Derive default auth data from the builder hostname - #168
Merged
Merged
Conversation
nflaig
marked this pull request as ready for review
September 16, 2026 20:20
JasonVranek
reviewed
Sep 17, 2026
0w3n-d
approved these changes
Sep 17, 2026
0w3n-d
left a comment
There was a problem hiding this comment.
Looks good to me. I'm a fan of defaults like this.
JasonVranek
approved these changes
Sep 17, 2026
syjn99
approved these changes
Sep 18, 2026
4 tasks
StefanBratanov
approved these changes
Sep 18, 2026
mergify Bot
pushed a commit
to sigp/lighthouse
that referenced
this pull request
Sep 18, 2026
## Description Adds the per-validator builder configuration endpoints from [ethereum/keymanager-APIs#88](ethereum/keymanager-APIs#88). - `GET /eth/v1/validator/{pubkey}/builder_config` returns the configuration in use for the validator. - `POST /eth/v1/validator/{pubkey}/builder_config` replaces and persists the full configuration on a per-validator basis. It does not merge with the previous entry. - `DELETE /eth/v1/validator/{pubkey}/builder_config` removes the stored entry, so the validator inherits the global configuration again. The API stores per-validator entries under `validator_configs` in `builder_definitions.yml`. Changes made by `POST` and `DELETE` apply to subsequent builder preference publication and Gloas block production without a restart. When `auth_data` is omitted, global and per-validator builder configurations use the builder URL's lowercase ASCII hostname, following [ethereum/builder-specs#168](ethereum/builder-specs#168), [ethereum/beacon-APIs#642](ethereum/beacon-APIs#642) and [ethereum/keymanager-APIs#94](ethereum/keymanager-APIs#94). URLs with and without a trailing slash produce the same auth data. Closes #9796 Closes #10076 Co-authored-by: Mark Mackey <mark@sigmaprime.io>
ckoopmann
approved these changes
Sep 18, 2026
ckoopmann
left a comment
There was a problem hiding this comment.
Yes this would work for the ultrasound relay as well.
nflaig
added a commit
to ChainSafe/lodestar
that referenced
this pull request
Sep 18, 2026
Follows ethereum/builder-specs#168, an omitted `auth_data` of a builder entry is now the hostname of its url instead of the url bytes verbatim, so a trailing slash, an explicit default port or different casing no longer changes the signed bytes. buildoor still compares the url verbatim, so the builder-dev kurtosis setup fails auth until it follows the spec change.
Open
2 tasks
SamAg19
pushed a commit
to SamAg19/lighthouse
that referenced
this pull request
Sep 18, 2026
## Description Adds the per-validator builder configuration endpoints from [ethereum/keymanager-APIs#88](ethereum/keymanager-APIs#88). - `GET /eth/v1/validator/{pubkey}/builder_config` returns the configuration in use for the validator. - `POST /eth/v1/validator/{pubkey}/builder_config` replaces and persists the full configuration on a per-validator basis. It does not merge with the previous entry. - `DELETE /eth/v1/validator/{pubkey}/builder_config` removes the stored entry, so the validator inherits the global configuration again. The API stores per-validator entries under `validator_configs` in `builder_definitions.yml`. Changes made by `POST` and `DELETE` apply to subsequent builder preference publication and Gloas block production without a restart. When `auth_data` is omitted, global and per-validator builder configurations use the builder URL's lowercase ASCII hostname, following [ethereum/builder-specs#168](ethereum/builder-specs#168), [ethereum/beacon-APIs#642](ethereum/beacon-APIs#642) and [ethereum/keymanager-APIs#94](ethereum/keymanager-APIs#94). URLs with and without a trailing slash produce the same auth data. Closes sigp#9796 Closes sigp#10076 Co-authored-by: Mark Mackey <mark@sigmaprime.io>
nflaig
added a commit
to ethereum/keymanager-APIs
that referenced
this pull request
Sep 18, 2026
Aligns the `auth_data` default with ethereum/builder-specs#168, the builder's hostname instead of the URL bytes verbatim, and updates the examples accordingly.
nflaig
added a commit
to ethereum/beacon-APIs
that referenced
this pull request
Sep 18, 2026
Aligns the `data` default with ethereum/builder-specs#168, the builder's hostname instead of the URL bytes verbatim.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The default
datais the UTF-8 bytes of the builder URL exactly as advertised, so a trailing/, an explicit:443or different casing on the proposer side fails the builder's check.Use the builder's hostname instead: lowercased, without scheme, userinfo, port or path. It is a pure function of the configured URL, so all validator clients derive the same bytes, and it is only applied when constructing the
BuilderRequestAuth, the signed bytes are still verified unchanged.Builders that need a finer identity than their hostname can still agree
dataout of band. Theauth_datadescriptions in keymanager-APIs and beacon-APIs are updated in ethereum/keymanager-APIs#94 and ethereum/beacon-APIs#642.