Retrospective LLM-Based Complexity Evaluations

EIP complexity assessment

EIP-2935: Serve historical block hashes from state

Assessed in Prague / Pectra. The score describes the EIP text available at the assessment cutoff, not the EIP as it stands today.

RetrospectivePrague / PectraAssessment cutoff 2024-04-11Included by cutoffLayers: execution
LLM Completescore 21
Human Not available· Human complexity assessments were not produced for this fork; only the LLM assessment exists.

LLM assessment

Evaluated on: · Spec revision: 2022-05-06 · 9e393a79d9

Scope at the cutoff. This early, Stagnant revision of EIP-2935 makes the protocol store each parent block hash in storage at `HISTORY_STORAGE_ADDRESS` (0xff…fe). Before any transactions run in every block after `FORK_BLKNUM`, the protocol performs `sstore(HISTORY_STORAGE_ADDRESS, block.number - 1, block.prevhash)`. Once `block.number > FORK_BLKNUM + 256`, `BLOCKHASH` changes: it returns that stored value for any `arg` with `FORK_BLKNUM <= arg < block.number`, and 0 otherwise. This extends `BLOCKHASH` past the 256-block window. The revision specifies no contract code, gas changes, account-creation rules, access-list behaviour or test cases.

21MediumMedium
Evaluator
LLMChecklist v3
Confidence
Medium
Under-specified at assessment cutoff
Yes — 8 criteria affected
Plausible range
14–28 (Medium–High)
Assessment cutoff
2024-04-11 · EIP revision 9e393a79d9 (2022-05-06)
Score bands · Checklist revision 3
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the LLM total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. Modified opcodes3
  2. Edge/boundary conditions3
  3. Added system contracts2
  4. New invariant on pre-existing tests2

Under-specified at assessment cutoff: Yes

The EIP text available at the assessment cutoff left material behavior unresolved. The affected criteria and the plausible total range record that uncertainty.

Why: This revision is a short Stagnant draft. It leaves out gas for the new BLOCKHASH read and the system write, access-list effects, how the history account is created or what its status is (nonce/code), how block-number activation fits timestamp-based forks, and any test cases.

Unresolved questions at the cutoff (5)
  • Is HISTORY_STORAGE_ADDRESS created with a nonce or code? If not, is it an 'empty' account that can be deleted when touched, wiping the stored history?
  • Does BLOCKHASH's sload add the address or slot to the accessed sets, and does it change BLOCKHASH's gas cost?
  • Does the block-start sstore consume block gas, and does it touch or warm the account?
  • How does FORK_BLKNUM map onto timestamp-based activation in the post-Merge baseline?
  • Can calls or value transfers to 0xff…fe change its state, and how does that interact with any existing protocol use of this address?
Notable ambiguities noted by the assessor (5)
  • Activation is by block number (FORK_BLKNUM) and BLOCKHASH switches 256 blocks later, while the Cancun baseline activates forks by timestamp.
  • No code is given for HISTORY_STORAGE_ADDRESS, so whether it is a 'system contract' or just a protocol storage account is ambiguous.
  • The address 0xff…fe may coincide with an address used by baseline system-call machinery; the document does not address this.
  • Security Considerations expects the mechanism to be temporary (later replaced by an eth2 accumulator), but this has no normative testing consequence.
  • The Test Cases and Implementation sections are TBD.

