Retrospective LLM-Based Complexity Evaluations

EIP complexity assessment

EIP-7906: Transaction Assertions via State Diff Opcode

Assessed in Hegotá. The score describes the EIP text available at the snapshot, not the EIP as it stands today.

ProspectiveHegotáSnapshot 2026-10-07EIP-8081: CFILayers: execution
LLM Completescore 27
Human Available in open PRscore 23 · Checklist revision 2· ethspecs/pm #132

Evaluated on: · Spec revision: 2026-10-07 · 6dac5e7491 · EIP-8081 list: CFI

Scope at the cutoff. EIP-7906 adds three opcodes: TXTRACE (0xb6), TXDIFF (0xb7) and EVENTDATACOPY (0xb8). Together they expose the transaction's net state diff (balances, storage, newly deployed code, account change flags), the logs it emitted, the gas pre-charge and the gas payer. It also amends the EIP-8141 frame transaction with a new frame mode, POST_TX (3). POST_TX frames must form a contiguous trailing suffix, execute read-only as STATICCALLs, and cannot carry the atomic-batch flag; the frame directly before them cannot carry it either. If a POST_TX frame reverts or halts, the whole execution body is unconditionally rolled back, the validation prefix and gas payment stay committed, the remaining POST_TX frames are skipped with status 2, and the receipts of the reverted body frames lose their logs and state gas. The opcodes halt exceptionally outside POST_TX frames. TXDIFF is priced with EIP-2929 cold/warm costs and records accesses in the EIP-2929 access lists and the EIP-7928 block-level access list (BAL).

27HighHigh
Evaluator
LLMChecklist v3
Confidence
Medium
Under-specified at assessment cutoff
Yes — 6 criteria affected
Plausible range
26–34 (High)
Snapshot
2026-10-07 · EIP revision 6dac5e7491 (2026-10-07)
Score bands · Checklist revision 3
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the LLM total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. Cross-EIP interactions4
  2. Added opcodes3
  3. Edge/boundary conditions3
  4. EVM Gas rule changes2

Under-specified at assessment cutoff: Yes

The EIP text available at the assessment cutoff left material behavior unresolved. The affected criteria and the plausible total range record that uncertainty.

Why: Several observable outputs are ambiguous: gas_pre_charge contradicts the max_cost that EIP-8141 actually collects, and it is unclear whether remote storage queries warm the account and what codehash_before is for nonexistent accounts. Handling of the refund counter, warm/cold sets and approval context on a whole-body revert is not stated.

Unresolved questions at the cutoff (6)
  • Does gas_pre_charge use standard_gas_limit or max_gas, and max_fee_per_gas or the effective price, to match the amount EIP-8141 actually deducts?
  • Does a TXDIFF storage query (0x00/0x01) also warm the account, or record it in the BAL separately?
  • What does TXDIFF codehash_before/after return for a nonexistent account: the empty-code hash or 0?
  • On POST_TX failure, are the body's EIP-3529 refund-counter contributions and warm/cold additions discarded?
  • If a VERIFY frame after the payer is set (for example only_verify after pay) is part of the execution body, is its APPROVE_EXECUTION rolled back?
  • Does an out-of-gas TXDIFF record its target in the BAL?
Notable ambiguities noted by the assessor (4)
  • The gas_pre_charge formula (gas_limit × gas_price) does not match EIP-8141's max_cost collection.
  • Remote storage reads were left unpriced by EIP-2929 Note 2. TXDIFF defines only slot pricing, not account pricing.
  • The 'execution body' boundary relative to the validation prefix when SENDER or VERIFY frames are interleaved around payment approval.
  • Storage wipes of never-written slots are excluded, so account_change_flags==0 is not a full invariant.

