Retrospective LLM-Based Complexity Evaluations

EIP complexity assessment

EIP-4895: Beacon chain push withdrawals as operations

Assessed in Shanghai / Shapella. The score describes the EIP text available at the assessment cutoff, not the EIP as it stands today.

RetrospectiveShanghai / ShapellaAssessment cutoff 2022-03-11Included by cutoffLayers: execution, consensus
LLM Completescore 26
Human Not available· Human complexity assessments were not produced for this fork; only the LLM assessment exists.

LLM assessment

Evaluated on: · Spec revision: 2022-03-11 · 1ce607ac37

Scope at the cutoff. At the supplied revision, EIP-4895 adds a new block-level "operation", the `Withdrawal`. Each withdrawal is RLP([index uint64, address 20 bytes, amount uint256 wei]) and is supplied by the consensus layer. Blocks gain a `withdrawals` list, and the header gains a `withdrawals_root` commitment built like the transactions root (an MPT keyed by list position), with a new block-validity check that the two match. From `FORK_TIMESTAMP` onward, withdrawals are processed after all user transactions as unconditional, gas-free balance increases that MUST NOT fail. Whether withdrawals emit logs or receipts is left as a TODO.

26HighHigh
Evaluator
LLMChecklist v3
Confidence
Medium
Under-specified at assessment cutoff
Yes — 5 criteria affected
Plausible range
22–30 (Medium–High)
Assessment cutoff
2022-03-11 · EIP revision 1ce607ac37 (2022-03-11)
Score bands · Checklist revision 3
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the LLM total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. New block / header fields3
  2. Encoding changes (RLP/SSZ)3
  3. Block syncing changes3
  4. Engine API changes2

Under-specified at assessment cutoff: Yes

The EIP text available at the assessment cutoff left material behavior unresolved. The affected criteria and the plausible total range record that uncertainty.

Why: This draft leaves several consensus-visible details open. Logs and receipts for withdrawals are an explicit TODO. Element positions in the block and header RLP lists are not given. It does not say whether the EL validates index monotonicity or bounds the withdrawal count. Zero-amount and empty-account semantics, and amount overflow, are unspecified. The Engine API transport for withdrawals is not specified, although CL supply is required.

Unresolved questions at the cutoff (7)
  • Do withdrawals emit logs or receipts, and is there a receipts commitment for them?
  • Must the EL validate that withdrawal indices are monotonically increasing or contiguous across blocks?
  • What is the maximum number of withdrawals per block, and must the EL enforce it?
  • Does a zero-amount withdrawal to a nonexistent account create or touch it, and how do empty-account deletion rules apply?
  • Where do withdrawals and withdrawals_root sit in the block and header RLP lists, and how is their absence or presence validated around FORK_TIMESTAMP?
  • How are withdrawals transported over the Engine API for payload validation and for block building?
  • What happens if a credit would overflow a 256-bit balance, given that the operation MUST NOT fail?
Notable ambiguities noted by the assessor (6)
  • The 'TODO: add logs?' in State transition leaves the receipt structure undecided.
  • The state transition uses lowercase 'should increase the balance' but follows it with 'MUST not fail'.
  • Block validity begins with 'Assuming the block is well-formatted' without defining the well-formedness rules for the new fields.
  • The index is described as 'monotonically increasing', but no EL validation of this is stated.
  • The rationale calls withdrawals a 'new transaction type' in a heading, while the specification defines them as non-transaction operations.
  • The count bound on withdrawals is enforced only by the CL, per the rationale; no EL-side limit is given.