Criterion breakdown

EIP-2935 Prague / Pectra: LLM criterion scores and rationale
CriterionScoreWhy this scoreEvidence / uncertainty
Modified opcodes3BLOCKHASH's return values change: it now returns stored hashes beyond 256 blocks and reads state.
  • eip.md · Specification — "change the logic of the BLOCKHASH opcode" BLOCKHASH's return value and data source change.
  • eip.md · Backwards Compatibility — "The range of BLOCKHASH is increased" Observable return values change for older arguments.
Confidence: High
Edge/boundary conditions3There are several boundary-sensitive mechanisms: the write starting at FORK_BLKNUM+1, the BLOCKHASH switch at FORK_BLKNUM+257, and the new argument range. These form an elevated matrix. The result depends jointly on block.number relative to FORK_BLKNUM+256 and on arg relative to FORK_BLKNUM, block.number-256 and block.number. For example, arg=FORK_BLKNUM or arg=block.number-257 gives a different result before and after the switch, and arg=FORK_BLKNUM-1 must return 0.
  • eip.md · Specification — "block.number > FORK_BLKNUM" Boundary for when the history write starts.
  • eip.md · Specification — "When block.number > FORK_BLKNUM + 256 ... if FORK_BLKNUM <= arg < block.number" Delayed logic switch, plus a range check bounded by the fork block and the current block.
Confidence: Medium
Uncertainty: Whether these dimensions count as an elevated matrix rather than independent boundaries is a judgement call; 2 is defensible.
Added system contractsUnder-specified2Exactly one protocol-designated stateful account is introduced: it has persistent storage written every block and read by BLOCKHASH.
  • eip.md · Simple Summary — "Store historical block hashes in a contract" A protocol-designated contract or account holds the history.
  • eip.md · Specification — "HISTORY_STORAGE_ADDRESS | 0xfffffffffffffffffffffffffffffffffffffffe" A single protocol-designated address with persistent storage written by the protocol.
  • eip.md · Rationale — "Writing the EIP in EVM code" removed No EVM code is specified; the storage is maintained natively.
Confidence: Medium
Uncertainty: No code is specified, so the account may not count as an EVM 'contract'. Under that reading the score would be 0.
New invariant on pre-existing tests2Every post-fork block test, and every state test if the tool performs the pre-transaction write, has a new protocol-mandated storage entry in its post-state. Pre-fork vectors are unaffected, so the universal-assertion case is level 2.
  • eip.md · Specification — "At the start of processing any block where block.number > FORK_BLKNUM ... run sstore(HISTORY_STORAGE_ADDRESS, ...)" Every post-fork block makes a protocol-mandated storage write, which changes post-state and the state root.
Confidence: Medium
Uncertainty: Whether single-transaction state tests apply the block-start write depends on test-harness conventions not given in the documents.
Security risksUnder-specified2Testing must show that user activity cannot corrupt or erase the history storage. Examples: touching the account while it has no nonce, code or balance (baseline empty-account cleanup), value transfers, and SELFDESTRUCT beneficiaries. Testing must also cover the changed BLOCKHASH assumption for contracts. This is a bounded interaction between the new storage and baseline account-lifecycle rules, needing targeted integration cases.
  • eip.md · Specification — "HISTORY_STORAGE_ADDRESS" Protocol-critical storage lives in an ordinary account reachable by user transactions (calls, value transfers).
  • eip.md · Backwards Compatibility — "The range of BLOCKHASH is increased" Contracts relying on BLOCKHASH returning 0 for old blocks see changed results.
Confidence: Medium
Uncertainty: The account's existence and emptiness status is not specified. If the account were properly installed, this would mostly reduce to local checks (level 1).
Performance risksUnder-specified2BLOCKHASH keeps its baseline low gas charge but now does a storage read over a large, growing storage trie with an attacker-chosen key. Blocks that spam BLOCKHASH with distinct old arguments need integrated benchmarks against the state database. This is a bounded interaction between the opcode and the state backend.
  • eip.md · Specification — "return sload(HISTORY_STORAGE_ADDRESS, arg)" BLOCKHASH now performs a storage-trie read over a growing storage set.
  • eip.md · Security Considerations — "~2.5 million storage slots per year" The history account's storage grows without bound.
