Retrospective LLM-Based Complexity Evaluations

EIP complexity assessment

EIP-7702: Set Code for EOAs

Assessed in Prague / Pectra. The score describes the EIP text available at the assessment cutoff, not the EIP as it stands today.

RetrospectivePrague / PectraAssessment cutoff 2024-05-23Included by cutoffLayers: execution
LLM Completescore 26
Human Not available· Human complexity assessments were not produced for this fork; only the LLM assessment exists.

LLM assessment

Evaluated on: · Spec revision: 2024-05-09 · ad9ecb077c

Scope at the cutoff. This revision of EIP-7702 adds a new EIP-2718 transaction type whose payload carries a list of `[contract_code, y_parity, r, s]` authorization tuples. When the transaction starts, each tuple's signer is recovered with `ecrecover(keccak(MAGIC + contract_code), ...)`. The signer's code must be empty; it is then set to `contract_code`, and the signer is added to the EIP-2929 `accessed_addresses` set. Every signer's code is set back to empty when the transaction ends. Intrinsic gas is the EIP-2930 formula plus calldata-style per-byte costs over each `contract_code` and 5000 per tuple. The EIP adds no opcodes, precompiles, system contracts or header fields.

26HighHigh
Evaluator
LLMChecklist v3
Confidence
Medium
Under-specified at assessment cutoff
Yes — 6 criteria affected
Plausible range
25–33 (High)
Assessment cutoff
2024-05-23 · EIP revision ad9ecb077c (2024-05-09)
Score bands · Checklist revision 3
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the LLM total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. New transaction types3
  2. Encoding changes (RLP/SSZ)3
  3. Security risks3
  4. EVM Gas rule changes2

Under-specified at assessment cutoff: Yes

The EIP text available at the assessment cutoff left material behavior unresolved. The affected criteria and the plausible total range record that uncertainty.

Why: This early draft omits several consensus-relevant outcomes. It does not say what happens when signature recovery or the code-emptiness check fails, including for duplicate signers. Behavior of the code reset on revert is not specified, nor whether storage and nonce changes made under temporary code persist. The payload has no value field, and the outer signing hash, receipt payload, MAGIC and TX_TYPE are undefined. Authorization signatures carry no nonce or chain_id.

Unresolved questions at the cutoff (8)
  • Does a failed code-emptiness check or invalid signature make the transaction invalid, abort execution, or skip the tuple?
  • How is a signer that appears twice in one list handled, given that the second check sees code already set?
  • Is code reset at the end of the transaction also on revert or out-of-gas, and do storage or balance changes made by temporary code persist?
  • Where is the value field, or can value not be transferred?
  • What hash does the outer transaction signature cover, and what is the receipt payload?
  • Is contract creation (empty destination) allowed?
  • Which signature validity bounds (s range, y_parity) apply to authorization tuples?
  • Is there a size limit on contract_code?
Notable ambiguities noted by the assessor (6)
  • The payload has no value field despite having destination and data.
  • The authorization message keccak(MAGIC + contract_code) has no nonce or chain_id, so signatures are replayable indefinitely and across chains.
  • The consequence of a failed 'Verify that the contract code of signer is empty' is not stated.
  • The fee-market fields assume EIP-1559, which is not listed in requires.
  • MAGIC, TX_TYPE and FORK_BLKNUM are TBD; FORK_BLKNUM and FORK_BLOCK_NUMBER are used inconsistently.
  • It is not stated whether a signer may equal tx.origin, or how sender-with-code rules interact with that case.