Criterion breakdown

EIP-7906 Hegotá: LLM criterion scores and rationale
CriterionScoreWhy this scoreEvidence / uncertainty
Cross-EIP interactionsExceptional4The target couples EIP-8141 frame execution with EIP-2929 access pricing, EIP-7928 BAL recording, EIP-7708 log semantics, EIP-6780 deletion timing and EIP-7702 designators. Coordinated scenarios across these interactions are needed, so this is level 3.
  • eip.md · The `POST_TX` Frame Mode Amends EIP-8141 modes, atomic batches, receipts, default code and payer settlement.
  • eip.md · Transaction Diff Lookup Opcode > Gas Cost TXDIFF uses EIP-2929 cold/warm pricing and records accesses in the EIP-7928 BAL.
  • eip.md · State Difference Semantics EIP-7702 designators are excluded from contracts_deployed, EIP-6780 destroyed contracts still appear, and EIP-7708 transfer logs count as events.
  • eip.md · Rationale > Gas Pre-Charge Parameter EIP-4844 blob fees are included in gas_pre_charge.
Confidence: High
Uncertainty: Interactions with EIP-8037, EIP-3529 and EIP-7819 are referenced through EIP-8141 but not supplied.
Interacting EIPs: EIP-8141, EIP-2929, EIP-7928, EIP-7708, EIP-6780, EIP-7702, EIP-4844, EIP-1559
Added opcodes3Three instructions are added, and at least two are complex because their gas is dynamic. This is level 3.
  • eip.md · Specification, instruction table Defines TXTRACE 0xb6, TXDIFF 0xb7 and EVENTDATACOPY 0xb8.
  • eip.md · Transaction Diff Lookup Opcode > Gas Cost; Event Data Copy Opcode TXDIFF has dynamic cold/warm gas. EVENTDATACOPY has memory-expansion and copy gas.
Confidence: High
Edge/boundary conditions3There are many independent boundary-sensitive rules: index bounds, topic counts, reserved operands, copy bounds, suffix rules, cold/warm, and net-change inclusion. Two are elevated matrices. First, POST_TX failure × frame position × atomic-batch state × number of POST_TX frames × validation-prefix boundary, which changes receipts and committed state. Second, diff-entry inclusion × create/selfdestruct/delegation × write-then-restore. This is level 3.
  • eip.md · Transaction Trace Opcode param table; Reserved Inputs Out-of-range indices, missing topics and non-zero reserved operands cause an exceptional halt.
  • eip.md · Event Data Copy Opcode > Behavior EVENTDATACOPY halts when event_index ≥ events_count or when dataOffset+length exceeds the data length.
  • eip.md · The `POST_TX` Frame Mode Rules cover the contiguous suffix, the atomic flag on the preceding frame, failure ending execution, skipped frames getting status 2, and the body revert extending only up to the validation prefix.
  • eip.md · State Difference Semantics Net-change inclusion rules: restored values are excluded, storage wipes are excluded, delegation designators are excluded, and EIP-6780 created-and-destroyed contracts are included.
Confidence: High
EVM Gas rule changesUnder-specified2The EIP adds new accounting: remote storage-read pricing (cold SLOAD on any address, with no account-access charge), the gas schedules of the new opcodes, and gas settlement after a POST_TX-triggered body revert. Baseline operations keep their expected gas results, so this is level 2.
  • eip.md · Transaction Diff Lookup Opcode > Gas Cost TXDIFF storage params charge COLD_SLOAD_COST/WARM for an arbitrary (address, slot) pair, and balance/codehash params charge COLD_ACCOUNT_ACCESS_COST/WARM. The view params charge a flat 100.
  • supporting/eip-2929.md · Storage read changes, 'Note 2' EIP-2929 says pricing for remote cold storage reads is undefined, and any EIP adding them must define it. TXDIFF is such a remote storage read.
  • eip.md · The `POST_TX` Frame Mode, 'payer is fully charged for the gas consumed up to the point of the failure' A POST_TX failure reverts the execution body but keeps its execution gas charged. Skipped POST_TX frame budgets are refunded.
Confidence: Medium
Uncertainty: Two points are unspecified and could alter baseline-like settlement expectations: whether the EIP-3529 refund counter accumulated by the body is discarded on POST_TX failure, and whether a cold storage query also warms the account.