Confidence: Medium
Uncertainty: Whether any additional gas is intended is unspecified. With an appropriate storage-read charge, component benchmarks (level 1) might be enough.
Unspecified behavior requiring cross-client consensus2Several localized, consensus-visible outcomes have competing readings: (1) whether the storage-only account counts as empty and can be deleted on touch; (2) the access-list and gas effects of BLOCKHASH's read; (3) whether the system write consumes block gas or changes the account. Expected state roots and gas results cannot be fixed until clients agree on these.
  • eip.md · Specification — "run sstore(HISTORY_STORAGE_ADDRESS, block.number - 1, block.prevhash)" Does not say whether or how the account is created (nonce, code, balance), so its emptiness status and survival after being touched are open.
  • eip.md · Specification — "return sload(HISTORY_STORAGE_ADDRESS, arg)" Gas, and warm/cold or access-list effects of the internal read, are not specified.
  • eip.md · Specification — "FORK_BLKNUM | TBD" Activation is by block number, not defined relative to timestamp-based activation in the baseline.
Confidence: Medium
State-access ordering within opcode executionUnder-specified1Only BLOCKHASH changes. Tests must fix whether its storage read warms HISTORY_STORAGE_ADDRESS or the slot under the baseline access-list rules, and whether it is charged as cold or warm. No general ordering rule for an opcode class changes.
  • eip.md · Specification — "return sload(HISTORY_STORAGE_ADDRESS, arg)" BLOCKHASH now reads account storage instead of history, so its access to state changes.
  • eip.md · Motivation — "the BLOCKHASH opcode would then access state and not history" Confirms that BLOCKHASH becomes a state-accessing instruction.
Confidence: Low
Uncertainty: Warm/cold and access-list effects are not specified. If no access-list effect is intended, this could be 0. If it is treated as a new state-accessing operation needing its own ordering rule, it could be 2.
Transition-tool interface changesUnder-specified1The tool must know the numeric activation block for the BLOCKHASH range and switch-over condition, and must have the parent hash for the write. One new semantic input (activation block) is most likely needed. The parent hash may already be derivable from existing block-hash inputs.
  • eip.md · Specification — "if FORK_BLKNUM <= arg < block.number" BLOCKHASH results depend on the numeric fork block, which named-fork selection does not supply.
  • eip.md · Specification — "block.prevhash" The block-start write needs the parent hash.
Confidence: Low
Uncertainty: No tool evidence is supplied. The change could be none (if FORK_BLKNUM is derived internally) or two fields (if the parent hash is also a new input).
Patterns affecting pre-existing tests1Rework is limited to BLOCKHASH out-of-range boundary cases in post-activation chains: queries older than 256 blocks that previously expected 0. This is a boundary subset of one family. The new storage write in every block's post-state is assessed under INV.
  • eip.md · Backwards Compatibility — "behavior within the previous 256-block range remains unchanged" Only queries outside the old 256-block window change result.
  • eip.md · Specification — "if FORK_BLKNUM <= arg < block.number, return sload" Arguments older than 256 blocks but at or after the fork block now return stored hashes instead of 0.
Confidence: Medium
New test-framework primitives1Tests need long post-fork chains and fork-transition fixtures keyed to a block number. The Cancun baseline activates forks by timestamp, so existing chain-building and transition-fork primitives need a local extension. No new expectation abstraction is required.
  • eip.md · Specification — "When block.number > FORK_BLKNUM + 256" Tests need chains of more than 256 post-fork blocks and a numeric activation block.
Confidence: Medium
Uncertainty: How well the existing framework supports block-number activation after the Merge is not evidenced.
Cross-EIP interactionsUnder-specified1The candidate EIPs are citations only. The unnumbered interactions with baseline storage-access warmth and account-emptiness rules need local compatibility checks, such as BLOCKHASH followed by accesses to the address, and touches of the address.
  • eip.md · Rationale — "Very similar ideas were proposed before in EIP-98 and EIP-210" EIP-98 and EIP-210 are cited only as superseded prior designs, not as active behavior the target interacts with.
