Retrospective LLM-Based Complexity Evaluations

EIP complexity assessment

EIP-7002: Execution layer triggerable withdrawals

Assessed in Prague / Pectra. The score describes the EIP text available at the assessment cutoff, not the EIP as it stands today.

RetrospectivePrague / PectraAssessment cutoff 2024-01-18Included by cutoffLayers: execution, consensus
LLM Completescore 31
Human Not available· Human complexity assessments were not produced for this fork; only the LLM assessment exists.

LLM assessment

Evaluated on: · Spec revision: 2023-06-29 · 28cbb0162f

Scope at the cutoff. This revision of EIP-7002 adds a stateful native precompile at an address not yet chosen (TBD). The precompile accepts a 48-byte validator_pubkey and a value-bearing CALL, checks an EIP-1559/4844-style exponential exit fee, increments a per-block exit count and appends (msg.sender, pubkey) to a storage queue. It then returns any overpayment through a CALL with a 2300-gas stipend. Starting at FORK_TIMESTAMP, the block body gets a new list of RLP-encoded exits and the header gets a new exits_root trie commitment. Block validity requires that the body exits equal the first min(queue length, 16) queue entries. End-of-block processing advances or resets the queue pointers, updates excess_exits against a target of 2 and resets the exit count. Gas cost and address are TBD, and the EL-side Engine API changes are only sketched through the consensus-layer ExecutionPayload.

31HighHigh
Evaluator
LLMChecklist v3
Confidence
Medium
Under-specified at assessment cutoff
Yes — 11 criteria affected
Plausible range
26–43 (High)
Assessment cutoff
2024-01-18 · EIP revision 28cbb0162f (2023-06-29)
Score bands · Checklist revision 3
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the LLM total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. New block / header fields3
  2. Encoding changes (RLP/SSZ)3
  3. Block syncing changes3
  4. Edge/boundary conditions3

Under-specified at assessment cutoff: Yes

The EIP text available at the assessment cutoff left material behavior unresolved. The affected criteria and the plausible total range record that uncertainty.

Why: Gas cost and address are TBD. The queue storage layout contradicts itself: a stride of 3 when writing versus 2 when reading, and pubkey reconstruction reads the wrong slots. The return_excess_payment call has the wrong arity. Failure semantics are unspecified for wrong input length, static/delegate calls, insufficient gas and a failed excess return, as are return data, address storage alignment and whether the precompile account must exist. Engine API changes are only implied by the CL sketch.

Unresolved questions at the cutoff (8)
  • Is the queue slot stride 3 (as written in insert_exit_to_queue) or 2 (as read in block validity), and how is the 48-byte pubkey read back?
  • How is the 20-byte source_address aligned within its 32-byte storage slot?
  • What is the precompile's gas cost, and is it fixed or dynamic?
  • What happens on input that is not exactly 48 bytes, under STATICCALL, DELEGATECALL or CALLCODE, or when the fee is insufficient (revert versus consuming all gas)?
  • Does a failed excess-return CALL revert the whole exit, including queue and count writes?
  • Must the precompile account be created or kept non-empty at activation, and does end-of-block processing touch it?
  • What Engine API methods and fields carry exits, and is exits_root included in the payload?
  • What return data, if any, does the precompile produce?
Notable ambiguities noted by the assessor (7)
  • The queue stride differs between insertion (*3) and validation (*2), and the pubkey reconstruction concatenates slot+1 four times.
  • trigger_exit calls return_excess_payment(msg.value), but the helper takes (fee_sent, source_address).
  • The exit fee compares msg.value against MIN_EXIT_FEE=1 with no units stated (presumably wei).
  • The rationale refers to the 'blob gas price', apparently carried over from EIP-4844.
  • excess_exits is updated from exit_count (calls made this block), not from the number of exits dequeued.
  • The relative order of the end-of-block update versus withdrawal processing is unspecified.
  • The supplied EIP-4788 revision describes a stateful precompile, which is the only evidence of how such a precompile behaves in the baseline.