Criterion breakdown

EIP-7702 Prague / Pectra: LLM criterion scores and rationale
CriterionScoreWhy this scoreEvidence / uncertainty
New transaction types3A new EIP-2718 transaction type is introduced.
  • eip.md · Specification — "a new EIP-2718 transaction is introduced with TransactionType = TX_TYPE(TBD)" A new typed transaction envelope with a TBD type byte.
Confidence: High
Encoding changes (RLP/SSZ)3A new serialized transaction schema is defined.
  • eip.md · Specification — "rlp([chain_id, nonce, max_priority_fee_per_gas, max_fee_per_gas, gas_limit, destination, data, access_list, [[contract_code, y_parity, r, s], ...], signature_y_parity, signature_r, signature_s])" Defines a new RLP transaction payload schema with a nested authorization-tuple list.
Confidence: High
Uncertainty: The signing payload of the outer transaction and the receipt payload are not specified, and the schema has no value field.
Security risks3The EIP changes shared authorization and trust invariants across several components. EOAs can execute arbitrary code signed once with no replay protection; balances can drop without the owner sending a transaction (affecting mempool and inclusion lists); and EOA-versus-contract assumptions in contracts change. Coordinated adversarial scenarios are needed, so level 3.
  • eip.md · Backwards Compatibility — "breaks the invariant that an account balance can only decrease as a result of transactions originating from that account" Changes an invariant relied on by mempool design and other EIPs, such as inclusion lists.
  • eip.md · Specification — "keccak(MAGIC + contract_code)" The authorization signature covers no nonce or chain_id, so replay across transactions and chains is possible within the rules.
  • eip.md · Security Considerations Shares EIP-3074's security considerations; wallets must be careful about which contract_code they sign.
  • supporting/eip-3074.md · Allowing tx.origin as Signer Lists invariants (msg.sender == tx.origin checks, EOA detection) that delegated execution of EOAs can break.
Confidence: High
EVM Gas rule changes2The EIP adds a new intrinsic-gas accounting mechanism for authorization tuples, and signer pre-warming uses the existing EIP-2929 mechanism. Both apply only to the new transaction type, so existing rules and baseline gas results do not change. This fits level 2.
  • eip.md · Specification — "Additionally, we add a cost of `16 * non-zero calldata bytes + 4 * zero calldata bytes` over each `contract_code`, plus `PER_CONTRACT_CODE_BASE_COST`" Adds a new intrinsic-gas component for the new transaction type: calldata-style pricing over each contract_code plus 5000 per tuple.
  • eip.md · Specification — "Add the `signer` account to `accessed_addresses`" Signers are pre-warmed, which changes cold/warm costs for later accesses to them, but only inside the new transaction type.
Confidence: High
Uncertainty: The text does not say whether the signer warming is reverted if the transaction later fails; warming at transaction start is presumably not revertible.
New or modified transaction validity mechanismsUnder-specified2The new transaction type and its intrinsic-gas rule need dedicated validity cases. These can be built on the existing typed-transaction validation sequence, so level 2.
  • eip.md · Specification — intrinsic cost paragraph New intrinsic-gas rule for the new transaction type.
  • eip.md · Specification — "Verify that the contract code of signer is empty." Adds a check on third-party (signer) account state. Its failure consequence (invalid transaction or skipped tuple) is not stated.
Confidence: Medium
Uncertainty: If a failed code-emptiness or signature check makes the whole transaction invalid, validity would depend on other accounts' state, possibly changed by earlier transactions in the block. That would need coordinated multi-account/state scenarios and would reach level 3.
New test-framework primitives2The target suite needs a new construction abstraction (authorization tuples signed by arbitrary keys and attached to the new transaction type). This is limited to the target's own test suite and does not change how other families are built, so level 2.
  • eip.md · Specification — "signer = ecrecover(keccak(MAGIC + contract_code), y_parity, r, s)" Tests must build and sign authorization tuples over a new MAGIC-prefixed message.
  • eip.md · Specification — "At the end of the transaction, set the contract_code of each signer back to empty." Tests need checks on code that is temporary within the transaction, e.g. observed during execution through EXTCODE* or calls and empty in the post-state.
Confidence: Medium
Uncertainty: The actual capabilities of existing helpers are not evidenced.
Performance risks2Targeted integrated benchmarks are needed for transactions with many tuples. The bounded interaction is signature recovery, code writes and reset of arbitrary-size code against the state/commitment path, which must be checked against the 5000 per-tuple and calldata pricing. This is level 2.
  • eip.md · Specification — per-tuple processing steps Each tuple requires keccak plus ecrecover, a code read and a code write, followed by a code reset at the end of the transaction.
  • eip.md · Parameters — "PER_CONTRACT_CODE_BASE_COST = 5000" A flat per-tuple cost bounds the workload. Contract_code size has no explicit cap beyond calldata pricing.