  • eip.md · Specification — sstore/sload on HISTORY_STORAGE_ADDRESS Uses baseline storage-access semantics, which interact with the baseline access-list and empty-account rules.
Confidence: Low
Uncertainty: These interactions follow from baseline semantics, not from explicit text. They could be 0 if not counted, or 2 if coordinated cases are needed.
Show 16 zero-score criteria
Zero-score criteria (Checklist revision 3)
CriterionScoreWhy this scoreEvidence / uncertainty
Added opcodes0No new instruction.
  • eip.md · Simple Summary — "modify the BLOCKHASH (0x40) opcode" An existing opcode is modified; no new one is added.
Added precompiles0None.
  • eip.md · Specification No precompile introduced.
Modified precompiles0None.
  • eip.md · Specification No precompile changed.
Modified system contracts0No baseline system contract's rules change according to the supplied text.
  • eip.md · Specification No existing system contract is changed by the text.
Uncertainty: The address 0xff…fe may coincide with an address used by baseline Cancun system-call machinery. The document does not mention this.
EVM Gas rule changesUnder-specified0No execution-gas accounting rule or parameter is changed by the text. BLOCKHASH keeps its baseline charge, and the protocol-level write has no stated gas.
  • eip.md · Specification Specifies only a pre-transaction sstore and new BLOCKHASH lookup logic; no gas cost, metering or limit is stated for either.
Uncertainty: The text does not say whether the internal sload adds storage-access gas to BLOCKHASH, or whether the system sstore uses block gas. Either reading would make this level 1.
Blob gas accounting changes0Blob-gas accounting is untouched.
  • eip.md · Specification Nothing about blobs or blob gas.
State gas accounting changes0A protocol storage write is added, but no state-byte cost, budget or spill rule is introduced or changed.
  • eip.md · Security Considerations — "Adding ~2.5 million storage slots per year" State growth is acknowledged, but no state-gas charging mechanism is introduced.
New EVM gas refund0No new refund is introduced.
  • eip.md · Specification No refund mechanism is mentioned.
New transaction types0None.
  • eip.md · Specification No transaction type defined.
New or modified transaction validity mechanisms0Transaction validity is unchanged.
  • eip.md · Specification No transaction validity or intrinsic gas rule.
New block / header fields0No header or block field is added.
  • eip.md · Specification — "block.prevhash" Uses the existing parent hash; no header member added.
Encoding changes (RLP/SSZ)0No serialized schema changes; the new storage entries use the existing format.
  • eip.md · Specification Only storage values within the existing account/storage schema.
Block syncing changes0Only execution rules change; block structure validation is untouched.
  • eip.md · Specification No block or header decoding or structural validation change.
New fork activation mechanismUnder-specified0Starting a recurring block-start write does not count as an activation-specific transition, and no one-time installation is specified.
  • eip.md · Specification — "At the start of processing any block where block.number > FORK_BLKNUM" Only recurring per-block processing starts; no backfill, migration or code installation is specified.
Uncertainty: If clients had to create or install the account (for example, set a nonce or code) at activation to protect it from empty-account rules, this would become 3. The text does not require it.
Engine API changes0The Engine API is unchanged.
  • eip.md · Specification No Engine API fields or methods mentioned.
Cryptography0Existing block hashes are stored without change. No cryptographic rule changes.
  • eip.md · Specification Stores existing block hashes; no new hashing, signing or proof rule.
Assessment provenance
Assessed EIP revision
ethereum/EIPs@9e393a79d9 EIPS/eip-2935.md committed 2022-05-06 · information cutoff 2024-04-11
Current master · File history · blob bbe12f21b0 · sha256 bcdb09d0585a
Rubric
Checklist revision 3 · ethspecs/pm@fe2f793b03
Evaluator
Opus 5.5 (claude-opus-5-5) at high effort, one tool-less call per EIP · isolation bubblewrap_claude_p_no_tools_v1
Source record
Frozen research record research/tasks/10-opus-v3-reassessment/retrospective/outputs/assessments/prague/eip-2935.yaml · sha256 d1e021e9534c
Criterion legend and glossary