Criterion breakdown

EIP-7002 Prague / Pectra: LLM criterion scores and rationale
CriterionScoreWhy this scoreEvidence / uncertainty
New block / header fields3The execution header gains exits_root and the block body gains an exits list.
  • eip.md · Block structure — "block header MUST be appended with the new exits_root field" Execution header field exits_root.
  • eip.md · Block structure — "block body MUST be appended with a list of exit operations" Block-level body member exits.
Confidence: High
Encoding changes (RLP/SSZ)3The block body RLP gains an exits list of a new exit RLP structure, and the header gains exits_root. Per the CL sketch, the ExecutionPayload SSZ also gains an exits list.
  • eip.md · Exit operation — rlp_encoded_exit New RLP object [source_address, validator_pubkey].
  • eip.md · Block structure — block_body_rlp and exits_root The block body and header schemas both gain a field.
Confidence: High
Block syncing changes3Several rules change: decoding of the new body list and header field, the exits_root consistency check, which depends on the body, and the equality with the state-derived queue. The latter two are complex, so this is level 3.
  • eip.md · Block structure — block_body_rlp A new exits list is appended to the block body RLP.
  • eip.md · Block validity — conditions 1 and 2 exits_root must equal the trie root of the body exits, and body exits must equal the queue head read from post-transaction state.
Confidence: High
Edge/boundary conditions3Several boundary-sensitive mechanisms are introduced: the fee threshold, the 16-exit dequeue cap, the target-2 excess update with its zero floor, the 48-byte input, the pointer reset on an empty queue, and the excess return (zero versus positive, and the stipend limit). These form an elevated matrix. Exits per block (versus target and max), the backlog carried across blocks, and the pointer-reset condition combine to determine body contents, pointer values and later fees. excess_exits counts calls while dequeue is capped, so the dimensions cannot be tested independently.
  • eip.md · check_exit_fee — "require(fee_sent >= exit_fee" The fee sufficiency boundary.
  • eip.md · Block validity — "num_exits_to_dequeue = min(num_exits_in_queue, MAX_EXITS_PER_BLOCK)" The dequeue cap of 16.
  • eip.md · update_excess_exits / update_exit_queue Excess is computed against TARGET=2 with a floor at 0. Queue pointers reset when the queue empties.
  • eip.md · return_excess_payment — EXCESS_RETURN_GAS_STIPEND 2300 The excess-return call can fail under the stipend, and only if excess > 0.
Confidence: High
State-access ordering within opcode executionUnder-specified2The precompile is a new state-accessing operation. It reads and writes four or more storage slots, transfers value and makes a nested call to the caller. It therefore needs an ordering rule covering gas charging versus storage writes, out-of-gas before or after writes, and cold/warm status of its slots and the callee. No existing opcode's own ordering changes, so this is level 2 rather than level 3.
  • eip.md · Validator Exit precompile — trigger_exit pseudocode The precompile performs SLOAD/SSTORE on its own storage and a value-transferring CALL back to msg.sender.
  • eip.md · Gas cost — "TBD" There is no rule for when gas is charged relative to these state accesses.
Confidence: Low
Uncertainty: The template excludes precompile internals from instruction ordering. If the stateful precompile is not treated as a 'new state-accessing operation', this would be 0.
Engine API changesUnder-specified2The ExecutionPayload carried over the Engine API must gain an exits field containing source_address and validator_pubkey. This likely requires new versioned payload methods. The target does not specify Engine API methods, so this is scored as an endpoint change with one field change.
  • eip.md · Consensus layer — "Will show up in ExecutionPayload as an SSZ List bound by length MAX_EXITS_PER_BLOCK" The execution payload exchanged between CL and EL gains an exits list.
Confidence: Low
Uncertainty: No Engine API text is supplied. The range is 1 (field only) to 3 (new methods plus an exits_root or other fields).
Transition-tool interface changesUnder-specified2Several output fields are needed: the exits list, with source_address and validator_pubkey entries, and exits_root. The exchange sequence stays the same, since end-of-block processing is internal to the tool, so no new mechanism is counted.
  • eip.md · Block structure The transition tool must output the dequeued exits list and the exits_root.
  • eip.md · Per-block precompile storage calculations End-of-block dequeue and fee update run after transactions, inside the state transition.
Confidence: Medium
Uncertainty: No transition-tool specification was supplied. If exits must be passed in for validation-style runs, the interface could need a new mechanism (level 3).
New invariant on pre-existing tests2All post-fork blockchain tests must produce and check exits_root (the empty-list root) and the exits body list, which is a new block commitment. No evidence requires pre-fork vectors to be re-derived, so this is level 2.
  • eip.md · Block structure — "the block header MUST be appended with the new exits_root field" Every post-fork block carries an exits_root commitment and an exits body list.
  • eip.md · Block validity — condition 2 Every block's exits list must match the queue head.
Confidence: High
