Retrospective LLM-Based Complexity Evaluations

EIP complexity assessment

EIP-4788: Beacon block root in the EVM

Assessed in Cancun / Dencun. The score describes the EIP text available at the assessment cutoff, not the EIP as it stands today.

RetrospectiveCancun / DencunAssessment cutoff 2023-04-27Included by cutoffLayers: execution, consensus
LLM Completescore 30
Human Not available· Human complexity assessments were not produced for this fork; only the LLM assessment exists.

LLM assessment

Evaluated on: · Spec revision: 2023-04-13 · 5b909b76ac

Scope at the cutoff. This revision of EIP-4788 adds a 32-byte parent beacon block root to the execution block header, after `withdrawals_root`, starting at FORK_TIMESTAMP. At the start of each post-fork block, before any transactions run, the protocol writes that root into the storage of HISTORY_STORAGE_ADDRESS (0xff..fd). It writes once for every slot from the parent block's slot up to, but not including, the current block's slot, at key `slot % 8192`, so a ring buffer holds the history. A new opcode, BEACON_ROOT (0x48), pops a slot number, charges a constant 20 gas and returns `sload(HISTORY_STORAGE_ADDRESS, slot % 8192)`. A missing value reads as 0. The revision does not define the slot conversion, Engine API delivery, test cases or security considerations.

30HighHigh
Evaluator
LLMChecklist v3
Confidence
Medium
Under-specified at assessment cutoff
Yes — 9 criteria affected
Plausible range
21–38 (Medium–High)
Assessment cutoff
2023-04-27 · EIP revision 5b909b76ac (2023-04-13)
Score bands · Checklist revision 3
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the LLM total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. New block / header fields3
  2. Encoding changes (RLP/SSZ)3
  3. Edge/boundary conditions3
  4. Added system contracts2

Under-specified at assessment cutoff: Yes

The EIP text available at the assessment cutoff left material behavior unresolved. The affected criteria and the plausible total range record that uncertainty.

Why: The revision leaves several things undefined: convert_to_slot, how the root reaches the EL (Engine API), the history account's nonce/code status and empty-account treatment, whether the opcode affects accessed sets, and how large timestamp gaps are bounded. Test Cases, Reference Implementation and Security Considerations are all TODO, and the gas-constant name is inconsistent.

Unresolved questions at the cutoff (6)
  • How does convert_to_slot map timestamps to slots (genesis time, slot duration, rounding), and where does the EL get these parameters?
  • How does the parent beacon block root reach the EL (Engine API fields/methods, payload attributes for building)?
  • Does HISTORY_STORAGE_ADDRESS need a nonce or code, and is it protected from EIP-161 empty-account clearing?
  • Does BEACON_ROOT add the history address or slot to EIP-2929 accessed sets or interact with warm/cold pricing?
  • Is the skipped-slot write loop capped (for example at SLOTS_PER_HISTORICAL_ROOT) for very large timestamp gaps?
  • Is the opcode gas constant G_beacon_root or G_beacon_state_root (both presumably 20)?
Notable ambiguities noted by the assessor (4)
  • The text calls the opcode gas constant G_beacon_state_root, but the table defines only G_beacon_root = 20.
  • The rationale claims constant work per block, while the pseudocode loops over every skipped slot.
  • The opcode reduces any slot modulo 8192, so requests for future or out-of-window slots return aliased stale roots instead of 0.
  • The history account is called a contract but has no code or account fields specified.