Confidence: Medium
Uncertainty: Without a code-size limit, the cost of setting and resetting large code depends on client state handling.
Edge/boundary conditionsUnder-specified2Several boundary-sensitive mechanisms are introduced: the intrinsic-gas threshold, the code-emptiness check (including duplicates and order in the list), and signature-value bounds. An elevated matrix is plausible (signer identity versus origin or destination × prior code × transaction outcome), but the failure outcomes are unspecified, so level 2 is the best-supported score.
  • eip.md · Specification — intrinsic cost paragraph Intrinsic gas now depends on tuple count and contract_code byte composition, so the gas-limit boundary must be tested.
  • eip.md · Specification — "Verify that the contract code of signer is empty." Boundary on prior code state, including duplicate signers in one list (the second check sees code already set) and empty versus non-empty code.
  • eip.md · Specification — "[[contract_code, y_parity, r, s], ...]" The list may be empty or contain empty contract_code. No size limits on contract_code or the list are stated.
Confidence: Medium
Uncertainty: Once failure semantics are defined, interactions between signer identity, duplicate entries and revert/reset behavior could justify level 3.
Cross-EIP interactions2EIP-2929 and EIP-2930 need coordinated cases: warm/cold gas for signers, and signers that also appear in the access list or as tx.origin or destination. EIP-2718 needs only local envelope compatibility checks. This does not amount to coupled restructuring across many EIPs, so level 2.
  • eip.md · Specification — "Add the signer account to accessed_addresses (as defined in EIP-2929.)" Signer warming interacts with EIP-2929 cold/warm charging for CALL, EXTCODE* and BALANCE targeting signers.
  • eip.md · Specification — "The intrinsic cost of the new transaction is inherited from EIP-2930" The access list and authorization tuples coexist; intrinsic-gas totals and duplicate warming (signer also in the access list) need combined cases.
  • supporting/eip-2718.md · Transactions / Security Considerations The new type must fit the typed envelope and receipt rules and include the type in signed data.
Confidence: Medium
Uncertainty: The fee fields imply EIP-1559, and sender-with-code rules (EIP-3607) are relevant, but neither is supplied or cited.
Interacting EIPs: EIP-2929, EIP-2930, EIP-2718
Unspecified behavior requiring cross-client consensusUnder-specified2Several localized, constructible outcomes have competing interpretations: failure handling for verification and signatures, duplicate signers, persistence of storage written by temporary code, and the missing value field. Expected results cannot be fixed until these are agreed, so level 2.
  • eip.md · Specification — "Verify that the contract code of signer is empty." The outcome of a failed check (invalid transaction, aborted execution or skipped tuple) is not stated. Invalid or unrecoverable signatures are likewise not handled.
  • eip.md · Specification — "At the end of the transaction, set the contract_code of each signer back to empty." Silent on revert/failure paths and on storage or nonce changes made under the temporary code.
  • eip.md · Specification — TransactionPayload There is no value field. The outer signature hash, receipt payload, MAGIC and contract-creation (empty destination) handling are unspecified.
Confidence: Medium
Uncertainty: EOAs executing code and holding storage is newly observable behavior. If agreeing on it required re-baselining across families, level 3 could be argued.
Block syncing changesUnder-specified1Block import must accept and structurally decode one new transaction payload format, which is a simple local rule. No header or cross-block validation changes, so level 1.
  • eip.md · Specification — TransactionPayload Block bodies must decode a new typed transaction with a nested authorization-tuple list.
  • supporting/eip-2718.md · Transactions Typed transactions in the block transaction trie use a type byte followed by an opaque payload.
Confidence: Medium
Uncertainty: Element-type constraints on the tuples (byte lengths, y_parity range) are not stated. If they are enforced as several structural rules, level 2 could apply.
Transition-tool interface changes1One new semantic transaction-input field (the contract_code authorization list) must be passed. No new tool mechanism or exchange sequence is required, so this is level 1.
  • eip.md · Specification — "[[contract_code, y_parity, r, s], ...]" Transaction input to the state-transition tool needs a new authorization-list field.
Confidence: Medium
Uncertainty: No transition-tool evidence was supplied. Whether recovered signers must be reported in output is unspecified.
CryptographyUnder-specified1Exactly one established mechanism (secp256k1 ECDSA recovery with keccak) is added as a new protocol validation site. Hashing and recovery primitives are unchanged, but the validity rules for authorization signatures are new, so level 1.
  • eip.md · Specification — "Let signer = ecrecover(keccak(MAGIC + contract_code), y_parity, r, s)" Adds a protocol-level secp256k1 signature recovery over a new message domain for each authorization tuple.