New test-framework primitivesUnder-specified2The test suite needs new abstractions: an exit-operation type in the block-body model, an expectation for per-block dequeued exits and queue state, and a fee-calculation helper for constructing calls with value. The shared block and header representation must carry exits and exits_root. This is comparable to adding any body or header list field and does not clearly change how other families are built, so it stays at level 2.
  • eip.md · Block validity / Block processing Expected exits depend on the multi-block queue state, so tests need a model of the queue and of excess fees.
  • eip.md · Additional Helpers — fake_exponential Expected fees must be computed from excess_exits.
Confidence: Medium
Uncertainty: If the shared block model change counts as altering construction of all blockchain families, this could be level 3.
Security risksUnder-specified2The EL now produces authorization data, source_address, that the CL trusts to authorize exits. Correct attribution must hold under CALL, DELEGATECALL, CALLCODE and STATICCALL. Other EL-side boundaries are reentrancy through the excess-return call, fee bypass, rollback of queue state on revert, and body-versus-queue consistency. This is a bounded EL-to-CL interaction that needs targeted integration and fuzzing (level 2).
  • eip.md · trigger_exit — insert_exit_to_queue(msg.sender, validator_pubkey) The recorded source_address is the authorization basis the CL relies on.
  • eip.md · Rate limiting using exit fee The fee mechanism is the anti-griefing defense.
  • eip.md · return_excess_payment An external call to the caller from inside the precompile creates reentrancy and failure surfaces.
Confidence: Medium
Uncertainty: If the move of exit authorization from the BLS key to EL withdrawal credentials is treated as a shared invariant across multiple EL components, this could be level 3.
Performance risksUnder-specified2Targeted integrated benchmarks are needed for a bounded interaction. The cost of a native precompile doing four SSTOREs plus a value CALL must be measured to set its price. End-of-block dequeue processing and queue growth under maximum-call blocks also need validation.
  • eip.md · Gas cost — "we'll estimate the cost of running the above computations fully in the EVM" Gas pricing must be derived from benchmarks of storage writes plus a nested call.
  • eip.md · Exit message queue — "the execution layer gas limit can provide for far more calls" The queue in state can grow without bound, while dequeue is capped at 16 per block.
Confidence: Medium
Uncertainty: The gas cost is TBD, so the workload bound cannot be fixed yet (range 1–2).
Unspecified behavior requiring cross-client consensus2These are localized but competing outcomes and contradictions in the precompile's storage layout and queue-reading rules, plus unspecified failure semantics: wrong input length, static/delegate calls, whether a failed excess return reverts the exit, and return data. All are consensus-visible through state roots and block body contents and need agreement before expected results can be fixed. They are confined to the new mechanism rather than requiring re-baselining across families, so this is level 2.
  • eip.md · insert_exit_to_queue — "queue_tail_index * 3" vs Block validity — "(queue_head_index + i) * 2" The queue slot stride contradicts itself (3 versus 2).
  • eip.md · Block validity — validator_pubkey reconstruction Reads slot+1 four times and concatenates them, which contradicts the two-slot write of pubkey[0:32] and [32:48].
  • eip.md · trigger_exit — "return_excess_payment(msg.value)" vs definition with (fee_sent, source_address) Arity mismatch. Storage alignment of the address and the input-length and failure semantics are also unspecified.
  • eip.md · Gas cost — "TBD"; Configuration — address "TBD" Gas and address are unresolved.
Confidence: Medium
Added precompilesUnder-specified1One precompile is added at one (TBD) address, with a fixed 48-byte input and an intended constant gas cost. That meets the template's definition of simple, which gives level 1 even though the precompile is stateful, accepts value and makes a nested call.
  • eip.md · Validator Exit precompile — "requires a single 48 byte input" Fixed supported input length.
  • eip.md · Utilizing `CALL` to return excess payment — "allowing it to be a fixed instead of dynamic cost" A fixed gas cost is intended, though the actual value is TBD.
Confidence: Medium
Uncertainty: Gas is TBD. If it becomes dynamic, for example from SSTORE or warm/cold pricing, the precompile is complex (level 2).
Patterns affecting pre-existing testsUnder-specified1Baseline tests that call or inspect the newly designated address (empty-account or non-precompile behavior) would change. That rework is confined to particular address cases. With no exits, end-of-block writes store zeros, so ordinary state expectations should not change.
  • eip.md · Configuration — VALIDATOR_EXIT_PRECOMPILE_ADDRESS "TBD" A previously empty address gains precompile behavior and state.
  • eip.md · Per-block precompile storage calculations End-of-block writes run every block, but with an idle queue they write zero values.
Confidence: Medium
Uncertainty: It is unspecified whether the precompile account must exist in state. If end-of-block processing creates or touches it, every post-fork state root changes (up to level 2).
Cross-EIP interactionsUnder-specified1Only local compatibility checks are needed. The exit fee must be shown to be separate from EIP-1559 gas payment and refunds. exits_root must be appended after the Cancun header fields, including EIP-4788's parent_beacon_block_root, and both stateful system writes must coexist in the same block. The target's behavior can otherwise be tested on its own.