Every stacked bar, comparison matrix, and criterion table on this site uses the same criterion colours, abbreviations, and order. Colour marks the criterion group; the abbreviation and name identify the criterion. Scores are 0–3 per criterion (4 is exceptional; cross-EIP interactions is uncapped).

EVM surface

Opcodes, precompiles, and system contracts that are added or modified.

  • Added opcodes
    Introduces new opcodes
    Score anchors
    0
    No new opcodes are introduced.
    1
    A new simple opcode is introduced (no data portion, no complex stack mechanics, and a constant gas cost).
    2
    Multiple new simple opcodes are introduced, or a single new complex opcode is introduced (has data portion, or complex stack mechanics, or a dynamic gas cost).
    3
    Multiple new opcodes are introduced, and at least one of them is complex (has data portion, or complex stack mechanics, or a dynamic gas cost).
    • Cryptography opcodes are not considered complex by default. Refer to the "Cryptography" section for a separate assessment.
  • Modified opcodes
    Modifies pre-existing opcodes
    Score anchors
    0
    No pre-existing opcode modifications are introduced.
    3
    At least one pre-existing opcode's behavior is modified (not including gas changes) or a pre-existing opcode is deprecated.
  • Added precompiles
    Introduces new precompiles
    Score anchors
    0
    No new precompiles are introduced.
    1
    A new simple precompile is introduced (constant input length, constant gas cost).
    2
    Multiple new simple precompiles are introduced, or a single new complex precompile is introduced (dynamic input length or dynamic gas cost).
    3
    Multiple new precompiles are introduced, and at least one of them is complex (dynamic input length or dynamic gas cost).
    • Cryptography precompiles are not considered complex by default. Refer to the "Cryptography" for a separate assessment.
  • Modified precompiles
    Modifies pre-existing precompiles logic or gas-accounting
    Score anchors
    0
    No pre-existing precompiles are modified.
    1
    At least one pre-existing precompile has its gas schedule modified.
    2
    Multiple pre-existing precompiles have their gas schedule modified, or a single pre-existing precompile has its behavior modified.
    3
    The behavior of multiple pre-existing precompiles, or a single complex pre-existing precompile modified.
  • Added system contracts
    Introduces new system contract, stateful or not
    Score anchors
    0
    No new system contracts are introduced.
    1
    A new system contract is introduced that is not stateful nor does it trigger a new system action (e.g. requests to the consensus layer).
    2
    Multiple new system contracts are introduced or a single new system contract that is either stateful or triggers a new system action (e.g. requests to the consensus layer).
    3
    Multiple new system contracts are introduced and at least one of them is either stateful or triggers a new system action (e.g. requests to the consensus layer).
  • Modified system contracts
    Modifies pre-existing system contracts
    Score anchors
    0
    No modifications to pre-existing system contracts are introduced, directly or indirectly.
    1
    Does not directly modify any system contract, but its behavior has minor indirect effects on one or more system contracts.
    2
    Does not directly modify any system contract, but its behavior has major indirect effects on one or more system contracts.
    3
    At least one pre-existing system contract code or state is modified, which would involve irregular state transition or a similarly complex transition methodology.

Gas and accounting

Execution, blob, and state gas rules, refunds, and where charges happen inside opcodes.