State-access ordering within opcode execution2TXDIFF is a new state-accessing operation that needs its own ordering and BAL-recording rule (cold/warm, live-state fallback versus diff-only answers, out-of-gas before access). No existing opcode class changes, so this is level 2.
  • eip.md · Transaction Diff Lookup Opcode > Gas Cost, 'added to the EIP-2929 access list after the call' For TXDIFF params 0x00–0x05, the accessed slot or address is added to the access list after the call and recorded in the EIP-7928 BAL. Params 0x06–0x0C and TXTRACE/EVENTDATACOPY add no accesses.
  • supporting/eip-7928.md · Gas Validation Before State Access BAL inclusion depends on a pre-state gas check passing before the access. TXDIFF is not in the table.
Confidence: Medium
Uncertainty: The text does not say whether an out-of-gas TXDIFF records the access in the BAL, or whether a storage query also records or warms the account.
State gas accounting changesUnder-specified2The existing EIP-8141 state-gas rollback mechanism is applied at a new site: a whole-body rollback spanning several frames and batches, triggered by a later frame. No new charging mechanism is added, so this is level 2.
  • eip.md · The `POST_TX` Frame Mode, 'the state gas recorded in them is removed, as for an unrolled EIP-8141 atomic batch' On POST_TX failure, the state gas of every execution-body frame is rolled back, reusing the atomic-batch rollback at a new, wider boundary.
  • supporting/eip-8141.md · State-gas attribution and refills The state-gas journal is restored at frame, call and batch boundaries, and cross-frame refills adjust earlier receipts.
Confidence: Medium
Uncertainty: Interplay of the body rollback with refills of charges owned by validation-prefix frames (for example a deploy frame) is not detailed.
New or modified transaction validity mechanisms2New static validity rules need dedicated cases, but they fit EIP-8141's existing static-constraint sequencing. This is level 2.
  • eip.md · The `POST_TX` Frame Mode, 'A frame transaction violating this is invalid' New static rules: mode 3 is accepted, POST_TX frames must form a contiguous suffix, and the atomic flag is invalid on a POST_TX frame and on the frame directly before one.
  • eip.md · The `POST_TX` Frame Mode, 'Neither a POST_TX revert nor an exceptional halt invalidates the transaction' A POST_TX failure is explicitly not a validity failure, unlike a VERIFY failure.
Confidence: Medium
New test-framework primitives2The target's suite needs a new expectation abstraction: a model computing the expected net diff and its sorted indices, event and topic views, and receipt transformations after a POST_TX failure. The frame builder also needs a local extension for the new mode. Other families are unaffected, so this is level 2.
  • eip.md · State Difference Semantics; Results Ordering Expected opcode outputs depend on a net, sorted transaction state diff and on log tables with per-address and per-topic views.
  • eip.md · The `POST_TX` Frame Mode Tests must build frame transactions with a POST_TX suffix and check a body revert with modified receipts.
Confidence: Medium
Security risksUnder-specified2The change alters EIP-8141's rollback and commit boundaries: which frames revert, payer charging, receipts, logs and state gas. Targeted adversarial integration cases are needed, for example payment approval placed after SENDER frames, atomic batches before POST_TX, and griefing through gas exhaustion. The interaction is bounded to frame execution, so this is level 2.
  • eip.md · The `POST_TX` Frame Mode, 'overrides the atomic-batch unrolling behavior' A later frame can now roll back earlier frames while the validation prefix and payment stay committed.
  • eip.md · Security Considerations > The `POST_TX` Frame Mode Not Reverting Validation Prefix The boundary between the committed prefix and the reverted body is safety-critical, including deploy-frame side effects.
  • eip.md · Security Considerations > Assertion Inputs Controlled by the Transaction Contracts can detect POST_TX context. Introspection breaks encapsulation.