Criterion breakdown

EIP-4895 Shanghai / Shapella: LLM criterion scores and rationale
CriterionScoreWhy this scoreEvidence / uncertainty
New block / header fields3The execution header gains withdrawals_root, and the block body gains a withdrawals member.
  • eip.md · Commitment to withdrawals — "block_header.withdrawals_root" New execution header member.
  • eip.md · New field in the execution block: withdrawals New block-level member, `block.withdrawals`.
Confidence: High
Encoding changes (RLP/SSZ)3Block and header schemas gain serialized fields, and a new Withdrawal RLP object is defined.
  • eip.md · System-level operation: withdrawal — "`RLP([index, address, amount])`" New RLP schema for the Withdrawal object.
  • eip.md · New field in the execution block: withdrawals The block RLP gains a withdrawals list.
  • eip.md · Commitment to withdrawals The header RLP gains withdrawals_root.
Confidence: High
Uncertainty: The exact position of the new elements within the block and header lists is not specified.
Block syncing changes3Several structural rules change: body decoding with the new withdrawals list, header decoding with the new field (timestamp-gated presence), and Withdrawal element decoding. The root-matches-body check depends on another field (the body list), so at least one rule is complex. That is level 3.
  • eip.md · New field in the execution block: withdrawals New RLP body element that must be decoded during import.
  • eip.md · Commitment to withdrawals New header field.
  • eip.md · Block validity — "ensure that the `withdrawals_root` matches the expected value" A cross-field validation of the header commitment against the body contents.
Confidence: High
Engine API changesUnder-specified2The withdrawals list has to cross the EL/CL boundary in executed payloads and in build requests. That is one distinct semantic field, and in practice new or versioned payload exchange behavior. Endpoint behavior with at most one field change is level 2.
  • eip.md · System-level operation: withdrawal — "three key pieces of information supplied from the consensus layer" The CL must deliver withdrawals to the EL, both for payload validation and for block building.
Confidence: Low
Uncertainty: This revision does not specify the Engine API at all. The endpoint and field shape is inferred from the requirement that the CL supply the withdrawals.
Transition-tool interface changesUnder-specified2The transition tool needs a new input (the withdrawals list, applied after transactions). By analogy with the transactions root, it also plausibly needs a new output, withdrawalsRoot. That makes multiple semantic fields with no new exchange mechanism, which is level 2.
  • eip.md · System-level operation: withdrawal — "supplied from the consensus layer" The state transition needs a withdrawals list as an input that is not a transaction.
  • eip.md · Commitment to withdrawals — "constructed identically to the transactions root" A new root is computed analogously to the transactions root, which the transition tool produces.
Confidence: Medium
Uncertainty: No transition-tool documentation was supplied. If the framework computes the root itself, only the input field changes (level 1).
New invariant on pre-existing tests2Every blockchain/import test in the fork has to produce and check the new header commitment, even when its withdrawals list is empty. Because activation is gated by fork timestamp, pre-fork vectors do not need to be re-derived. Under the template's note, a universal assertion without pre-fork vector changes is level 2.
  • eip.md · Block validity — "assert block_header.withdrawals_root == compute_trie_root_from_indexed_data(block.withdrawals)" Every post-fork block must carry a correct withdrawals_root commitment, including over an empty list.
  • eip.md · Specification — "Beginning with the execution timestamp `FORK_TIMESTAMP`" The rule is timestamp-gated, so pre-fork vectors are unaffected.
Confidence: High
Uncertainty: If the logs/receipts TODO were resolved by adding receipts for withdrawals, a further commitment assertion would follow. That would still be level 2.
New test-framework primitives2The framework needs a Withdrawal construction abstraction, block builders that attach withdrawals and compute withdrawals_root, and post-state balance expectations driven by withdrawals. These are new construction and expectation abstractions within the target's suite. Other families only see an empty default list, so level 3 is not met.
  • eip.md · System-level operation: withdrawal A new block-level object type that is distinct from transactions.
  • eip.md · New field in the execution block: withdrawals Blocks must be built with a withdrawals list and a matching root.
Confidence: Medium