  • EVM Gas rule changes
    New EVM gas accounting rules
    Score anchors
    0
    No gas accounting changes.
    1
    Existing gas accounting mechanism is updated.
    2
    A new gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State-access ordering within opcode execution · not in checklist revision 1
    Changes *where inside an opcode's execution* state is accessed, or where gas is charged relative to that access. Because a state access is recorded in the block-level access list only if execution had enough gas to reach it, this ordering is consensus-critical: moving it changes the BAL at every gas boundary of every affected opcode.
    Score anchors
    0
    No change to where state is accessed, or to where gas is charged relative to a state access, within any opcode.
    1
    A single opcode's state-access or gas-charge ordering changes.
    2
    Multiple opcodes' ordering changes, or a new state-accessing operation is introduced whose position in the order must be settled.
    3
    The ordering rule changes for a whole class of state-accessing opcodes at once, or what counts as a recordable state access is redefined — requiring existing BAL vectors to be re-derived across opcodes and forks.
    • Distinct from "Modified opcodes", which asks whether an opcode's **result** changed. This row asks about the **path to the result**, which is observable even when the result is identical. An EIP can be 0 on that row and 3 on this one.
    • Score changes **to** the ordering. Do not score the fact that state accesses are observable — they always are.
    • Each boundary must be re-tested against every other dimension that can change the answer (cold/warm, static/non-static, delegated/direct, revert/success), so the case count grows multiplicatively rather than additively. Note this explicitly under Special Considerations.
  • Blob gas accounting changes
    New Blob gas accounting rules which potentially affect pre-existing tests
    Score anchors
    0
    No blob gas accounting changes.
    1
    Existing blob gas accounting mechanism is updated.
    2
    A new blob gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new blob gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State gas accounting changes · not in checklist revision 1
    New state gas accounting rules. State gas is the cost of *writing* state, as opposed to accessing or executing it: `StateGasCosts`, `COST_PER_STATE_BYTE`, the block-level state gas budget, and the spill path into execution gas.
    Score anchors
    0
    No state gas accounting changes.
    1
    An existing state gas cost or `STATE_BYTES_PER_*` rate is adjusted.
    2
    A new state-gas-charging site is introduced, or the block-level state gas budget or reservoir allocation is modified.
    3
    A new state gas charging mechanism is introduced, or the spill interaction between state gas and execution gas is modified, affecting existing gas tests.
    • Harder to test than blob gas: the spill path means state gas cannot be metered independently of execution gas, and some costs (e.g. `NEW_ACCOUNT`) are state-dependent.
  • New EVM gas refund
    New gas-refund mechanism
    Score anchors
    0
    No new gas-refund mechanisms are introduced.
    1
    A new simple gas-refund mechanism is introduced that does not affect either existing tests or existing gas-refund mechanisms.
    2
    A new complex gas-refund mechanism is introduced or a simple mechanism that affects existing tests or existing gas-refund mechanisms.
    3
    A new complex gas-refund mechanism is introduced that affects existing tests or existing gas-refund mechanisms.

Blocks, transactions, and encoding

Transaction types and validity, block and header fields, encodings, syncing, and activation-time changes.

  • New transaction types
    Introduces a new transaction type
    Score anchors
    0
    No new transaction types are introduced.
    3
    A new transaction type is introduced.
  • New or modified transaction validity mechanisms
    Creates new or modifies pre-existing transaction types' validation mechanisms
    Score anchors
    0
    No changes are introduced to the validity rules of existing transaction types or to their intrinsic gas cost calculation.
    1
    Minor adjustments are introduced to validity rules or intrinsic gas cost calculation, but they do not significantly affect existing tests.
    2
    Changes to validity rules or intrinsic gas cost calculation affect existing tests, but require only limited updates to test cases and no redesign of the testing infrastructure.
    3
    Changes to validity rules or intrinsic gas cost calculation require extensive rework or redesign of the tests or testing infrastructure.
  • New block / header fields
    Introduces new block or block header fields
    Score anchors
    0
    No new block or header fields are introduced.
    3
    A new block or header field is introduced.
  • Encoding changes (RLP/SSZ)
    Introduces encoding changes at the transaction/block/interfaces level
    Score anchors
    0
    No encoding changes are introduced at the transaction, block, or interfaces levels.
    3
    An encoding change is introduced at transaction, block or interfaces level (e.g. RLP -> SSZ).
    • "Interfaces level" includes the Engine API. Score an Engine API encoding change (e.g. JSON -> SSZ) here.
  • Block syncing changes
    Modifies block RLP validation mechanisms that require test client syncing.
    Score anchors
    0
    No new RLP validation mechanism is introduced.
    1
    A single simple RLP validation mechanism is introduced.
    2
    Multiple simple RLP validation mechanisms are introduced or a single complex one.
    3
    Multiple RLP validation mechanisms are introduced and at least one of them is deemed complex.
  • New fork activation mechanism
    Modifies state, internal variables, or similar, at the fork activation block
    Score anchors
    0
    No state modifications, internal variables or similar are modified at the fork activation block.
    3
    Either a state modification or internal variables are modified at the fork activation block.
    • Initialization of new internal variable is not considered a modification.