Confidence: Medium
Uncertainty: It could be judged 3 if the body-revert boundary is considered to change trust invariants shared by mempool, settlement and BAL components.
Performance risks2Targeted integrated benchmarks are needed for a bounded interaction. The worst case is a full-gas execution body that maximizes touched slots and logs, followed by POST_TX frames using TXTRACE/TXDIFF topic and address views, and possibly a whole-body revert. These check that index construction and flat 100-gas pricing hold. This is level 2.
  • eip.md · Rationale > Gas Cost, 'A client can build an index over the diff and the logs when a POST_TX frame first reads them' Each call is priced at a flat 100 gas on the assumption of a lazily built index whose cost grows with the touched entries and logs.
  • eip.md · Assertion Gas Exhaustion, '~42,600 events' An attacker can pad a transaction with tens of thousands of events. Per-topic and per-address views must stay constant-time.
Confidence: Medium
Unspecified behavior requiring cross-client consensus2Several localized observable outcomes have competing interpretations: the gas_pre_charge value, codehash for nonexistent accounts, warming side effects, and refund-counter and access-set handling on body revert. Clients must agree on these before expected results can be fixed, so this is level 2.
  • eip.md · Transaction Trace Opcode, 'gas_pre_charge = gas_limit × gas_price + ...' The formula uses gas_limit × gas_price, but EIP-8141 collects max_cost = max_gas × max_fee_per_gas + blob cost. The returned value is ambiguous or contradictory.
  • supporting/eip-8141.md · Transaction settlement, 'max_cost = (max_gas * tx.fees.max_fee_per_gas' Defines the amount actually deducted at APPROVE.
  • eip.md · Transaction Diff Lookup Opcode > Gas Cost; 'codehash_before is equal to the empty-code hash for undeployed contracts' The text does not say whether a remote storage query warms the account, nor how codehash is reported for nonexistent accounts (EXTCODEHASH returns 0).
  • eip.md · The `POST_TX` Frame Mode, 'the entire execution body of a transaction is reverted' The body revert does not address the refund counter, warm/cold sets or approval context changes (for example APPROVE_EXECUTION after payer is set).
Confidence: Medium
Uncertainty: Could reach 3 if the net-diff view is considered to make previously unobservable intra-transaction bookkeeping consensus-visible across families.
Patterns affecting pre-existing tests1Rework is confined to boundary cases of frame-mode static validation (mode value 3) and to any undefined-opcode cases using 0xb6–0xb8, which still halt outside POST_TX. This is level 1.
  • eip.md · The `POST_TX` Frame Mode, 'POST_TX is added to the set of mode values accepted' Mode 3 changes from invalid to valid, so EIP-8141 invalid-mode boundary cases need rework.
  • eip.md · Specification, opcode table 0xb6/0xb7/0xb8 Previously undefined opcode bytes gain defined (context-restricted) behavior.
Confidence: Medium
Show 16 zero-score criteria
Zero-score criteria (Checklist revision 3)
CriterionScoreWhy this scoreEvidence / uncertainty
Modified opcodesUnder-specified0Existing instructions (APPROVE, FRAMEPARAM, ORIGIN) apply their existing rules in the new frame context. FRAMEPARAM can return mode 3, but that is a new value, not a new selector. No instruction's specified semantics change.
  • eip.md · The `POST_TX` Frame Mode, 'calling APPROVE anywhere in a POST_TX frame's call subtree is an ordinary STATICCALL violation' APPROVE in a POST_TX frame halts under the existing static-context rules. No new APPROVE semantics are defined.
  • eip.md · Backwards Compatibility States that no changes are made to existing opcodes.
Uncertainty: Treating APPROVE's halt in POST_TX as a change of its availability, rather than inherited STATICCALL behavior, would make this 3.
Added precompiles0None added.
  • eip.md · Backwards Compatibility No precompiles are added.
Modified precompiles0None modified.