Criterion breakdown

EIP-4788 Cancun / Dencun: LLM criterion scores and rationale
CriterionScoreWhy this scoreEvidence / uncertainty
New block / header fields3An EL execution-header member is added.
  • eip.md · Block structure and validity "set 32 bytes of the execution block header after the withdrawals_root" Adds parent_beacon_block_root to the execution block header.
Confidence: High
Encoding changes (RLP/SSZ)3The execution header serialization schema changes.
  • eip.md · Block structure and validity "this field is appended to the current block header structure" The RLP schema of the execution block header gains a 32-byte field after withdrawals_root.
Confidence: High
Edge/boundary conditionsUnder-specified3There are several boundary-sensitive mechanisms: the fork-timestamp gate, the write loop over skipped slots with modulo wrap, the opcode's modular read with arbitrary arguments, and the header field's presence by timestamp. The write mechanism forms an elevated matrix: gap length (0, 1, many, at least 8192) × ring-wrap position × fork-boundary parent. These combine to determine which keys hold which roots, so they cannot be tested independently.
  • eip.md · EVM changes / Block processing "for slot in range(start_slot, end_slot)" The number of writes depends on the timestamp gap between parent and child. Skipped slots are filled, and the keys wrap modulo 8192.
  • eip.md · EVM changes / New opcode "slot % SLOTS_PER_HISTORICAL_ROOT" The read key wraps modulo 8192 for any 256-bit argument, so future or stale slots alias other entries.
  • eip.md · Block processing "block.timestamp >= FORK_TIMESTAMP" There is a fork-activation timestamp boundary, and the first post-fork block has a pre-fork parent.
Confidence: Medium
Uncertainty: If the gap and wrap dimensions are treated as separable, this would be 2. Undefined slot conversion (rounding of non-aligned timestamps) adds further boundaries.
Added system contractsUnder-specified2Exactly one protocol-designated, stateful (ring-buffer storage) contract location is introduced, which is level 2.
  • eip.md · Background "block roots are stored in a canonical place in the execution state ... in given contract's storage" A protocol-designated account at 0xff..fd holds persistent storage.
  • eip.md · EVM changes / New opcode "a read of the history contract's storage" The spec itself calls it the history contract. It is written by the protocol and read by the opcode.
Confidence: Medium
Uncertainty: No code is specified. If a code-less storage account is not treated as an EVM system contract, this could be 0.
State-access ordering within opcode executionUnder-specified2A new state-accessing operation needs an ordering rule: when gas is charged relative to the read, and whether the read adds HISTORY_STORAGE_ADDRESS or its slot to the accessed sets. This meets level 2. No existing opcode class's ordering changes.
  • eip.md · EVM changes / New opcode "sload(HISTORY_STORAGE_ADDRESS, slot % SLOTS_PER_HISTORICAL_ROOT)" BEACON_ROOT is a new instruction that reads another account's storage.
Confidence: Medium
Uncertainty: The spec gives no ordering or access-set rule. With a constant charge the ordering may be trivial (low end 0).
Block syncing changesUnder-specified2Header decoding and structural validation must require the 32-byte field from FORK_TIMESTAMP onward and reject it before then. This is one rule that depends on another field (timestamp), so it is complex (level 2).
  • eip.md · Block structure and validity "appended to the current block header structure ... grows after (and including) the FORK_TIMESTAMP" Header RLP gains a field whose presence depends on the block's timestamp.
Confidence: Medium
Uncertainty: If treated as a simple local length/presence check this would be 1. The EL cannot validate the value itself.
New invariant on pre-existing tests2Every post-fork block-level test must account for the new header field and the history-storage write. The change is gated by timestamp, so pre-fork vectors do not need re-deriving. A universal assertion without pre-fork changes is level 2.
  • eip.md · Block structure and validity Every post-fork header carries the new 32-byte root field.
  • eip.md · EVM changes / Block processing "At the start of processing any execution block where block.timestamp >= FORK_TIMESTAMP" Every post-fork block performs a protocol-mandated storage write to HISTORY_STORAGE_ADDRESS.
Confidence: High
Security risks2The change creates a bounded cross-layer trust interaction: CL-provided roots enter EL state and consensus, and contracts are invited to rely on them. It also adds DoS surfaces (an underpriced read and unmetered writes) and the reserved-address state. Each needs targeted integration review.
  • eip.md · Block structure and validity The EL commits CL-supplied data it cannot verify, and exposes it to contracts as a trust anchor.
  • eip.md · Security Considerations "TODO" No security analysis is provided.