Security risks2The EL now credits ETH on CL authority, which changes EL supply and balance assumptions at the CL/EL trust boundary. It also adds a new path for balance changes without code execution that contracts may not expect, though coinbase credits are an existing analog. This bounded cross-layer interaction needs targeted integration review and fuzzing of the withdrawals commitment and processing.
  • eip.md · Security Considerations — "does not have a current analog in the EVM and thus deserves very high security scrutiny" A new ETH issuance path from the CL into EL balances.
  • eip.md · State transition — "unconditional and **MUST** not fail" Unconditional credits to any address, without EVM execution.
Confidence: Medium
Edge/boundary conditionsUnder-specified2There are several independent boundary-sensitive rules: the fork-timestamp activation boundary for the block/header structure; field-width bounds on index and amount in decoding; and the amount/recipient boundaries (zero amount, nonexistent or empty recipient, list empty versus many). No interacting matrix whose combinations change the result is clearly established, so this is level 2.
  • eip.md · Specification — "Beginning with the execution timestamp `FORK_TIMESTAMP`" There is a timestamp boundary for when the withdrawals field and rules apply.
  • eip.md · System-level operation: withdrawal — "`index` as a `uint64` ... `amount` ... 256-bit value" Field-width bounds for index and amount, including zero and maximum values.
  • eip.md · State transition — "This balance change is unconditional and **MUST** not fail." Boundary outcomes for amount zero, credits to nonexistent or empty accounts, and large amounts.
Confidence: Medium
Uncertainty: How zero-amount credits to empty accounts behave, and whether amount overflow is possible, is unspecified. This could create a combined matrix (amount × account state × same-block transaction effects).
Unspecified behavior requiring cross-client consensus2Several localized outcomes have competing interpretations: logs and receipts (observable through the receipts root), EL enforcement of index monotonicity, empty-account creation or touch semantics for zero amounts, and the element positions in the block and header. These need specification agreement before expected results can be fixed. They are localized rather than a cross-family re-baselining.
  • eip.md · State transition — "TODO: add logs? this implies receipt structure for the withdrawals and a commitment to the list of receipts" Whether withdrawals produce logs, receipts or an extra commitment is unresolved.
  • eip.md · System-level operation: withdrawal — "a monotonically increasing `index`" The spec does not say whether the EL must validate index monotonicity.
  • eip.md · State transition — "the implementation should increase the balance" Treatment of zero-amount credits to empty or nonexistent accounts, and of overflow, is not specified.
Confidence: Medium
Uncertainty: Empty-account semantics might be defined by baseline rules that were not supplied (an evidence gap rather than a pure omission).
Patterns affecting pre-existing testsUnder-specified1Baseline header and block-structure validation cases (for example field-count and malformed-header RLP cases, and fork-transition block shapes) need reworked inputs and expectations for post-fork blocks. This is confined to one family: block structure/import validation. Ordinary state-execution tests keep their behavior. The new commitment value itself is counted under INV.
  • eip.md · Commitment to withdrawals — "The execution block header gains a new field" Post-fork headers carry an extra field, so Paris-shaped headers become structurally invalid after the fork.
  • eip.md · New field in the execution block: withdrawals The block body gains a new list element.
Confidence: Medium
Uncertainty: Whether regenerating block hashes in every post-fork blockchain test counts as rework or only as the new-commitment assertion is a matter of interpretation. I attribute it to INV.
Performance risksUnder-specified1The new workload consists of gas-free balance credits and the withdrawals trie root, outside gas-limit bounds. Component benchmarks of processing the maximum withdrawal count are enough, since the rationale states the cost is negligible next to block execution.
  • eip.md · Rationale — "Why no (gas) costs ..." — "bounded (enforced by the consensus layer) and this limit is kept small" Withdrawal work is not gas-metered, and the EL relies on a CL-enforced count bound.
Confidence: Medium
Uncertainty: The maximum count is not given in the supplied text. A large bound could require integrated benchmarks; a trivially small one might need none.