  • supporting/eip-3074.md · AUTH Behavior — "Signature validity and signer recovery are handled analogously to transaction signatures" Shows the established precedent for ECDSA recovery rules, including malleability limits, in a related design. The target does not adopt these rules explicitly.
Confidence: Medium
Uncertainty: The s-range, y_parity range and handling of an invalid signature are not stated. If reuse of an unchanged primitive is read as no new mechanism, the score would be 0.
Show 15 zero-score criteria
Zero-score criteria (Checklist revision 3)
CriterionScoreWhy this scoreEvidence / uncertainty
Added opcodes0No new instruction.
  • eip.md · Rationale — "It does not require adding any opcodes" Explicitly adds no opcodes.
Modified opcodes0No instruction's specified semantics change. EXTCODE* and CALL into a signer behave normally against the state that holds the temporary code.
  • eip.md · Rationale — Conversion of EIP-3074 use cases Uses existing calls and TSTORE/TLOAD unchanged; existing instructions only observe the temporarily set code.
Added precompiles0No new precompile.
  • eip.md · Specification No precompile is added.
Modified precompiles0No precompile semantics or gas change.
  • eip.md · Specification — "ecrecover(...)" ecrecover is used as a protocol function; the precompile itself is not changed.
Added system contracts0No system contract.
  • eip.md · Specification No protocol-designated contract is introduced.
Modified system contracts0No system contract is modified.
  • eip.md · Specification No existing system contract is referenced or changed.
State-access ordering within opcode executionUnder-specified0No opcode's state-access or gas-charge ordering changes. The new access sequence (recover, check code, set code, warm) is transaction-level setup rather than instruction execution, so level 0 is the best fit.
  • eip.md · Specification — "At the start of executing the transaction, for each [contract_code, y_parity, r, s] tuple" The state accesses (reading signer code, setting code, warming) happen in transaction-level processing, not inside any instruction.
  • eip.md · Rationale — "It does not require adding any opcodes" No instruction's sequence of access and gas charging is changed.
Uncertainty: If the authorization processing were treated as a new state-accessing operation that needs an ordering rule, level 2 could be argued.
Blob gas accounting changes0Blob-gas accounting is not affected.
  • eip.md · Specification — TransactionPayload The payload has no blob fields, and nothing about blob gas is specified.
State gas accounting changes0The EIP introduces no state-gas accounting, state-byte rates or budgets. Its flat per-tuple cost is intrinsic execution gas and is scored under GAS.
  • eip.md · Specification — "PER_CONTRACT_CODE_BASE_COST = 5000" Writing temporary code is covered by a flat intrinsic charge, not by any state-gas mechanism.
  • eip.md · Specification — "At the end of the transaction, set the contract_code of each signer back to empty." The code write is temporary; no state-byte accounting is introduced.
New EVM gas refund0No new refund mechanism.
  • eip.md · Specification No refund rule is mentioned, including when code is reset at the end of the transaction.
New block / header fields0No header member is added.
  • eip.md · Specification No header or block-level field is added.
New fork activation mechanism0No activation-specific state transition is required.
  • eip.md · Parameters — "FORK_BLKNUM = TBD" Activation only enables the new transaction type; no state migration or code installation happens.
Engine API changes0No Engine API field or endpoint changes.
  • eip.md · Specification No Engine API changes; transactions travel as opaque typed bytes.
Patterns affecting pre-existing tests0Existing transaction types and opcode behaviors keep their inputs and expected results. The new behavior is reached only through the new transaction type, so no baseline test family needs rework.
  • eip.md · Specification — "As of FORK_BLOCK_NUMBER, a new EIP-2718 transaction is introduced" All new behavior is triggered only by the new transaction type.
  • eip.md · Backwards Compatibility The broken invariant concerns account balances and mempool design, not the results of existing execution tests.
Uncertainty: Existing tests that assume an EOA can never execute code are application-level, not baseline EL tests.
New invariant on pre-existing tests0Baseline tests need no new assertion.
  • eip.md · Specification No new header, receipt field, log or protocol-mandated write applies to existing tests.
Assessment provenance
Assessed EIP revision
ethereum/EIPs@ad9ecb077c EIPS/eip-7702.md committed 2024-05-09 · information cutoff 2024-05-23
Current master · File history · blob 8534301caf · sha256 ed08fdd82ff9
Rubric
Checklist revision 3 · ethspecs/pm@fe2f793b03
Evaluator
Opus 5.5 (claude-opus-5-5) at high effort, one tool-less call per EIP · isolation bubblewrap_claude_p_no_tools_v1
Source record
Frozen research record research/tasks/10-opus-v3-reassessment/retrospective/outputs/assessments/prague/eip-7702.yaml · sha256 366e812c27c1
Supporting documents supplied with the EIP
supporting/eip-20.md, supporting/eip-2718.md, supporting/eip-2929.md, supporting/eip-2930.md, supporting/eip-3074.md, supporting/eip-4337.md, supporting/eip-5003.md
Criterion legend and glossary