  • eip.md · EVM changes / New opcode "slot % SLOTS_PER_HISTORICAL_ROOT" Out-of-window slots silently alias to other slots' roots.
Confidence: Medium
Performance risksUnder-specified2Two bounded interactions need targeted integrated benchmarks. First, gas-unmetered storage writes proportional to skipped slots during block processing, up to and beyond 8192 slots. Second, a 20-gas trie storage read that contracts can repeat across many keys.
  • eip.md · EVM changes / Block processing "for slot in range(start_slot, end_slot)" Unmetered system storage writes scale with the timestamp gap. Nothing bounds the loop.
  • eip.md · Rationale / Gas cost of opcode A storage read is priced at 20 gas, the BLOCKHASH price, well below SLOAD's cold-read pricing.
  • eip.md · Rationale / Beacon block root instead of state root "constant amount of work" The rationale claims constant work, which conflicts with the per-slot loop.
Confidence: Medium
Uncertainty: Whether implementations cap the loop at 8192 iterations is unspecified.
Unspecified behavior requiring cross-client consensus2Several localized, consensus-visible outcomes have competing interpretations and need client agreement: how slots are converted, whether and how the history account exists (and so the state root), whether the opcode warms accessed sets, and loop behavior for large gaps. This is level 2.
  • eip.md · EVM changes / Block processing "convert_to_slot(start_timestamp)" convert_to_slot is never defined (genesis time, seconds per slot, rounding), but it decides the consensus-visible storage keys.
  • eip.md · EVM changes / New opcode "gas cost of G_beacon_state_root" The text names a constant that differs from the one in the table.
  • eip.md · Background / Block processing The account state (nonce/code, empty-account treatment), access-set warming and behavior for very large gaps are unspecified.
Confidence: High
Added opcodes1Exactly one simple instruction is introduced (fixed stack effects, no immediate data, constant gas).
  • eip.md · EVM changes / New opcode "consumes one word from the stack" BEACON_ROOT at 0x48 pops 1 word, pushes 1 word and takes no immediates.
  • eip.md · Specification (constants) "G_beacon_root | 20" Constant gas cost.
Confidence: High
Uncertainty: The gas constant is named inconsistently (G_beacon_root vs G_beacon_state_root), but both refer to the single value 20.
EVM Gas rule changesUnder-specified1No new accounting mechanism is added. There is a new constant gas entry for an instruction that reads state outside the existing cold/warm storage pricing, and the system writes are unmetered. This fits a parameter-level change (level 1) rather than a new mechanism.
  • eip.md · Specification (constants table) "G_beacon_root | 20" The new opcode has a constant gas cost of 20.
  • eip.md · Rationale / Gas cost of opcode The cost copies BLOCKHASH, although the opcode reads storage, which bypasses the cold/warm storage-read pricing.
  • eip.md · EVM changes / Block processing The protocol's storage writes happen before any transactions. No gas charge is specified for them.
Confidence: Medium
Uncertainty: The spec does not say whether the read is subject to EIP-2929 warm/cold charging. If it were, a new accounting interaction would push this toward 2. A strict reading that a new opcode's fixed cost is not an accounting change would give 0.
Engine API changesUnder-specified1The EL can only obtain the parent beacon block root from the CL, so at least one Engine API field must carry it. The revision specifies no field or endpoint, so the minimum supported reading is used.
  • eip.md · Block structure and validity The EL must set a header field holding CL-derived data, which implies the CL must supply it.
  • eip.md · Reference Implementation "TODO" No Engine API changes are specified.
Confidence: Low
Uncertainty: Delivery (new versioned methods, payload attributes for block building) is entirely unspecified. Plausible range is 0–3.
Transition-tool interface changesUnder-specified1The tool's environment needs one new field, the parent beacon block root, with no new exchange mechanism (level 1).
  • eip.md · EVM changes / Block processing "parent_beacon_block_root = block_header.parent_beacon_block_root" Block processing needs the parent beacon block root as an input to the state transition.
  • eip.md · EVM changes / Block processing "convert_to_slot(start_timestamp)" Slot conversion needs the parent timestamp and an undefined timestamp-to-slot mapping.
Confidence: Medium
Uncertainty: If convert_to_slot needs genesis time or slot-duration parameters, or the parent timestamp must be supplied newly, multiple fields would change (2). No tool evidence was supplied.
Patterns affecting pre-existing tests1Rework is confined to boundary cases in one family: invalid/undefined-opcode tests that cover 0x48, plus incidental use of the newly reserved address. The universal header and storage-write effects belong under INV.
  • eip.md · Specification (constants) "OPCODE_VALUE | 0x48" Opcode 0x48, previously undefined, becomes valid at the fork.