  • eip.md · Rate limiting using exit fee — "The EIP-1559-style mechanism" The fee design is analogous to EIP-1559 but paid in ETH through msg.value, independent of the base fee.
  • eip.md · Rate limiting using exit fee — "Method (a) (not used in this EIP) would require EIP-4788" EIP-4788 is not used for authorization.
  • supporting/eip-4788.md · Block structure and validity / Block processing Cancun header field parent_beacon_block_root and a start-of-block stateful write, which coexist with exits_root and end-of-block writes.
Confidence: Medium
Uncertainty: Interactions without an EIP number (warm precompile address and storage, static-call restrictions, empty-account touching, body ordering after withdrawals) could need coordinated cases, which would raise this to level 2.
Interacting EIPs: EIP-1559, EIP-4788
Show 13 zero-score criteria
Zero-score criteria (Checklist revision 3)
CriterionScoreWhy this scoreEvidence / uncertainty
Added opcodes0No new opcode.
  • eip.md · Specification No new instruction is defined.
Modified opcodes0Callee behavior changes, but no instruction's semantics change.
  • eip.md · Validator Exit precompile — "CALLs to VALIDATOR_EXIT_PRECOMPILE_ADDRESS perform the following" New behavior is reached through an unchanged CALL to a new callee.
Modified precompiles0No change to existing precompiles.
  • supporting/eip-4788.md · New stateful precompile No existing precompile is modified by the target.
Added system contracts0No EVM system contract is introduced. The stateful precompile is assessed under +PC.
  • eip.md · Abstract — "Adds a new stateful precompile" The mechanism is specified as a native precompile, not EVM bytecode.
  • eip.md · Gas cost — "being able to execute the above logic natively" Native execution is confirmed.
Modified system contracts0No existing system contract's rules or surrounding behavior change.
  • supporting/eip-4788.md · New stateful precompile The baseline beacon-root mechanism is unaffected by the target.
EVM Gas rule changesUnder-specified0No execution-gas charging, metering or settlement rule is actually specified. The exit fee is paid in ETH through msg.value, not gas, and the precompile's own gas schedule (TBD) belongs under +PC. How the nested 2300-stipend CALL inside a native precompile is metered is unresolved, so it is recorded as under-specified rather than scored.
  • eip.md · Gas cost — "TBD" The precompile's gas cost is left undefined pending review.
  • eip.md · Utilizing `CALL` to return excess payment — "simplify precompile gas accounting (allowing it to be a fixed instead of dynamic cost)" The 2300 stipend is meant to keep the precompile at a fixed cost, but no metering rule is specified.
Uncertainty: If the final cost charges the nested stipend CALL or the SSTOREs dynamically, a new accounting mechanism would be introduced (level 2).
Blob gas accounting changes0Blob-gas charging, pricing and limits are unchanged.
  • eip.md · Exit fee update rule — "maximum downwards rate of change of the blob gas price" The mention of blob gas is a copy-over in the rationale. The mechanism prices exits, not blob gas.
State gas accounting changes0No state-gas accounting mechanism is introduced or changed.
  • eip.md · Validator Exit precompile — insert_exit_to_queue Uses ordinary storage writes. No state-byte cost or state-gas budget is defined.
New EVM gas refund0No new gas refund mechanism is introduced.
  • eip.md · Utilizing `CALL` to return excess payment The returned excess is ETH sent back by CALL, not a gas refund.
  • eip.md · Per-block precompile storage calculations — reset_exit_count Storage resets happen in end-of-block system processing, outside transaction gas refund accounting.
New transaction types0No new transaction type.
  • eip.md · Validator Exit precompile Exits are triggered by ordinary calls, not a new transaction envelope.
New or modified transaction validity mechanisms0No transaction-validity or intrinsic-gas rule changes.
  • eip.md · Block validity New validity rules apply to blocks, not to transaction eligibility. A failed fee check is an in-execution revert.
New fork activation mechanismUnder-specified0Storage slots start at zero and processing simply begins at FORK_TIMESTAMP. No one-time migration or code installation is specified, so starting recurring processing alone does not count.
  • eip.md · Per-block precompile storage calculations — "block.timestamp >= FORK_TIMESTAMP" Recurring end-of-block processing starts at the fork, with no specified migration or installation.
Uncertainty: It is unspecified whether the stateful precompile account must be created or kept non-empty at activation, for example to avoid empty-account deletion. That would be an activation-specific transition (level 3).
Cryptography0No cryptographic verification, signing or hashing rule is added or changed.
  • eip.md · Block structure — compute_trie_root_from_indexed_data Reuses the existing indexed-trie root construction.
  • eip.md · Validator `validator_pubkey` field The pubkey is stored as opaque bytes. The EL performs no BLS verification.
Assessment provenance
Assessed EIP revision
ethereum/EIPs@28cbb0162f EIPS/eip-7002.md committed 2023-06-29 · information cutoff 2024-01-18
Current master · File history · blob d3249f6388 · sha256 acf1880b4186
Rubric
Checklist revision 3 · ethspecs/pm@fe2f793b03
Evaluator
Opus 5.5 (claude-opus-5-5) at high effort, one tool-less call per EIP · isolation bubblewrap_claude_p_no_tools_v1
Source record
Frozen research record research/tasks/10-opus-v3-reassessment/retrospective/outputs/assessments/prague/eip-7002.yaml · sha256 e9f385280719
Supporting documents supplied with the EIP
supporting/eip-1559.md, supporting/eip-4788.md
Criterion legend and glossary