Every stacked bar, comparison matrix, and criterion table on this site uses the same criterion colours, abbreviations, and order. Colour marks the criterion group; the abbreviation and name identify the criterion. Scores are 0–3 per criterion (4 is exceptional; cross-EIP interactions is uncapped).

EVM surface

Opcodes, precompiles, and system contracts that are added or modified.

  • Added opcodes
    Introduces new opcodes
    Score anchors
    0
    No new opcodes are introduced.
    1
    A new simple opcode is introduced (no data portion, no complex stack mechanics, and a constant gas cost).
    2
    Multiple new simple opcodes are introduced, or a single new complex opcode is introduced (has data portion, or complex stack mechanics, or a dynamic gas cost).
    3
    Multiple new opcodes are introduced, and at least one of them is complex (has data portion, or complex stack mechanics, or a dynamic gas cost).
    • Cryptography opcodes are not considered complex by default. Refer to the "Cryptography" section for a separate assessment.
  • Modified opcodes
    Modifies pre-existing opcodes
    Score anchors
    0
    No pre-existing opcode modifications are introduced.
    3
    At least one pre-existing opcode's behavior is modified (not including gas changes) or a pre-existing opcode is deprecated.
  • Added precompiles
    Introduces new precompiles
    Score anchors
    0
    No new precompiles are introduced.
    1
    A new simple precompile is introduced (constant input length, constant gas cost).
    2
    Multiple new simple precompiles are introduced, or a single new complex precompile is introduced (dynamic input length or dynamic gas cost).
    3
    Multiple new precompiles are introduced, and at least one of them is complex (dynamic input length or dynamic gas cost).
    • Cryptography precompiles are not considered complex by default. Refer to the "Cryptography" for a separate assessment.
  • Modified precompiles
    Modifies pre-existing precompiles logic or gas-accounting
    Score anchors
    0
    No pre-existing precompiles are modified.
    1
    At least one pre-existing precompile has its gas schedule modified.
    2
    Multiple pre-existing precompiles have their gas schedule modified, or a single pre-existing precompile has its behavior modified.
    3
    The behavior of multiple pre-existing precompiles, or a single complex pre-existing precompile modified.
  • Added system contracts
    Introduces new system contract, stateful or not
    Score anchors
    0
    No new system contracts are introduced.
    1
    A new system contract is introduced that is not stateful nor does it trigger a new system action (e.g. requests to the consensus layer).
    2
    Multiple new system contracts are introduced or a single new system contract that is either stateful or triggers a new system action (e.g. requests to the consensus layer).
    3
    Multiple new system contracts are introduced and at least one of them is either stateful or triggers a new system action (e.g. requests to the consensus layer).
  • Modified system contracts
    Modifies pre-existing system contracts
    Score anchors
    0
    No modifications to pre-existing system contracts are introduced, directly or indirectly.
    1
    Does not directly modify any system contract, but its behavior has minor indirect effects on one or more system contracts.
    2
    Does not directly modify any system contract, but its behavior has major indirect effects on one or more system contracts.
    3
    At least one pre-existing system contract code or state is modified, which would involve irregular state transition or a similarly complex transition methodology.