  • eip.md · Specification (constants) "HISTORY_STORAGE_ADDRESS" Address 0xff..fd now receives protocol writes, which affects any baseline test that uses that address as an ordinary account.
Confidence: Medium
Uncertainty: If expected post-state roots in all blockchain tests are counted as rework rather than a new assertion, this could be 2.
New test-framework primitives1The existing header and environment primitives need a local extension for the beacon root field, plus a helper to model expected ring-buffer contents. No shared new abstraction is clearly required.
  • eip.md · Block structure and validity The new header field must be settable and checkable in generated blocks.
  • eip.md · EVM changes / Block processing Expected history storage depends on the timestamp gap and ring-buffer indexing.
Confidence: Medium
Uncertainty: An expected-history-storage modeling abstraction across tests could be argued as level 2.
Cross-EIP interactions1Only local compatibility checks are needed. The header field must sit after withdrawals_root. If EIP-2935 were also active, its history address and BLOCKHASH behavior would need to stay unaffected. The target's behavior can otherwise be tested on its own.
  • eip.md · Background "inspired by EIP-2935" The opcode design is modeled on EIP-2935's history storage approach.
  • supporting/eip-2935.md · Specification EIP-2935 uses a separate address (0xff..fe) and modifies BLOCKHASH. The target uses 0xff..fd and leaves BLOCKHASH unchanged.
  • eip.md · Block structure and validity "after the withdrawals_root" Header field placement depends on the existing withdrawals header field.
Confidence: Medium
Uncertainty: EIP-2935 is not part of the assessed Cancun baseline, and the evidence does not establish that it is scheduled alongside this EIP.
Interacting EIPs: EIP-2935
Show 11 zero-score criteria
Zero-score criteria (Checklist revision 3)
CriterionScoreWhy this scoreEvidence / uncertainty
Modified opcodes0No existing defined instruction changes semantics. 0x48 was undefined, so it counts under added opcodes.
  • eip.md · Rationale / Why not repurpose BLOCKHASH? BLOCKHASH is explicitly left unchanged.
Added precompiles0No new precompile.
  • eip.md · Specification No precompile is introduced.
Modified precompiles0No precompile is modified.
  • eip.md · Specification No precompile changes.
Modified system contracts0No existing system contract's rules change.
  • supporting/eip-2935.md · Specification "HISTORY_STORAGE_ADDRESS | 0xff...fe" EIP-2935's history address is distinct and is not part of the Shanghai+Cancun baseline.
Blob gas accounting changes0Blob-gas accounting does not change.
  • eip.md · Specification Nothing in the specification refers to blob gas.
State gas accounting changes0No state-gas accounting mechanism or parameter is introduced or changed.
  • eip.md · EVM changes / Block processing The protocol writes storage, but no state-gas charging or budget is defined.
New EVM gas refund0There is no new refund mechanism.
  • eip.md · Specification No refund rules are introduced.
New transaction types0No new transaction envelope.
  • eip.md · Specification No transaction type is defined.
New or modified transaction validity mechanisms0Transaction validity is unchanged.
  • eip.md · Specification There are no transaction-validity or intrinsic-gas rule changes.
New fork activation mechanismUnder-specified0Starting recurring block processing does not count. No activation-specific state conversion or code installation is specified.
  • eip.md · EVM changes / Block processing The writes are recurring per-block processing that starts at FORK_TIMESTAMP. No one-time migration or code installation is specified.
Uncertainty: The account's nonce/code status at activation is unspecified. A required activation-time installation (for example, to avoid empty-account clearing) would make this 3.
Cryptography0The EL adds or changes no cryptographic verification, hashing or proof rule. The root is opaque data.
  • eip.md · Block structure and validity "32 byte hash tree root of the parent beacon block" The EL only stores a 32-byte value computed by the CL. It does not verify it.
  • supporting/ethereum-consensus-specs--ssz-simple-serialize.md · Merkleization hash_tree_root is defined in the CL's SSZ specification. The EL never runs it under this EIP.
Assessment provenance
Assessed EIP revision
ethereum/EIPs@5b909b76ac EIPS/eip-4788.md committed 2023-04-13 · information cutoff 2023-04-27
Current master · File history · blob a2553d4b78 · sha256 4df9dad7b1f5
Rubric
Checklist revision 3 · ethspecs/pm@fe2f793b03
Evaluator
Opus 5.5 (claude-opus-5-5) at high effort, one tool-less call per EIP · isolation bubblewrap_claude_p_no_tools_v1
Source record
Frozen research record research/tasks/10-opus-v3-reassessment/retrospective/outputs/assessments/cancun/eip-4788.yaml · sha256 833491eb91fd
Supporting documents supplied with the EIP
supporting/eip-2935.md, supporting/ethereum-consensus-specs--ssz-simple-serialize.md
Criterion legend and glossary