Cross-EIP interactions1The target interacts with existing block-processing behavior, needing local compatibility checks: credits to the coinbase after fee crediting, to accounts destroyed or created earlier in the block, and to empty accounts. Its core behavior can otherwise be tested on its own. EIP-4863 is a superseded alternative, and EIP-4788 is a cited alternative not established in the same-fork scenario, so neither needs target-specific cases.
  • eip.md · State transition — "processed **after** any user-level transactions are applied" Withdrawal credits apply after transaction effects such as fee payments and account deletions.
  • eip.md · Motivation — "more involved than the prior EIP-4863"; "pull-based alternatives (e.g. EIP-4788 ...)" EIP-4788 and EIP-4863 are cited as alternative designs, not as prerequisites or co-scheduled mechanisms.
Confidence: Medium
Uncertainty: If EIP-4788 were scheduled in the same fork, block-start beacon-root writes and block-end withdrawals would need joint block-structure and processing checks. The supplied text does not establish that scenario.
Show 15 zero-score criteria
Zero-score criteria (Checklist revision 3)
CriterionScoreWhy this scoreEvidence / uncertainty
Added opcodes0No new opcode.
  • eip.md · Specification No new instruction is defined.
Modified opcodes0No instruction's semantics or availability change.
  • eip.md · Rationale — "firewalls off generic EVM execution" Withdrawals involve no EVM execution and change no opcode semantics.
Added precompiles0No new precompile.
  • eip.md · Specification No precompile is defined.
Modified precompiles0No precompile changes.
  • eip.md · Specification No precompile is changed.
Added system contracts0No system contract is introduced.
  • eip.md · Rationale — "Why only balance updates? No general EVM execution?" Only balance updates are applied. No protocol contract is introduced.
Modified system contracts0No system contract exists in the baseline, and none is modified.
  • eip.md · State transition No existing system contract is touched.
EVM Gas rule changes0No execution-gas charging, metering, limit or settlement rule changes. Withdrawals sit outside gas accounting entirely.
  • eip.md · State transition — "This operation has no associated gas costs." Withdrawals do not consume or change execution gas. Transaction gas accounting is untouched.
State-access ordering within opcode execution0No opcode's state-access or gas-charge ordering changes. The withdrawal balance credit is a block-level operation, not an instruction, and there is no access-list concept involved.
  • eip.md · State transition — "processed **after** any user-level transactions" The ordering is at block level (withdrawals after transactions), not inside any instruction.
Blob gas accounting changes0No blob-gas accounting rule changes.
  • eip.md · Specification Nothing in the spec relates to blobs or blob gas.
State gas accounting changes0No state-gas mechanism, rate or budget is introduced or changed.
  • eip.md · State transition — "no associated gas costs" The balance writes carry no state-gas charge.
New EVM gas refund0No refund mechanism is introduced.
  • eip.md · State transition No refund mechanism is defined.
New transaction types0Withdrawals are not in the transaction list and have no EIP-2718 discriminator. This contrasts with the EIP-4863 alternative.
  • eip.md · Rationale — "Why not a new transaction type?" Withdrawals are explicitly a separate operation type, not a transaction envelope.
New or modified transaction validity mechanisms0No transaction validity rules change.
  • eip.md · State transition Withdrawals are applied after transactions and do not alter transaction eligibility or intrinsic gas.
New fork activation mechanism0There is no one-time state conversion or code installation at activation. Timestamp-based rule selection and starting recurring withdrawal processing do not count.
  • eip.md · Specification — "`FORK_TIMESTAMP` | TBD" Activation is selected by timestamp, and the spec describes no state migration.
Cryptography0An existing primitive and commitment scheme are reused unchanged. No cryptographic verification or rule changes.
  • eip.md · Commitment to withdrawals — "constructed identically to the transactions root" The spec reuses the existing Merkle-Patricia trie and Keccak hashing unchanged.
Assessment provenance
Assessed EIP revision
ethereum/EIPs@1ce607ac37 EIPS/eip-4895.md committed 2022-03-11 · information cutoff 2022-03-11T12:28:57Z
Current master · File history · blob 20168103d6 · sha256 34436435c8cd
Rubric
Checklist revision 3 · ethspecs/pm@fe2f793b03
Evaluator
Opus 5.5 (claude-opus-5-5) at high effort, one tool-less call per EIP · isolation bubblewrap_claude_p_no_tools_v1
Source record
Frozen research record research/tasks/10-opus-v3-reassessment/retrospective/outputs/assessments/shanghai/eip-4895.yaml · sha256 6f7400ba7c34
Supporting documents supplied with the EIP
supporting/eip-4788.md, supporting/eip-4863.md
Criterion legend and glossary