Gas and accounting

Execution, blob, and state gas rules, refunds, and where charges happen inside opcodes.

  • EVM Gas rule changes
    New EVM gas accounting rules
    Score anchors
    0
    No gas accounting changes.
    1
    Existing gas accounting mechanism is updated.
    2
    A new gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State-access ordering within opcode execution · not in checklist revision 1
    Changes *where inside an opcode's execution* state is accessed, or where gas is charged relative to that access. Because a state access is recorded in the block-level access list only if execution had enough gas to reach it, this ordering is consensus-critical: moving it changes the BAL at every gas boundary of every affected opcode.
    Score anchors
    0
    No change to where state is accessed, or to where gas is charged relative to a state access, within any opcode.
    1
    A single opcode's state-access or gas-charge ordering changes.
    2
    Multiple opcodes' ordering changes, or a new state-accessing operation is introduced whose position in the order must be settled.
    3
    The ordering rule changes for a whole class of state-accessing opcodes at once, or what counts as a recordable state access is redefined — requiring existing BAL vectors to be re-derived across opcodes and forks.
    • Distinct from "Modified opcodes", which asks whether an opcode's **result** changed. This row asks about the **path to the result**, which is observable even when the result is identical. An EIP can be 0 on that row and 3 on this one.
    • Score changes **to** the ordering. Do not score the fact that state accesses are observable — they always are.
    • Each boundary must be re-tested against every other dimension that can change the answer (cold/warm, static/non-static, delegated/direct, revert/success), so the case count grows multiplicatively rather than additively. Note this explicitly under Special Considerations.
  • Blob gas accounting changes
    New Blob gas accounting rules which potentially affect pre-existing tests
    Score anchors
    0
    No blob gas accounting changes.
    1
    Existing blob gas accounting mechanism is updated.
    2
    A new blob gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new blob gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State gas accounting changes · not in checklist revision 1
    New state gas accounting rules. State gas is the cost of *writing* state, as opposed to accessing or executing it: `StateGasCosts`, `COST_PER_STATE_BYTE`, the block-level state gas budget, and the spill path into execution gas.
    Score anchors
    0
    No state gas accounting changes.
    1
    An existing state gas cost or `STATE_BYTES_PER_*` rate is adjusted.
    2
    A new state-gas-charging site is introduced, or the block-level state gas budget or reservoir allocation is modified.
    3
    A new state gas charging mechanism is introduced, or the spill interaction between state gas and execution gas is modified, affecting existing gas tests.
    • Harder to test than blob gas: the spill path means state gas cannot be metered independently of execution gas, and some costs (e.g. `NEW_ACCOUNT`) are state-dependent.
  • New EVM gas refund
    New gas-refund mechanism
    Score anchors
    0
    No new gas-refund mechanisms are introduced.
    1
    A new simple gas-refund mechanism is introduced that does not affect either existing tests or existing gas-refund mechanisms.
    2
    A new complex gas-refund mechanism is introduced or a simple mechanism that affects existing tests or existing gas-refund mechanisms.
    3
    A new complex gas-refund mechanism is introduced that affects existing tests or existing gas-refund mechanisms.

Blocks, transactions, and encoding

Transaction types and validity, block and header fields, encodings, syncing, and activation-time changes.