  • eip.md · Backwards Compatibility No precompile changes.
Added system contracts0No protocol-designated contract is introduced.
  • eip.md · Specification Only opcodes and a frame mode are defined. Assertion contracts are application contracts.
Modified system contracts0No existing system contract is affected.
  • eip.md · Specification No system contract is referenced or changed.
Blob gas accounting changes0No blob-gas charging, pricing or limit rule changes. The blob fee is only exposed for reading.
  • eip.md · Transaction Trace Opcode, 'gas_pre_charge = gas_limit × gas_price + blob_count × GAS_PER_BLOB × blob_base_fee' Blob fees are only reported through a read-only TXTRACE param. Blob charging is unchanged.
New EVM gas refundUnder-specified0Returning unused gas from skipped frames reuses the existing EIP-8141 settlement. No new protocol refund mechanism is introduced.
  • eip.md · The `POST_TX` Frame Mode, 'their gas is refunded at the end of the transaction' Unexecuted POST_TX frame budgets are returned as unused gas, in the same way as skipped atomic-batch frames.
Uncertainty: Discarding the body's EIP-3529 refund-counter contributions on POST_TX failure is implied, not stated.
New transaction types0No new EIP-2718 type.
  • eip.md · The `POST_TX` Frame Mode Amends the existing EIP-8141 frame transaction and adds no new envelope.
New block / header fields0None.
  • eip.md · Specification No header fields are added.
Encoding changes (RLP/SSZ)0Only new values within unchanged schemas.
  • eip.md · Constants, 'POST_TX = 3' A new value goes into the existing frame `mode` field. The receipt schema is reused.
  • supporting/eip-8141.md · Receipt Encoding The frame receipt schema [status, gas_used, logs] already allows status 2.
Block syncing changes0No block decoding or structural rule changes.
  • eip.md · The `POST_TX` Frame Mode Changes affect frame-transaction validity and execution, not block RLP decoding or structural validation.
New fork activation mechanism0Only rule selection at activation.
  • eip.md · Backwards Compatibility Opcodes occupy unused slots. No state migration or code installation is mentioned.
Engine API changes0No Engine API field or endpoint changes.
  • eip.md · Backwards Compatibility No Engine API changes are described.
Transition-tool interface changesUnder-specified0No new transition-tool field or mechanism is needed. Frame mode values and receipts use existing EIP-8141 schemas.
  • eip.md · The `POST_TX` Frame Mode POST_TX is a new value of the existing frame `mode` field. The receipt shape, including status 2, is unchanged.
Uncertainty: No transition-tool evidence was supplied. If tools need to expose the computed diff or the payer separately for debugging, this could be level 1.
New invariant on pre-existing tests0Baseline tests gain no new output to assert.
  • eip.md · Backwards Compatibility Existing opcodes, transaction types and precompiles are unchanged. No new receipt or header output is produced for baseline transactions.
Cryptography0No cryptographic verification, signing or hashing rule changes.
  • eip.md · Transaction Trace Opcode, param 0x0B 'codehash_after' Only existing code hashes are reported. No cryptographic rule is added.
Assessment provenance
Assessed EIP revision
ethereum/EIPs@6dac5e7491 EIPS/eip-7906.md committed 2026-10-07 · information cutoff 2026-10-07T22:23:55Z
Current master · File history · blob 5ec349d092 · sha256 d7438d26b149
Rubric
Checklist revision 3 · ethspecs/pm@fe2f793b03
Evaluator
Opus 5.5 (claude-opus-5-5) at high effort, one tool-less call per EIP · isolation bubblewrap_claude_p_no_tools_v1
Source record
Frozen research record research/tasks/10-opus-v3-reassessment/prospective/outputs/assessments/hegota-2026-10-08/eip-7906.yaml · sha256 344daa0d677d
Supporting documents supplied with the EIP
supporting/eip-20.md, supporting/eip-721.md, supporting/eip-1155.md, supporting/eip-1559.md, supporting/eip-2929.md, supporting/eip-4844.md, supporting/eip-6780.md, supporting/eip-7702.md, supporting/eip-7708.md, supporting/eip-7928.md, supporting/eip-8141.md