Every stacked bar, comparison matrix, and criterion table on this site uses the same criterion colours, abbreviations, and order. Colour marks the criterion group; the abbreviation and name identify the criterion. Scores are 0–3 per criterion (4 is exceptional; cross-EIP interactions is uncapped).

EVM surface

Opcodes, precompiles, and system contracts that are added or modified.

  • Added opcodes
    Introduces new opcodes
    Score anchors
    0
    No new opcodes are introduced.
    1
    A new simple opcode is introduced (no data portion, no complex stack mechanics, and a constant gas cost).
    2
    Multiple new simple opcodes are introduced, or a single new complex opcode is introduced (has data portion, or complex stack mechanics, or a dynamic gas cost).
    3
    Multiple new opcodes are introduced, and at least one of them is complex (has data portion, or complex stack mechanics, or a dynamic gas cost).
    • Cryptography opcodes are not considered complex by default. Refer to the "Cryptography" section for a separate assessment.
  • Modified opcodes
    Modifies pre-existing opcodes
    Score anchors
    0
    No pre-existing opcode modifications are introduced.
    3
    At least one pre-existing opcode's behavior is modified (not including gas changes) or a pre-existing opcode is deprecated.
  • Added precompiles
    Introduces new precompiles
    Score anchors
    0
    No new precompiles are introduced.
    1
    A new simple precompile is introduced (constant input length, constant gas cost).
    2
    Multiple new simple precompiles are introduced, or a single new complex precompile is introduced (dynamic input length or dynamic gas cost).
    3
    Multiple new precompiles are introduced, and at least one of them is complex (dynamic input length or dynamic gas cost).
    • Cryptography precompiles are not considered complex by default. Refer to the "Cryptography" for a separate assessment.
  • Modified precompiles
    Modifies pre-existing precompiles logic or gas-accounting
    Score anchors
    0
    No pre-existing precompiles are modified.
    1
    At least one pre-existing precompile has its gas schedule modified.
    2
    Multiple pre-existing precompiles have their gas schedule modified, or a single pre-existing precompile has its behavior modified.
    3
    The behavior of multiple pre-existing precompiles, or a single complex pre-existing precompile modified.
  • Added system contracts
    Introduces new system contract, stateful or not
    Score anchors
    0
    No new system contracts are introduced.
    1
    A new system contract is introduced that is not stateful nor does it trigger a new system action (e.g. requests to the consensus layer).
    2
    Multiple new system contracts are introduced or a single new system contract that is either stateful or triggers a new system action (e.g. requests to the consensus layer).
    3
    Multiple new system contracts are introduced and at least one of them is either stateful or triggers a new system action (e.g. requests to the consensus layer).
  • Modified system contracts
    Modifies pre-existing system contracts
    Score anchors
    0
    No modifications to pre-existing system contracts are introduced, directly or indirectly.
    1
    Does not directly modify any system contract, but its behavior has minor indirect effects on one or more system contracts.
    2
    Does not directly modify any system contract, but its behavior has major indirect effects on one or more system contracts.
    3
    At least one pre-existing system contract code or state is modified, which would involve irregular state transition or a similarly complex transition methodology.