  • New transaction types
    Introduces a new transaction type
    Score anchors
    0
    No new transaction types are introduced.
    3
    A new transaction type is introduced.
  • New or modified transaction validity mechanisms
    Creates new or modifies pre-existing transaction types' validation mechanisms
    Score anchors
    0
    No changes are introduced to the validity rules of existing transaction types or to their intrinsic gas cost calculation.
    1
    Minor adjustments are introduced to validity rules or intrinsic gas cost calculation, but they do not significantly affect existing tests.
    2
    Changes to validity rules or intrinsic gas cost calculation affect existing tests, but require only limited updates to test cases and no redesign of the testing infrastructure.
    3
    Changes to validity rules or intrinsic gas cost calculation require extensive rework or redesign of the tests or testing infrastructure.
  • New block / header fields
    Introduces new block or block header fields
    Score anchors
    0
    No new block or header fields are introduced.
    3
    A new block or header field is introduced.
  • Encoding changes (RLP/SSZ)
    Introduces encoding changes at the transaction/block/interfaces level
    Score anchors
    0
    No encoding changes are introduced at the transaction, block, or interfaces levels.
    3
    An encoding change is introduced at transaction, block or interfaces level (e.g. RLP -> SSZ).
    • "Interfaces level" includes the Engine API. Score an Engine API encoding change (e.g. JSON -> SSZ) here.
  • Block syncing changes
    Modifies block RLP validation mechanisms that require test client syncing.
    Score anchors
    0
    No new RLP validation mechanism is introduced.
    1
    A single simple RLP validation mechanism is introduced.
    2
    Multiple simple RLP validation mechanisms are introduced or a single complex one.
    3
    Multiple RLP validation mechanisms are introduced and at least one of them is deemed complex.
  • New fork activation mechanism
    Modifies state, internal variables, or similar, at the fork activation block
    Score anchors
    0
    No state modifications, internal variables or similar are modified at the fork activation block.
    3
    Either a state modification or internal variables are modified at the fork activation block.
    • Initialization of new internal variable is not considered a modification.

Client interfaces

Engine API and transition-tool interface changes.

  • Engine API changes
    Introduces new fields to the Engine API directives
    Score anchors
    0
    No new fields or communication mechanisms are introduced to the Engine API.
    1
    A single new field is introduced in one of the Engine API endpoints.
    2
    Multiple fields are introduced to one or multiple Engine API end points, or a new Engine API end-point is introduced.
    3
    Multiple fields are introduced to one or multiple Engine API end points and a new Engine API end-point is introduced.
  • Engine API encoding changes · Checklist revision 1 only
    Engine API encoding changes (the revision-1 template defines no anchor text for this row).
  • Transition-tool interface changes
    Modifies or adds new fields to the transition tool interface.
    Score anchors
    0
    No modifications to the transition tool interface are required.
    1
    A single new field needs to be introduced to the transition tool interface.
    2
    Multiple new fields or a new mechanism has to be introduced to the transition tool interface.
    3
    Multiple new fields and a new mechanism has to be introduced to the transition tool interface.
    • Special consideration must be paid to this section if the EIP introduces a mechanism that requires the state transition tool to be aware whether the block it is processing is the fork-activation block.

Testing impact

Rework, new invariants, and new primitives required in the test framework.

  • Patterns affecting pre-existing tests
    Implements a new validation mechanism or rule that translates in reworking pre-existing tests
    Score anchors
    0
    No pre-existing tests are affected by this change.
    1
    Minor subset of existing tests are affected by this change.
    2
    Considerable subset of existing tests are affected by this change but involves only a contrived category of tests.
    3
    Major subset of existing tests are affected, including diverse category of tests (benchmarks, static, multiple forks, etc.).
  • New invariant on pre-existing tests · not in checklist revision 1
    Tests that are **not about this EIP** must nonetheless assert something this EIP produces. Their logic does not change; they gain a new thing to check.
    Score anchors
    0
    Pre-existing tests assert nothing new.
    1
    A narrow, contrived category of pre-existing tests gains a new assertion.
    2
    A broad category gains a new assertion, applied mechanically.
    3
    Every test in the fork gains the assertion regardless of what it tests, and pre-fork vectors must be re-derived to satisfy it.
    • Paired with the row above, and easy to confuse with it. "Patterns affecting pre-existing tests" asks whether existing tests must be **reworked**; this row asks whether they must **additionally assert something new**. Score both — an EIP can be low on one and high on the other.
  • New test-framework primitives · not in checklist revision 1
    Requires new abstractions in the test framework itself — expectation types, modifiers, helpers — beyond writing test functions with what already exists.
    Score anchors
    0
    Existing test primitives suffice.
    1
    Existing primitives need minor extension.
    2
    New expectation or modifier primitives are required, reusable within this EIP's own test suite.
    3
    New framework-level primitives are required that become a permanent part of the framework and are used by other EIPs' tests.