Evaluated on: Not recorded

23HighHigh
Evaluator
HumanChecklist v2
Confidence
Not recorded
Under-specified at assessment cutoff
Not recorded in the checklist
Checklist published
2026-08-24
Score bands · Checklist revision 2
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the Human total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. Cross-EIP interactions4
  2. Added opcodes3
  3. Edge/boundary conditions3
  4. State-access ordering within opcode execution2

Criterion breakdown

EIP-7906 Hegotá: Human criterion scores and rationale
CriterionScoreWhy this scoreNotes
Cross-EIP interactionsExceptional4Strong interdependencies. **EIP-8141** is a hard dependency that this EIP *amends* — nothing here is testable without it, and EIP-8141 is itself Draft and assessed 🔴 38. **EIP-2929** (pricing, and `TXDIFF` mutates the access list), **EIP-7928** (BAL recording for live-state reads), **EIP-7702** (designators excluded from `contracts_deployed`), **EIP-4844** (blob fees folded into `gas_pre_charge`). <br><br>The "valid only inside a `POST_TX` frame" restriction then pulls in every transaction type as a negative case: the three opcodes must be shown to halt in legacy, **EIP-2930**, **EIP-1559**, **EIP-4844** and **EIP-7702** transactions, and in the `DEFAULT`, `VERIFY` and `SENDER` frame modes — roughly 3 x 8 coordinated cases, each owned by a different EIP's transaction format. With **EIP-2718** framing those types, 8 interacting EIPs gives +1 for 5 beyond the first 3.—
Added opcodes3Three new opcodes, at least one complex: `TXTRACE` (22 params), `TXDIFF` (11 params, dynamic warm/cold gas), `EVENTDATACOPY` (4 stack inputs, memory expansion, `CALLDATACOPY` semantics).—
Edge/boundary conditions3Elevated case counts. `TXTRACE` has 22 params and `TXDIFF` 11, each with index bounds; every *must be 0* operand halts on non-zero; `event_topic0`–`3` halt past `event_topic_count`; `EVENTDATACOPY` halts on both out-of-range index and `dataOffset + length`. Plus net-zero collapsing (modified-then-restored sets no entry and no flag bit), canonical uint160/uint256 sort order, `CREATE` leaving empty code, and EIP-7702 designators excluded from `contracts_deployed`.—
State-access ordering within opcode execution2New state-accessing operations whose position must be settled per param. `TXDIFF` 0x00–0x05 read live state and record in the EIP-7928 BAL; 0x06–0x0A answer from the diff and touch neither. Each of the 11 params needs its access-list and BAL behaviour verified.—
New or modified transaction validity mechanisms2Amends EIP-8141's structural rules: `assert frame.mode < 3` becomes `< 4`, and `POST_TX` frames must form a contiguous trailing suffix or the transaction is invalid. Coordinated with EIP-8141 but no existing vectors to redesign.—
New test-framework primitives2New primitives needed to build `POST_TX` frames and to express an expected transaction diff and event enumeration. The BAL expectation types are the closest existing analogue but do not cover balances, codehashes or event ordering.—
Security risks2Introspection is inert: `POST_TX` is a `STATICCALL` that cannot modify state. But `TXDIFF` can still add arbitrary storage keys to the BAL reads, and we need to prove that this does not affect present usecases or future EIPs (the witness generation is affected by this).—
Performance risks2`TXDIFF` 0x00–0x05 take an arbitrary address, so this is the first mechanism by which execution can read another account's storage slot. Those reads enter the BAL, so an assertion can populate the BAL with `(address, slot)` pairs the owning contract never touched, which breaks the assumption that a BAL entry implies interaction by that contract.—
Unspecified behavior requiring cross-client consensus2Previously unobservable behaviour becomes consensus-critical and has to be settled by discussion before vectors can be baselined: what counts as a change, how net-zero writes collapse, and the canonical enumeration order. Localized to the diff model.—
EVM Gas rule changes1EIP-2929 access-list accounting is extended to a new class of read: `TXDIFF` params 0x00–0x05 fall back to live state, priced warm/cold, and add the slot or address to the access list afterwards.—
Show 18 zero-score criteria
Zero-score criteria (Checklist revision 2)
CriterionScoreWhy this scoreNotes
Modified opcodes0No rationale recorded.
Blank cell read as zero because the published total proves it.
Added precompiles0No rationale recorded.
Blank cell read as zero because the published total proves it.
Modified precompiles0No rationale recorded.
Blank cell read as zero because the published total proves it.
Added system contracts0No rationale recorded.
Blank cell read as zero because the published total proves it.
Modified system contracts0No rationale recorded.
Blank cell read as zero because the published total proves it.
Blob gas accounting changes0No rationale recorded.
Blank cell read as zero because the published total proves it.
State gas accounting changes0No rationale recorded.
Blank cell read as zero because the published total proves it.
New EVM gas refund0No rationale recorded.
Blank cell read as zero because the published total proves it.
New transaction types0No rationale recorded.
Blank cell read as zero because the published total proves it.
New block / header fields0No rationale recorded.
Blank cell read as zero because the published total proves it.
Encoding changes (RLP/SSZ)0No rationale recorded.
Blank cell read as zero because the published total proves it.
Block syncing changes0No rationale recorded.
Blank cell read as zero because the published total proves it.
New fork activation mechanism0No rationale recorded.
Blank cell read as zero because the published total proves it.
Engine API changes0No rationale recorded.
Blank cell read as zero because the published total proves it.
Transition-tool interface changes0No rationale recorded.
Blank cell read as zero because the published total proves it.
Patterns affecting pre-existing tests0Additive. The three opcodes halt outside a `POST_TX` frame, so legacy and EIP-1559 transactions are unaffected.—
New invariant on pre-existing tests0No rationale recorded.
Blank cell read as zero because the published total proves it.
Cryptography0No rationale recorded.
Blank cell read as zero because the published total proves it.
Assessment provenance
Rubric
Checklist revision 2 · ethspecs/pm@3d8c0128c5
Evaluator
STEEL team · ethspecs/pm complexity_assessments
Source record
Open pull request #132: Add EIP-7906 complexity assessment · checklist at 18cfcab5e2 · updated 2026-08-24
blob e2bc9d7fc5 · sha256 34e1b22f395f
Research record
research/tasks/09-hegota-human-assessment-snapshot/outputs/assessments/eip-7906.yaml · sha256 f363d8a27dc3

The LLM applied checklist revision 3 and the human reviewers revision 2 to EIP-7906 in Hegotá. Revision 3 phrases the same criteria more precisely; differences cover the 28 criteria both revisions share, and each total keeps its own revision. Δ is LLM minus Human.