Every stacked bar, comparison matrix, and criterion table on this site uses the same criterion colours, abbreviations, and order. Colour marks the criterion group; the abbreviation and name identify the criterion. Scores are 0–3 per criterion (4 is exceptional; cross-EIP interactions is uncapped).

EVM surface

Opcodes, precompiles, and system contracts that are added or modified.

  • Added opcodes
    Introduces new opcodes
    Score anchors
    0
    No new opcodes are introduced.
    1
    A new simple opcode is introduced (no data portion, no complex stack mechanics, and a constant gas cost).
    2
    Multiple new simple opcodes are introduced, or a single new complex opcode is introduced (has data portion, or complex stack mechanics, or a dynamic gas cost).
    3
    Multiple new opcodes are introduced, and at least one of them is complex (has data portion, or complex stack mechanics, or a dynamic gas cost).
    • Cryptography opcodes are not considered complex by default. Refer to the "Cryptography" section for a separate assessment.
  • Modified opcodes
    Modifies pre-existing opcodes
    Score anchors
    0
    No pre-existing opcode modifications are introduced.
    3
    At least one pre-existing opcode's behavior is modified (not including gas changes) or a pre-existing opcode is deprecated.
  • Added precompiles
    Introduces new precompiles
    Score anchors
    0
    No new precompiles are introduced.
    1
    A new simple precompile is introduced (constant input length, constant gas cost).
    2
    Multiple new simple precompiles are introduced, or a single new complex precompile is introduced (dynamic input length or dynamic gas cost).
    3
    Multiple new precompiles are introduced, and at least one of them is complex (dynamic input length or dynamic gas cost).
    • Cryptography precompiles are not considered complex by default. Refer to the "Cryptography" for a separate assessment.
  • Modified precompiles
    Modifies pre-existing precompiles logic or gas-accounting
    Score anchors
    0
    No pre-existing precompiles are modified.
    1
    At least one pre-existing precompile has its gas schedule modified.
    2
    Multiple pre-existing precompiles have their gas schedule modified, or a single pre-existing precompile has its behavior modified.
    3
    The behavior of multiple pre-existing precompiles, or a single complex pre-existing precompile modified.
  • Added system contracts
    Introduces new system contract, stateful or not
    Score anchors
    0
    No new system contracts are introduced.
    1
    A new system contract is introduced that is not stateful nor does it trigger a new system action (e.g. requests to the consensus layer).
    2
    Multiple new system contracts are introduced or a single new system contract that is either stateful or triggers a new system action (e.g. requests to the consensus layer).
    3
    Multiple new system contracts are introduced and at least one of them is either stateful or triggers a new system action (e.g. requests to the consensus layer).
  • Modified system contracts
    Modifies pre-existing system contracts
    Score anchors
    0
    No modifications to pre-existing system contracts are introduced, directly or indirectly.
    1
    Does not directly modify any system contract, but its behavior has minor indirect effects on one or more system contracts.
    2
    Does not directly modify any system contract, but its behavior has major indirect effects on one or more system contracts.
    3
    At least one pre-existing system contract code or state is modified, which would involve irregular state transition or a similarly complex transition methodology.