Every stacked bar, comparison matrix, and criterion table on this site uses the same criterion colours, abbreviations, and order. Colour marks the criterion group; the abbreviation and name identify the criterion. Scores are 0–3 per criterion (4 is exceptional; cross-EIP interactions is uncapped).

EVM surface

Opcodes, precompiles, and system contracts that are added or modified.

  • Added opcodes
    Introduces new opcodes
    Score anchors
    0
    No new opcodes are introduced.
    1
    A new simple opcode is introduced (no data portion, no complex stack mechanics, and a constant gas cost).
    2
    Multiple new simple opcodes are introduced, or a single new complex opcode is introduced (has data portion, or complex stack mechanics, or a dynamic gas cost).
    3
    Multiple new opcodes are introduced, and at least one of them is complex (has data portion, or complex stack mechanics, or a dynamic gas cost).
    • Cryptography opcodes are not considered complex by default. Refer to the "Cryptography" section for a separate assessment.
  • Modified opcodes
    Modifies pre-existing opcodes
    Score anchors
    0
    No pre-existing opcode modifications are introduced.
    3
    At least one pre-existing opcode's behavior is modified (not including gas changes) or a pre-existing opcode is deprecated.
  • Added precompiles
    Introduces new precompiles
    Score anchors
    0
    No new precompiles are introduced.
    1
    A new simple precompile is introduced (constant input length, constant gas cost).
    2
    Multiple new simple precompiles are introduced, or a single new complex precompile is introduced (dynamic input length or dynamic gas cost).
    3
    Multiple new precompiles are introduced, and at least one of them is complex (dynamic input length or dynamic gas cost).
    • Cryptography precompiles are not considered complex by default. Refer to the "Cryptography" for a separate assessment.
  • Modified precompiles
    Modifies pre-existing precompiles logic or gas-accounting
    Score anchors
    0
    No pre-existing precompiles are modified.
    1
    At least one pre-existing precompile has its gas schedule modified.
    2
    Multiple pre-existing precompiles have their gas schedule modified, or a single pre-existing precompile has its behavior modified.
    3
    The behavior of multiple pre-existing precompiles, or a single complex pre-existing precompile modified.
  • Added system contracts
    Introduces new system contract, stateful or not
    Score anchors
    0
    No new system contracts are introduced.
    1
    A new system contract is introduced that is not stateful nor does it trigger a new system action (e.g. requests to the consensus layer).
    2
    Multiple new system contracts are introduced or a single new system contract that is either stateful or triggers a new system action (e.g. requests to the consensus layer).
    3
    Multiple new system contracts are introduced and at least one of them is either stateful or triggers a new system action (e.g. requests to the consensus layer).
  • Modified system contracts
    Modifies pre-existing system contracts
    Score anchors
    0
    No modifications to pre-existing system contracts are introduced, directly or indirectly.
    1
    Does not directly modify any system contract, but its behavior has minor indirect effects on one or more system contracts.
    2
    Does not directly modify any system contract, but its behavior has major indirect effects on one or more system contracts.
    3
    At least one pre-existing system contract code or state is modified, which would involve irregular state transition or a similarly complex transition methodology.

Gas and accounting

Execution, blob, and state gas rules, refunds, and where charges happen inside opcodes.