Client interfaces

Engine API and transition-tool interface changes.

  • Engine API changes
    Introduces new fields to the Engine API directives
    Score anchors
    0
    No new fields or communication mechanisms are introduced to the Engine API.
    1
    A single new field is introduced in one of the Engine API endpoints.
    2
    Multiple fields are introduced to one or multiple Engine API end points, or a new Engine API end-point is introduced.
    3
    Multiple fields are introduced to one or multiple Engine API end points and a new Engine API end-point is introduced.
  • Engine API encoding changes · Checklist revision 1 only
    Engine API encoding changes (the revision-1 template defines no anchor text for this row).
  • Transition-tool interface changes
    Modifies or adds new fields to the transition tool interface.
    Score anchors
    0
    No modifications to the transition tool interface are required.
    1
    A single new field needs to be introduced to the transition tool interface.
    2
    Multiple new fields or a new mechanism has to be introduced to the transition tool interface.
    3
    Multiple new fields and a new mechanism has to be introduced to the transition tool interface.
    • Special consideration must be paid to this section if the EIP introduces a mechanism that requires the state transition tool to be aware whether the block it is processing is the fork-activation block.

Testing impact

Rework, new invariants, and new primitives required in the test framework.

  • Patterns affecting pre-existing tests
    Implements a new validation mechanism or rule that translates in reworking pre-existing tests
    Score anchors
    0
    No pre-existing tests are affected by this change.
    1
    Minor subset of existing tests are affected by this change.
    2
    Considerable subset of existing tests are affected by this change but involves only a contrived category of tests.
    3
    Major subset of existing tests are affected, including diverse category of tests (benchmarks, static, multiple forks, etc.).
  • New invariant on pre-existing tests · not in checklist revision 1
    Tests that are **not about this EIP** must nonetheless assert something this EIP produces. Their logic does not change; they gain a new thing to check.
    Score anchors
    0
    Pre-existing tests assert nothing new.
    1
    A narrow, contrived category of pre-existing tests gains a new assertion.
    2
    A broad category gains a new assertion, applied mechanically.
    3
    Every test in the fork gains the assertion regardless of what it tests, and pre-fork vectors must be re-derived to satisfy it.
    • Paired with the row above, and easy to confuse with it. "Patterns affecting pre-existing tests" asks whether existing tests must be **reworked**; this row asks whether they must **additionally assert something new**. Score both — an EIP can be low on one and high on the other.
  • New test-framework primitives · not in checklist revision 1
    Requires new abstractions in the test framework itself — expectation types, modifiers, helpers — beyond writing test functions with what already exists.
    Score anchors
    0
    Existing test primitives suffice.
    1
    Existing primitives need minor extension.
    2
    New expectation or modifier primitives are required, reusable within this EIP's own test suite.
    3
    New framework-level primitives are required that become a permanent part of the framework and are used by other EIPs' tests.

Risk and validation

Security, performance, boundary conditions, and cryptography that need validation.