Gas and accounting

Execution, blob, and state gas rules, refunds, and where charges happen inside opcodes.

  • EVM Gas rule changes
    New EVM gas accounting rules
    Score anchors
    0
    No gas accounting changes.
    1
    Existing gas accounting mechanism is updated.
    2
    A new gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State-access ordering within opcode execution · not in checklist revision 1
    Changes *where inside an opcode's execution* state is accessed, or where gas is charged relative to that access. Because a state access is recorded in the block-level access list only if execution had enough gas to reach it, this ordering is consensus-critical: moving it changes the BAL at every gas boundary of every affected opcode.
    Score anchors
    0
    No change to where state is accessed, or to where gas is charged relative to a state access, within any opcode.
    1
    A single opcode's state-access or gas-charge ordering changes.
    2
    Multiple opcodes' ordering changes, or a new state-accessing operation is introduced whose position in the order must be settled.
    3
    The ordering rule changes for a whole class of state-accessing opcodes at once, or what counts as a recordable state access is redefined — requiring existing BAL vectors to be re-derived across opcodes and forks.
    • Distinct from "Modified opcodes", which asks whether an opcode's **result** changed. This row asks about the **path to the result**, which is observable even when the result is identical. An EIP can be 0 on that row and 3 on this one.
    • Score changes **to** the ordering. Do not score the fact that state accesses are observable — they always are.
    • Each boundary must be re-tested against every other dimension that can change the answer (cold/warm, static/non-static, delegated/direct, revert/success), so the case count grows multiplicatively rather than additively. Note this explicitly under Special Considerations.
  • Blob gas accounting changes
    New Blob gas accounting rules which potentially affect pre-existing tests
    Score anchors
    0
    No blob gas accounting changes.
    1
    Existing blob gas accounting mechanism is updated.
    2
    A new blob gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new blob gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State gas accounting changes · not in checklist revision 1
    New state gas accounting rules. State gas is the cost of *writing* state, as opposed to accessing or executing it: `StateGasCosts`, `COST_PER_STATE_BYTE`, the block-level state gas budget, and the spill path into execution gas.
    Score anchors
    0
    No state gas accounting changes.
    1
    An existing state gas cost or `STATE_BYTES_PER_*` rate is adjusted.
    2
    A new state-gas-charging site is introduced, or the block-level state gas budget or reservoir allocation is modified.
    3
    A new state gas charging mechanism is introduced, or the spill interaction between state gas and execution gas is modified, affecting existing gas tests.
    • Harder to test than blob gas: the spill path means state gas cannot be metered independently of execution gas, and some costs (e.g. `NEW_ACCOUNT`) are state-dependent.
  • New EVM gas refund
    New gas-refund mechanism
    Score anchors
    0
    No new gas-refund mechanisms are introduced.
    1
    A new simple gas-refund mechanism is introduced that does not affect either existing tests or existing gas-refund mechanisms.
    2
    A new complex gas-refund mechanism is introduced or a simple mechanism that affects existing tests or existing gas-refund mechanisms.
    3
    A new complex gas-refund mechanism is introduced that affects existing tests or existing gas-refund mechanisms.

Blocks, transactions, and encoding

Transaction types and validity, block and header fields, encodings, syncing, and activation-time changes.