  • EVM Gas rule changes
    New EVM gas accounting rules
    Score anchors
    0
    No gas accounting changes.
    1
    Existing gas accounting mechanism is updated.
    2
    A new gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State-access ordering within opcode execution · not in checklist revision 1
    Changes *where inside an opcode's execution* state is accessed, or where gas is charged relative to that access. Because a state access is recorded in the block-level access list only if execution had enough gas to reach it, this ordering is consensus-critical: moving it changes the BAL at every gas boundary of every affected opcode.
    Score anchors
    0
    No change to where state is accessed, or to where gas is charged relative to a state access, within any opcode.
    1
    A single opcode's state-access or gas-charge ordering changes.
    2
    Multiple opcodes' ordering changes, or a new state-accessing operation is introduced whose position in the order must be settled.
    3
    The ordering rule changes for a whole class of state-accessing opcodes at once, or what counts as a recordable state access is redefined — requiring existing BAL vectors to be re-derived across opcodes and forks.
    • Distinct from "Modified opcodes", which asks whether an opcode's **result** changed. This row asks about the **path to the result**, which is observable even when the result is identical. An EIP can be 0 on that row and 3 on this one.
    • Score changes **to** the ordering. Do not score the fact that state accesses are observable — they always are.
    • Each boundary must be re-tested against every other dimension that can change the answer (cold/warm, static/non-static, delegated/direct, revert/success), so the case count grows multiplicatively rather than additively. Note this explicitly under Special Considerations.
  • Blob gas accounting changes
    New Blob gas accounting rules which potentially affect pre-existing tests
    Score anchors
    0
    No blob gas accounting changes.
    1
    Existing blob gas accounting mechanism is updated.
    2
    A new blob gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new blob gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State gas accounting changes · not in checklist revision 1
    New state gas accounting rules. State gas is the cost of *writing* state, as opposed to accessing or executing it: `StateGasCosts`, `COST_PER_STATE_BYTE`, the block-level state gas budget, and the spill path into execution gas.
    Score anchors
    0
    No state gas accounting changes.
    1
    An existing state gas cost or `STATE_BYTES_PER_*` rate is adjusted.
    2
    A new state-gas-charging site is introduced, or the block-level state gas budget or reservoir allocation is modified.
    3
    A new state gas charging mechanism is introduced, or the spill interaction between state gas and execution gas is modified, affecting existing gas tests.
    • Harder to test than blob gas: the spill path means state gas cannot be metered independently of execution gas, and some costs (e.g. `NEW_ACCOUNT`) are state-dependent.
  • New EVM gas refund
    New gas-refund mechanism
    Score anchors
    0
    No new gas-refund mechanisms are introduced.
    1
    A new simple gas-refund mechanism is introduced that does not affect either existing tests or existing gas-refund mechanisms.
    2
    A new complex gas-refund mechanism is introduced or a simple mechanism that affects existing tests or existing gas-refund mechanisms.
    3
    A new complex gas-refund mechanism is introduced that affects existing tests or existing gas-refund mechanisms.

Blocks, transactions, and encoding

Transaction types and validity, block and header fields, encodings, syncing, and activation-time changes.