Gas and accounting

Execution, blob, and state gas rules, refunds, and where charges happen inside opcodes.

  • EVM Gas rule changes
    New EVM gas accounting rules
    Score anchors
    0
    No gas accounting changes.
    1
    Existing gas accounting mechanism is updated.
    2
    A new gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State-access ordering within opcode execution · not in checklist revision 1
    Changes *where inside an opcode's execution* state is accessed, or where gas is charged relative to that access. Because a state access is recorded in the block-level access list only if execution had enough gas to reach it, this ordering is consensus-critical: moving it changes the BAL at every gas boundary of every affected opcode.
    Score anchors
    0
    No change to where state is accessed, or to where gas is charged relative to a state access, within any opcode.
    1
    A single opcode's state-access or gas-charge ordering changes.
    2
    Multiple opcodes' ordering changes, or a new state-accessing operation is introduced whose position in the order must be settled.
    3
    The ordering rule changes for a whole class of state-accessing opcodes at once, or what counts as a recordable state access is redefined — requiring existing BAL vectors to be re-derived across opcodes and forks.
    • Distinct from "Modified opcodes", which asks whether an opcode's **result** changed. This row asks about the **path to the result**, which is observable even when the result is identical. An EIP can be 0 on that row and 3 on this one.
    • Score changes **to** the ordering. Do not score the fact that state accesses are observable — they always are.
    • Each boundary must be re-tested against every other dimension that can change the answer (cold/warm, static/non-static, delegated/direct, revert/success), so the case count grows multiplicatively rather than additively. Note this explicitly under Special Considerations.
  • Blob gas accounting changes
    New Blob gas accounting rules which potentially affect pre-existing tests
    Score anchors
    0
    No blob gas accounting changes.
    1
    Existing blob gas accounting mechanism is updated.
    2
    A new blob gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new blob gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State gas accounting changes · not in checklist revision 1
    New state gas accounting rules. State gas is the cost of *writing* state, as opposed to accessing or executing it: `StateGasCosts`, `COST_PER_STATE_BYTE`, the block-level state gas budget, and the spill path into execution gas.
    Score anchors
    0
    No state gas accounting changes.
    1
    An existing state gas cost or `STATE_BYTES_PER_*` rate is adjusted.
    2
    A new state-gas-charging site is introduced, or the block-level state gas budget or reservoir allocation is modified.
    3
    A new state gas charging mechanism is introduced, or the spill interaction between state gas and execution gas is modified, affecting existing gas tests.
    • Harder to test than blob gas: the spill path means state gas cannot be metered independently of execution gas, and some costs (e.g. `NEW_ACCOUNT`) are state-dependent.
  • New EVM gas refund
    New gas-refund mechanism
    Score anchors
    0
    No new gas-refund mechanisms are introduced.
    1
    A new simple gas-refund mechanism is introduced that does not affect either existing tests or existing gas-refund mechanisms.
    2
    A new complex gas-refund mechanism is introduced or a simple mechanism that affects existing tests or existing gas-refund mechanisms.
    3
    A new complex gas-refund mechanism is introduced that affects existing tests or existing gas-refund mechanisms.

Blocks, transactions, and encoding

Transaction types and validity, block and header fields, encodings, syncing, and activation-time changes.