Risk and validation

Security, performance, boundary conditions, and cryptography that need validation.

  • Security risks
    Introduces or modifies mechanisms that could compromise the security of the chain, users, validators, or other stakeholders, if not implemented properly.
    Score anchors
    0
    No new mechanisms are introduced that could pose a security risk.
    1
    The introduced mechanisms are self-contained, can be validated in isolation, and do not alter existing invariants that could pose a security risk for any stakeholders.
    2
    The introduced mechanisms interact with a limited number of existing components, slightly altering their security assumptions and requiring a targeted security review or fuzzing.
    3
    The introduced mechanisms interact with multiple existing components, including critical ones, substantially altering their security assumptions and requiring an extensive security review and fuzzing.
  • Performance risks
    Introduces or modifies mechanisms and requires performance validation.
    Score anchors
    0
    No new mechanisms are introduced that require performance validation.
    1
    The introduced mechanisms can be benchmarked in isolation and do not affect existing performance behavior.
    2
    The introduced mechanisms cannot be fully benchmarked in isolation, but they only have a limited impact on the existing performance benchmarks.
    3
    The introduced mechanisms cannot be benchmarked in isolation and have a substantial impact on existing performance benchmarks or have complex interactions with existing mechanisms.
  • Edge/boundary conditions
    Feature contains edge/boundary conditions.
    Score anchors
    0
    No discernible edge cases or boundary conditions are introduced.
    1
    A single edge-case or boundary-condition prone mechanism is introduced.
    2
    Multiple edge-case or boundary-condition prone mechanisms are introduced, but none of them requires an elevated number of cases to test.
    3
    Multiple edge-case or boundary-condition prone mechanisms are introduced and at least one of them requires an elevated number of cases to test.
  • Cryptography
    Introduces new cryptography mechanisms or modifies existing functionality that involves cryptography
    Score anchors
    0
    No cryptography mechanisms are introduced.
    1
    A new cryptography mechanism is introduced but it is a well known mechanism that is known to have vast resources to aid on its testing.
    2
    Multiple new cryptography mechanisms are introduced that are well-known or a single but novel mechanism is introduced that is either untested or has limited resources.
    3
    Multiple new cryptography mechanisms are introduced and at least one of them is a novel mechanism.

Coordination

Cross-EIP interactions and behavior that clients must agree on before tests exist.

  • Cross-EIP interactions
    Introduces or modifies mechanisms that affect other EIPs in either the same or past forks.
    Score anchors
    0
    Fully self-contained EIP that does not depend on, modify, or conflict with any other EIP.
    1
    The EIP interacts with one or more other EIPs in a non-critical and limited way but can be tested independently for the most part.
    2
    The EIP depends on or modifies one or more other EIPs such that coordinated testing and consideration is required, but interactions are limited in scope and not complex.
    3
    The EIP has strong interdependencies with multiple EIPs, requiring extensive coordinated cross-EIP testing as well as potential re-design of existing test vectors.
    • +1 for every 3 additional interacting EIPs beyond the first 3, each of which requires its own coordinated test cases. List the EIPs in the rationale.
    • This row is intentionally uncapped, unlike every other anchor: each interacting EIP is another axis of the test matrix, so a ceiling would make a 12-EIP product indistinguishable from a 3-EIP one.
  • Unspecified behavior requiring cross-client consensus · not in checklist revision 1
    The EIP text does not determine the answer for cases a test can construct. Clients must agree on a previously unspecified detail before tests can be baselined. The cost here is coordination and re-baselining, not test writing.
    Score anchors
    0
    The EIP text determines the answer for every case a test could construct.
    1
    A few details are unspecified but have an obvious intended reading.
    2
    Details require client agreement before tests can be written, but they are localized.
    3
    A previously unspecified *and previously unobservable* behavior becomes consensus-critical; expect tests to be re-baselined on each round of EIP amendment.
    • Score this from the EIP's state at assessment time: whether it has client implementations, whether it has been through a devnet, and how many open questions remain on its discussion thread.