  • New transaction types
    Introduces a new transaction type
    Score anchors
    0
    No new transaction types are introduced.
    3
    A new transaction type is introduced.
  • New or modified transaction validity mechanisms
    Creates new or modifies pre-existing transaction types' validation mechanisms
    Score anchors
    0
    No changes are introduced to the validity rules of existing transaction types or to their intrinsic gas cost calculation.
    1
    Minor adjustments are introduced to validity rules or intrinsic gas cost calculation, but they do not significantly affect existing tests.
    2
    Changes to validity rules or intrinsic gas cost calculation affect existing tests, but require only limited updates to test cases and no redesign of the testing infrastructure.
    3
    Changes to validity rules or intrinsic gas cost calculation require extensive rework or redesign of the tests or testing infrastructure.
  • New block / header fields
    Introduces new block or block header fields
    Score anchors
    0
    No new block or header fields are introduced.
    3
    A new block or header field is introduced.
  • Encoding changes (RLP/SSZ)
    Introduces encoding changes at the transaction/block/interfaces level
    Score anchors
    0
    No encoding changes are introduced at the transaction, block, or interfaces levels.
    3
    An encoding change is introduced at transaction, block or interfaces level (e.g. RLP -> SSZ).
    • "Interfaces level" includes the Engine API. Score an Engine API encoding change (e.g. JSON -> SSZ) here.
  • Block syncing changes
    Modifies block RLP validation mechanisms that require test client syncing.
    Score anchors
    0
    No new RLP validation mechanism is introduced.
    1
    A single simple RLP validation mechanism is introduced.
    2
    Multiple simple RLP validation mechanisms are introduced or a single complex one.
    3
    Multiple RLP validation mechanisms are introduced and at least one of them is deemed complex.
  • New fork activation mechanism
    Modifies state, internal variables, or similar, at the fork activation block
    Score anchors
    0
    No state modifications, internal variables or similar are modified at the fork activation block.
    3
    Either a state modification or internal variables are modified at the fork activation block.
    • Initialization of new internal variable is not considered a modification.

Client interfaces

Engine API and transition-tool interface changes.

  • Engine API changes
    Introduces new fields to the Engine API directives
    Score anchors
    0
    No new fields or communication mechanisms are introduced to the Engine API.
    1
    A single new field is introduced in one of the Engine API endpoints.
    2
    Multiple fields are introduced to one or multiple Engine API end points, or a new Engine API end-point is introduced.
    3
    Multiple fields are introduced to one or multiple Engine API end points and a new Engine API end-point is introduced.
  • Engine API encoding changes · Checklist revision 1 only
    Engine API encoding changes (the revision-1 template defines no anchor text for this row).
  • Transition-tool interface changes
    Modifies or adds new fields to the transition tool interface.
    Score anchors
    0
    No modifications to the transition tool interface are required.
    1
    A single new field needs to be introduced to the transition tool interface.
    2
    Multiple new fields or a new mechanism has to be introduced to the transition tool interface.
    3
    Multiple new fields and a new mechanism has to be introduced to the transition tool interface.
    • Special consideration must be paid to this section if the EIP introduces a mechanism that requires the state transition tool to be aware whether the block it is processing is the fork-activation block.

Testing impact

Rework, new invariants, and new primitives required in the test framework.

  • Patterns affecting pre-existing tests
    Implements a new validation mechanism or rule that translates in reworking pre-existing tests
    Score anchors
    0
    No pre-existing tests are affected by this change.
    1
    Minor subset of existing tests are affected by this change.
    2
    Considerable subset of existing tests are affected by this change but involves only a contrived category of tests.
    3
    Major subset of existing tests are affected, including diverse category of tests (benchmarks, static, multiple forks, etc.).
  • New invariant on pre-existing tests · not in checklist revision 1
    Tests that are **not about this EIP** must nonetheless assert something this EIP produces. Their logic does not change; they gain a new thing to check.
    Score anchors
    0
    Pre-existing tests assert nothing new.
    1
    A narrow, contrived category of pre-existing tests gains a new assertion.
    2
    A broad category gains a new assertion, applied mechanically.
    3
    Every test in the fork gains the assertion regardless of what it tests, and pre-fork vectors must be re-derived to satisfy it.
    • Paired with the row above, and easy to confuse with it. "Patterns affecting pre-existing tests" asks whether existing tests must be **reworked**; this row asks whether they must **additionally assert something new**. Score both — an EIP can be low on one and high on the other.
  • New test-framework primitives · not in checklist revision 1
    Requires new abstractions in the test framework itself — expectation types, modifiers, helpers — beyond writing test functions with what already exists.
    Score anchors
    0
    Existing test primitives suffice.
    1
    Existing primitives need minor extension.
    2
    New expectation or modifier primitives are required, reusable within this EIP's own test suite.
    3
    New framework-level primitives are required that become a permanent part of the framework and are used by other EIPs' tests.

Risk and validation

Security, performance, boundary conditions, and cryptography that need validation.