  • New transaction types
    Introduces a new transaction type
    Score anchors
    0
    No new transaction types are introduced.
    3
    A new transaction type is introduced.
  • New or modified transaction validity mechanisms
    Creates new or modifies pre-existing transaction types' validation mechanisms
    Score anchors
    0
    No changes are introduced to the validity rules of existing transaction types or to their intrinsic gas cost calculation.
    1
    Minor adjustments are introduced to validity rules or intrinsic gas cost calculation, but they do not significantly affect existing tests.
    2
    Changes to validity rules or intrinsic gas cost calculation affect existing tests, but require only limited updates to test cases and no redesign of the testing infrastructure.
    3
    Changes to validity rules or intrinsic gas cost calculation require extensive rework or redesign of the tests or testing infrastructure.
  • New block / header fields
    Introduces new block or block header fields
    Score anchors
    0
    No new block or header fields are introduced.
    3
    A new block or header field is introduced.
  • Encoding changes (RLP/SSZ)
    Introduces encoding changes at the transaction/block/interfaces level
    Score anchors
    0
    No encoding changes are introduced at the transaction, block, or interfaces levels.
    3
    An encoding change is introduced at transaction, block or interfaces level (e.g. RLP -> SSZ).
    • "Interfaces level" includes the Engine API. Score an Engine API encoding change (e.g. JSON -> SSZ) here.
  • Block syncing changes
    Modifies block RLP validation mechanisms that require test client syncing.
    Score anchors
    0
    No new RLP validation mechanism is introduced.
    1
    A single simple RLP validation mechanism is introduced.
    2
    Multiple simple RLP validation mechanisms are introduced or a single complex one.
    3
    Multiple RLP validation mechanisms are introduced and at least one of them is deemed complex.
  • New fork activation mechanism
    Modifies state, internal variables, or similar, at the fork activation block
    Score anchors
    0
    No state modifications, internal variables or similar are modified at the fork activation block.
    3
    Either a state modification or internal variables are modified at the fork activation block.
    • Initialization of new internal variable is not considered a modification.

Client interfaces

Engine API and transition-tool interface changes.

  • Engine API changes
    Introduces new fields to the Engine API directives
    Score anchors
    0
    No new fields or communication mechanisms are introduced to the Engine API.
    1
    A single new field is introduced in one of the Engine API endpoints.
    2
    Multiple fields are introduced to one or multiple Engine API end points, or a new Engine API end-point is introduced.
    3
    Multiple fields are introduced to one or multiple Engine API end points and a new Engine API end-point is introduced.
  • Engine API encoding changes · Checklist revision 1 only
    Engine API encoding changes (the revision-1 template defines no anchor text for this row).
  • Transition-tool interface changes
    Modifies or adds new fields to the transition tool interface.
    Score anchors
    0
    No modifications to the transition tool interface are required.
    1
    A single new field needs to be introduced to the transition tool interface.
    2
    Multiple new fields or a new mechanism has to be introduced to the transition tool interface.
    3
    Multiple new fields and a new mechanism has to be introduced to the transition tool interface.
    • Special consideration must be paid to this section if the EIP introduces a mechanism that requires the state transition tool to be aware whether the block it is processing is the fork-activation block.

Testing impact

Rework, new invariants, and new primitives required in the test framework.

  • Patterns affecting pre-existing tests
    Implements a new validation mechanism or rule that translates in reworking pre-existing tests
    Score anchors
    0
    No pre-existing tests are affected by this change.
    1
    Minor subset of existing tests are affected by this change.
    2
    Considerable subset of existing tests are affected by this change but involves only a contrived category of tests.
    3
    Major subset of existing tests are affected, including diverse category of tests (benchmarks, static, multiple forks, etc.).
  • New invariant on pre-existing tests · not in checklist revision 1
    Tests that are **not about this EIP** must nonetheless assert something this EIP produces. Their logic does not change; they gain a new thing to check.
    Score anchors
    0
    Pre-existing tests assert nothing new.
    1
    A narrow, contrived category of pre-existing tests gains a new assertion.
    2
    A broad category gains a new assertion, applied mechanically.
    3
    Every test in the fork gains the assertion regardless of what it tests, and pre-fork vectors must be re-derived to satisfy it.
    • Paired with the row above, and easy to confuse with it. "Patterns affecting pre-existing tests" asks whether existing tests must be **reworked**; this row asks whether they must **additionally assert something new**. Score both — an EIP can be low on one and high on the other.
  • New test-framework primitives · not in checklist revision 1
    Requires new abstractions in the test framework itself — expectation types, modifiers, helpers — beyond writing test functions with what already exists.
    Score anchors
    0
    Existing test primitives suffice.
    1
    Existing primitives need minor extension.
    2
    New expectation or modifier primitives are required, reusable within this EIP's own test suite.
    3
    New framework-level primitives are required that become a permanent part of the framework and are used by other EIPs' tests.

