTripAndSign(t *testing.T) {
sig, err := validator.SignWithDomain(decodedRoot, domain)
require.NoError(t, err)

signed := &buildergloas.SignedRequestAuthV1{
signed := &gloastypes.SignedRequestAuthV1{
Message: decoded,
Signature: attphase0.BLSSignature(sig),
Signature: sig,
}
require.NoError(t, gloas.VerifyRequestAuth(signed, validator.PublicKey(), genesisForkVersion))
}
Expand Down Expand Up @@ -181,9 +175,9 @@ func TestVerifyRequestAuth_NilMessage(t *testing.T) {
validator, err := signer.NewBLSSigner(validatorPrivkeyHex)
require.NoError(t, err)

signed := &buildergloas.SignedRequestAuthV1{
signed := &gloastypes.SignedRequestAuthV1{
Message: nil,
Signature: attphase0.BLSSignature{},
Signature: phase0.BLSSignature{},
}

err = gloas.VerifyRequestAuth(signed, validator.PublicKey(), phase0.Version{})
Expand All @@ -194,13 +188,13 @@ func TestVerifyRequestAuth_GarbageSignature(t *testing.T) {
validator, err := signer.NewBLSSigner(validatorPrivkeyHex)
require.NoError(t, err)

signed := &buildergloas.SignedRequestAuthV1{
Message: &buildergloas.RequestAuthV1{
signed := &gloastypes.SignedRequestAuthV1{
Message: &gloastypes.RequestAuthV1{
Data: []byte(testBuilderURL),
Slot: 1,
},
// All-zero signature is not a valid BLS signature.
Signature: attphase0.BLSSignature{},
Signature: phase0.BLSSignature{},
}

err = gloas.VerifyRequestAuth(signed, validator.PublicKey(), phase0.Version{})
Expand Down
39 changes: 39 additions & 0 deletions pkg/builderapi/gloas/types/builderpreferencesrequestv1.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
// Copyright © 2026 Attestant Limited.
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.

package types

import (
"fmt"

"github.com/goccy/go-yaml"
)

// BuilderPreferencesRequestV1 is the body submitted to a builder via the
// submitBuilderPreferences API. The Auth.Message.Data identifies the
// intended builder so the builder can reject preferences that were not
// destined for it.
type BuilderPreferencesRequestV1 struct {
Preferences *BuilderPreferencesV1
Auth *SignedRequestAuthV1
}

// String returns a string version of the structure.
func (b *BuilderPreferencesRequestV1) String() string {
data, err := yaml.Marshal(b)
if err != nil {
return fmt.Sprintf("ERR: %v", err)
}

return string(data)
}
Loading