  • Security risks
    Introduces or modifies mechanisms that could compromise the security of the chain, users, validators, or other stakeholders, if not implemented properly.
    Score anchors
    0
    No new mechanisms are introduced that could pose a security risk.
    1
    The introduced mechanisms are self-contained, can be validated in isolation, and do not alter existing invariants that could pose a security risk for any stakeholders.
    2
    The introduced mechanisms interact with a limited number of existing components, slightly altering their security assumptions and requiring a targeted security review or fuzzing.
    3
    The introduced mechanisms interact with multiple existing components, including critical ones, substantially altering their security assumptions and requiring an extensive security review and fuzzing.
  • Performance risks
    Introduces or modifies mechanisms and requires performance validation.
    Score anchors
    0
    No new mechanisms are introduced that require performance validation.
    1
    The introduced mechanisms can be benchmarked in isolation and do not affect existing performance behavior.
    2
    The introduced mechanisms cannot be fully benchmarked in isolation, but they only have a limited impact on the existing performance benchmarks.
    3
    The introduced mechanisms cannot be benchmarked in isolation and have a substantial impact on existing performance benchmarks or have complex interactions with existing mechanisms.
  • Edge/boundary conditions
    Feature contains edge/boundary conditions.
    Score anchors
    0
    No discernible edge cases or boundary conditions are introduced.
    1
    A single edge-case or boundary-condition prone mechanism is introduced.
    2
    Multiple edge-case or boundary-condition prone mechanisms are introduced, but none of them requires an elevated number of cases to test.
    3
    Multiple edge-case or boundary-condition prone mechanisms are introduced and at least one of them requires an elevated number of cases to test.
  • Cryptography
    Introduces new cryptography mechanisms or modifies existing functionality that involves cryptography
    Score anchors
    0
    No cryptography mechanisms are introduced.
    1
    A new cryptography mechanism is introduced but it is a well known mechanism that is known to have vast resources to aid on its testing.
    2
    Multiple new cryptography mechanisms are introduced that are well-known or a single but novel mechanism is introduced that is either untested or has limited resources.
    3
    Multiple new cryptography mechanisms are introduced and at least one of them is a novel mechanism.

Coordination

Cross-EIP interactions and behavior that clients must agree on before tests exist.

  • Cross-EIP interactions
    Introduces or modifies mechanisms that affect other EIPs in either the same or past forks.
    Score anchors
    0
    Fully self-contained EIP that does not depend on, modify, or conflict with any other EIP.
    1
    The EIP interacts with one or more other EIPs in a non-critical and limited way but can be tested independently for the most part.
    2
    The EIP depends on or modifies one or more other EIPs such that coordinated testing and consideration is required, but interactions are limited in scope and not complex.
    3
    The EIP has strong interdependencies with multiple EIPs, requiring extensive coordinated cross-EIP testing as well as potential re-design of existing test vectors.
    • +1 for every 3 additional interacting EIPs beyond the first 3, each of which requires its own coordinated test cases. List the EIPs in the rationale.
    • This row is intentionally uncapped, unlike every other anchor: each interacting EIP is another axis of the test matrix, so a ceiling would make a 12-EIP product indistinguishable from a 3-EIP one.
  • Unspecified behavior requiring cross-client consensus · not in checklist revision 1
    The EIP text does not determine the answer for cases a test can construct. Clients must agree on a previously unspecified detail before tests can be baselined. The cost here is coordination and re-baselining, not test writing.
    Score anchors
    0
    The EIP text determines the answer for every case a test could construct.
    1
    A few details are unspecified but have an obvious intended reading.
    2
    Details require client agreement before tests can be written, but they are localized.
    3
    A previously unspecified *and previously unobservable* behavior becomes consensus-critical; expect tests to be re-baselined on each round of EIP amendment.
    • Score this from the EIP's state at assessment time: whether it has client implementations, whether it has been through a devnet, and how many open questions remain on its discussion thread.