Risk and validation

Security, performance, boundary conditions, and cryptography that need validation.

  • Security risks
    Introduces or modifies mechanisms that could compromise the security of the chain, users, validators, or other stakeholders, if not implemented properly.
    Score anchors
    0
    No new mechanisms are introduced that could pose a security risk.
    1
    The introduced mechanisms are self-contained, can be validated in isolation, and do not alter existing invariants that could pose a security risk for any stakeholders.
    2
    The introduced mechanisms interact with a limited number of existing components, slightly altering their security assumptions and requiring a targeted security review or fuzzing.
    3
    The introduced mechanisms interact with multiple existing components, including critical ones, substantially altering their security assumptions and requiring an extensive security review and fuzzing.
  • Performance risks
    Introduces or modifies mechanisms and requires performance validation.
    Score anchors
    0
    No new mechanisms are introduced that require performance validation.
    1
    The introduced mechanisms can be benchmarked in isolation and do not affect existing performance behavior.
    2
    The introduced mechanisms cannot be fully benchmarked in isolation, but they only have a limited impact on the existing performance benchmarks.
    3
    The introduced mechanisms cannot be benchmarked in isolation and have a substantial impact on existing performance benchmarks or have complex interactions with existing mechanisms.
  • Edge/boundary conditions
    Feature contains edge/boundary conditions.
    Score anchors
    0
    No discernible edge cases or boundary conditions are introduced.
    1
    A single edge-case or boundary-condition prone mechanism is introduced.
    2
    Multiple edge-case or boundary-condition prone mechanisms are introduced, but none of them requires an elevated number of cases to test.
    3
    Multiple edge-case or boundary-condition prone mechanisms are introduced and at least one of them requires an elevated number of cases to test.
  • Cryptography
    Introduces new cryptography mechanisms or modifies existing functionality that involves cryptography
    Score anchors
    0
    No cryptography mechanisms are introduced.
    1
    A new cryptography mechanism is introduced but it is a well known mechanism that is known to have vast resources to aid on its testing.
    2
    Multiple new cryptography mechanisms are introduced that are well-known or a single but novel mechanism is introduced that is either untested or has limited resources.
    3
    Multiple new cryptography mechanisms are introduced and at least one of them is a novel mechanism.

Coordination

Cross-EIP interactions and behavior that clients must agree on before tests exist.

  • Cross-EIP interactions
    Introduces or modifies mechanisms that affect other EIPs in either the same or past forks.
    Score anchors
    0
    Fully self-contained EIP that does not depend on, modify, or conflict with any other EIP.
    1
    The EIP interacts with one or more other EIPs in a non-critical and limited way but can be tested independently for the most part.
    2
    The EIP depends on or modifies one or more other EIPs such that coordinated testing and consideration is required, but interactions are limited in scope and not complex.
    3
    The EIP has strong interdependencies with multiple EIPs, requiring extensive coordinated cross-EIP testing as well as potential re-design of existing test vectors.
    • +1 for every 3 additional interacting EIPs beyond the first 3, each of which requires its own coordinated test cases. List the EIPs in the rationale.
    • This row is intentionally uncapped, unlike every other anchor: each interacting EIP is another axis of the test matrix, so a ceiling would make a 12-EIP product indistinguishable from a 3-EIP one.
  • Unspecified behavior requiring cross-client consensus · not in checklist revision 1
    The EIP text does not determine the answer for cases a test can construct. Clients must agree on a previously unspecified detail before tests can be baselined. The cost here is coordination and re-baselining, not test writing.
    Score anchors
    0
    The EIP text determines the answer for every case a test could construct.
    1
    A few details are unspecified but have an obvious intended reading.
    2
    Details require client agreement before tests can be written, but they are localized.
    3
    A previously unspecified *and previously unobservable* behavior becomes consensus-critical; expect tests to be re-baselined on each round of EIP amendment.
    • Score this from the EIP's state at assessment time: whether it has client implementations, whether it has been through a devnet, and how many open questions remain on its discussion thread.