  • New transaction types
    Introduces a new transaction type
    Score anchors
    0
    No new transaction types are introduced.
    3
    A new transaction type is introduced.
  • New or modified transaction validity mechanisms
    Creates new or modifies pre-existing transaction types' validation mechanisms
    Score anchors
    0
    No changes are introduced to the validity rules of existing transaction types or to their intrinsic gas cost calculation.
    1
    Minor adjustments are introduced to validity rules or intrinsic gas cost calculation, but they do not significantly affect existing tests.
    2
    Changes to validity rules or intrinsic gas cost calculation affect existing tests, but require only limited updates to test cases and no redesign of the testing infrastructure.
    3
    Changes to validity rules or intrinsic gas cost calculation require extensive rework or redesign of the tests or testing infrastructure.
  • New block / header fields
    Introduces new block or block header fields
    Score anchors
    0
    No new block or header fields are introduced.
    3
    A new block or header field is introduced.
  • Encoding changes (RLP/SSZ)
    Introduces encoding changes at the transaction/block/interfaces level
    Score anchors
    0
    No encoding changes are introduced at the transaction, block, or interfaces levels.
    3
    An encoding change is introduced at transaction, block or interfaces level (e.g. RLP -> SSZ).
    • "Interfaces level" includes the Engine API. Score an Engine API encoding change (e.g. JSON -> SSZ) here.
  • Block syncing changes
    Modifies block RLP validation mechanisms that require test client syncing.
    Score anchors
    0
    No new RLP validation mechanism is introduced.
    1
    A single simple RLP validation mechanism is introduced.
    2
    Multiple simple RLP validation mechanisms are introduced or a single complex one.
    3
    Multiple RLP validation mechanisms are introduced and at least one of them is deemed complex.
  • New fork activation mechanism
    Modifies state, internal variables, or similar, at the fork activation block
    Score anchors
    0
    No state modifications, internal variables or similar are modified at the fork activation block.
    3
    Either a state modification or internal variables are modified at the fork activation block.
    • Initialization of new internal variable is not considered a modification.

Client interfaces

Engine API and transition-tool interface changes.

  • Engine API changes
    Introduces new fields to the Engine API directives
    Score anchors
    0
    No new fields or communication mechanisms are introduced to the Engine API.
    1
    A single new field is introduced in one of the Engine API endpoints.
    2
    Multiple fields are introduced to one or multiple Engine API end points, or a new Engine API end-point is introduced.
    3
    Multiple fields are introduced to one or multiple Engine API end points and a new Engine API end-point is introduced.
  • Engine API encoding changes · Checklist revision 1 only
    Engine API encoding changes (the revision-1 template defines no anchor text for this row).
  • Transition-tool interface changes
    Modifies or adds new fields to the transition tool interface.
    Score anchors
    0
    No modifications to the transition tool interface are required.
    1
    A single new field needs to be introduced to the transition tool interface.
    2
    Multiple new fields or a new mechanism has to be introduced to the transition tool interface.
    3
    Multiple new fields and a new mechanism has to be introduced to the transition tool interface.
    • Special consideration must be paid to this section if the EIP introduces a mechanism that requires the state transition tool to be aware whether the block it is processing is the fork-activation block.

Testing impact

Rework, new invariants, and new primitives required in the test framework.

  • Patterns affecting pre-existing tests
    Implements a new validation mechanism or rule that translates in reworking pre-existing tests
    Score anchors
    0
    No pre-existing tests are affected by this change.
    1
    Minor subset of existing tests are affected by this change.
    2
    Considerable subset of existing tests are affected by this change but involves only a contrived category of tests.
    3
    Major subset of existing tests are affected, including diverse category of tests (benchmarks, static, multiple forks, etc.).
  • New invariant on pre-existing tests · not in checklist revision 1
    Tests that are **not about this EIP** must nonetheless assert something this EIP produces. Their logic does not change; they gain a new thing to check.
    Score anchors
    0
    Pre-existing tests assert nothing new.
    1
    A narrow, contrived category of pre-existing tests gains a new assertion.
    2
    A broad category gains a new assertion, applied mechanically.
    3
    Every test in the fork gains the assertion regardless of what it tests, and pre-fork vectors must be re-derived to satisfy it.
    • Paired with the row above, and easy to confuse with it. "Patterns affecting pre-existing tests" asks whether existing tests must be **reworked**; this row asks whether they must **additionally assert something new**. Score both — an EIP can be low on one and high on the other.
  • New test-framework primitives · not in checklist revision 1
    Requires new abstractions in the test framework itself — expectation types, modifiers, helpers — beyond writing test functions with what already exists.
    Score anchors
    0
    Existing test primitives suffice.
    1
    Existing primitives need minor extension.
    2
    New expectation or modifier primitives are required, reusable within this EIP's own test suite.
    3
    New framework-level primitives are required that become a permanent part of the framework and are used by other EIPs' tests.