  • Security risks
    Introduces or modifies mechanisms that could compromise the security of the chain, users, validators, or other stakeholders, if not implemented properly.
    Score anchors
    0
    No new mechanisms are introduced that could pose a security risk.
    1
    The introduced mechanisms are self-contained, can be validated in isolation, and do not alter existing invariants that could pose a security risk for any stakeholders.
    2
    The introduced mechanisms interact with a limited number of existing components, slightly altering their security assumptions and requiring a targeted security review or fuzzing.
    3
    The introduced mechanisms interact with multiple existing components, including critical ones, substantially altering their security assumptions and requiring an extensive security review and fuzzing.
  • Performance risks
    Introduces or modifies mechanisms and requires performance validation.
    Score anchors
    0
    No new mechanisms are introduced that require performance validation.
    1
    The introduced mechanisms can be benchmarked in isolation and do not affect existing performance behavior.
    2
    The introduced mechanisms cannot be fully benchmarked in isolation, but they only have a limited impact on the existing performance benchmarks.
    3
    The introduced mechanisms cannot be benchmarked in isolation and have a substantial impact on existing performance benchmarks or have complex interactions with existing mechanisms.
  • Edge/boundary conditions
    Feature contains edge/boundary conditions.
    Score anchors
    0
    No discernible edge cases or boundary conditions are introduced.
    1
    A single edge-case or boundary-condition prone mechanism is introduced.
    2
    Multiple edge-case or boundary-condition prone mechanisms are introduced, but none of them requires an elevated number of cases to test.
    3
    Multiple edge-case or boundary-condition prone mechanisms are introduced and at least one of them requires an elevated number of cases to test.
  • Cryptography
    Introduces new cryptography mechanisms or modifies existing functionality that involves cryptography
    Score anchors
    0
    No cryptography mechanisms are introduced.
    1
    A new cryptography mechanism is introduced but it is a well known mechanism that is known to have vast resources to aid on its testing.
    2
    Multiple new cryptography mechanisms are introduced that are well-known or a single but novel mechanism is introduced that is either untested or has limited resources.
    3
    Multiple new cryptography mechanisms are introduced and at least one of them is a novel mechanism.

Coordination

Cross-EIP interactions and behavior that clients must agree on before tests exist.

  • Cross-EIP interactions
    Introduces or modifies mechanisms that affect other EIPs in either the same or past forks.
    Score anchors
    0
    Fully self-contained EIP that does not depend on, modify, or conflict with any other EIP.
    1
    The EIP interacts with one or more other EIPs in a non-critical and limited way but can be tested independently for the most part.
    2
    The EIP depends on or modifies one or more other EIPs such that coordinated testing and consideration is required, but interactions are limited in scope and not complex.
    3
    The EIP has strong interdependencies with multiple EIPs, requiring extensive coordinated cross-EIP testing as well as potential re-design of existing test vectors.
    • +1 for every 3 additional interacting EIPs beyond the first 3, each of which requires its own coordinated test cases. List the EIPs in the rationale.
    • This row is intentionally uncapped, unlike every other anchor: each interacting EIP is another axis of the test matrix, so a ceiling would make a 12-EIP product indistinguishable from a 3-EIP one.
  • Unspecified behavior requiring cross-client consensus · not in checklist revision 1
    The EIP text does not determine the answer for cases a test can construct. Clients must agree on a previously unspecified detail before tests can be baselined. The cost here is coordination and re-baselining, not test writing.
    Score anchors
    0
    The EIP text determines the answer for every case a test could construct.
    1
    A few details are unspecified but have an obvious intended reading.
    2
    Details require client agreement before tests can be written, but they are localized.
    3
    A previously unspecified *and previously unobservable* behavior becomes consensus-critical; expect tests to be re-baselined on each round of EIP amendment.
    • Score this from the EIP's state at assessment time: whether it has client implementations, whether it has been through a devnet, and how many open questions remain on its discussion thread.