Risk and validation

Security, performance, boundary conditions, and cryptography that need validation.

  • Security risks
    Introduces or modifies mechanisms that could compromise the security of the chain, users, validators, or other stakeholders, if not implemented properly.
    Score anchors
    0
    No new mechanisms are introduced that could pose a security risk.
    1
    The introduced mechanisms are self-contained, can be validated in isolation, and do not alter existing invariants that could pose a security risk for any stakeholders.
    2
    The introduced mechanisms interact with a limited number of existing components, slightly altering their security assumptions and requiring a targeted security review or fuzzing.
    3
    The introduced mechanisms interact with multiple existing components, including critical ones, substantially altering their security assumptions and requiring an extensive security review and fuzzing.
  • Performance risks
    Introduces or modifies mechanisms and requires performance validation.
    Score anchors
    0
    No new mechanisms are introduced that require performance validation.
    1
    The introduced mechanisms can be benchmarked in isolation and do not affect existing performance behavior.
    2
    The introduced mechanisms cannot be fully benchmarked in isolation, but they only have a limited impact on the existing performance benchmarks.
    3
    The introduced mechanisms cannot be benchmarked in isolation and have a substantial impact on existing performance benchmarks or have complex interactions with existing mechanisms.
  • Edge/boundary conditions
    Feature contains edge/boundary conditions.
    Score anchors
    0
    No discernible edge cases or boundary conditions are introduced.
    1
    A single edge-case or boundary-condition prone mechanism is introduced.
    2
    Multiple edge-case or boundary-condition prone mechanisms are introduced, but none of them requires an elevated number of cases to test.
    3
    Multiple edge-case or boundary-condition prone mechanisms are introduced and at least one of them requires an elevated number of cases to test.
  • Cryptography
    Introduces new cryptography mechanisms or modifies existing functionality that involves cryptography
    Score anchors
    0
    No cryptography mechanisms are introduced.
    1
    A new cryptography mechanism is introduced but it is a well known mechanism that is known to have vast resources to aid on its testing.
    2
    Multiple new cryptography mechanisms are introduced that are well-known or a single but novel mechanism is introduced that is either untested or has limited resources.
    3
    Multiple new cryptography mechanisms are introduced and at least one of them is a novel mechanism.

Coordination

Cross-EIP interactions and behavior that clients must agree on before tests exist.

  • Cross-EIP interactions
    Introduces or modifies mechanisms that affect other EIPs in either the same or past forks.
    Score anchors
    0
    Fully self-contained EIP that does not depend on, modify, or conflict with any other EIP.
    1
    The EIP interacts with one or more other EIPs in a non-critical and limited way but can be tested independently for the most part.
    2
    The EIP depends on or modifies one or more other EIPs such that coordinated testing and consideration is required, but interactions are limited in scope and not complex.
    3
    The EIP has strong interdependencies with multiple EIPs, requiring extensive coordinated cross-EIP testing as well as potential re-design of existing test vectors.
    • +1 for every 3 additional interacting EIPs beyond the first 3, each of which requires its own coordinated test cases. List the EIPs in the rationale.
    • This row is intentionally uncapped, unlike every other anchor: each interacting EIP is another axis of the test matrix, so a ceiling would make a 12-EIP product indistinguishable from a 3-EIP one.
  • Unspecified behavior requiring cross-client consensus · not in checklist revision 1
    The EIP text does not determine the answer for cases a test can construct. Clients must agree on a previously unspecified detail before tests can be baselined. The cost here is coordination and re-baselining, not test writing.
    Score anchors
    0
    The EIP text determines the answer for every case a test could construct.
    1
    A few details are unspecified but have an obvious intended reading.
    2
    Details require client agreement before tests can be written, but they are localized.
    3
    A previously unspecified *and previously unobservable* behavior becomes consensus-critical; expect tests to be re-baselined on each round of EIP amendment.
    • Score this from the EIP's state at assessment time: whether it has client implementations, whether it has been through a devnet, and how many open questions remain on its discussion thread.