Using the latest scored LLM evaluation for this checklist: 2026-10-08 · spec 2026-10-07 · 6dac5e7491. The Human and LLM assessments may use different spec revisions.

LLM27High
Human23High
Δ total+4Same tier
Criteria25/28agree exactly · 2 differ by 1 · 1 differ by 2+

Complexity profiles side by side

LLM
Human

Largest disagreements: State gas accounting changes (+2), EVM Gas rule changes (+1), Patterns affecting pre-existing tests (+1)

Per-criterion scores, Human versus LLM, ordered by the size of the difference
CriterionLLMHumanΔAgreementRationale from each source
State gas accounting changes20+2Differ by 2+
Show rationale

LLM The existing EIP-8141 state-gas rollback mechanism is applied at a new site: a whole-body rollback spanning several frames and batches, triggered by a later frame. No new charging mechanism is added, so this is level 2.

Human No rationale recorded.

EVM Gas rule changes21+1Differ by 1
Show rationale

LLM The EIP adds new accounting: remote storage-read pricing (cold SLOAD on any address, with no account-access charge), the gas schedules of the new opcodes, and gas settlement after a POST_TX-triggered body revert. Baseline operations keep their expected gas results, so this is level 2.

Human EIP-2929 access-list accounting is extended to a new class of read: `TXDIFF` params 0x00–0x05 fall back to live state, priced warm/cold, and add the slot or address to the access list afterwards.

Patterns affecting pre-existing tests10+1Differ by 1
Show rationale

LLM Rework is confined to boundary cases of frame-mode static validation (mode value 3) and to any undefined-opcode cases using 0xb6–0xb8, which still halt outside POST_TX. This is level 1.

Human Additive. The three opcodes halt outside a `POST_TX` frame, so legacy and EIP-1559 transactions are unaffected.

Added opcodes330Agree
Show rationale

LLM Three instructions are added, and at least two are complex because their gas is dynamic. This is level 3.

Human Three new opcodes, at least one complex: `TXTRACE` (22 params), `TXDIFF` (11 params, dynamic warm/cold gas), `EVENTDATACOPY` (4 stack inputs, memory expansion, `CALLDATACOPY` semantics).

Modified opcodes000Agree
Show rationale

LLM Existing instructions (APPROVE, FRAMEPARAM, ORIGIN) apply their existing rules in the new frame context. FRAMEPARAM can return mode 3, but that is a new value, not a new selector. No instruction's specified semantics change.

Human No rationale recorded.

Added precompiles000Agree
Show rationale

LLM None added.

Human No rationale recorded.

Modified precompiles000Agree
Show rationale

LLM None modified.

Human No rationale recorded.

Added system contracts000Agree
Show rationale

LLM No protocol-designated contract is introduced.

Human No rationale recorded.

Modified system contracts000Agree
Show rationale

LLM No existing system contract is affected.

Human No rationale recorded.

State-access ordering within opcode execution220Agree
Show rationale

LLM TXDIFF is a new state-accessing operation that needs its own ordering and BAL-recording rule (cold/warm, live-state fallback versus diff-only answers, out-of-gas before access). No existing opcode class changes, so this is level 2.

Human New state-accessing operations whose position must be settled per param. `TXDIFF` 0x00–0x05 read live state and record in the EIP-7928 BAL; 0x06–0x0A answer from the diff and touch neither. Each of the 11 params needs its access-list and BAL behaviour verified.

Blob gas accounting changes000Agree
Show rationale

LLM No blob-gas charging, pricing or limit rule changes. The blob fee is only exposed for reading.

Human No rationale recorded.

New EVM gas refund000Agree
Show rationale

LLM Returning unused gas from skipped frames reuses the existing EIP-8141 settlement. No new protocol refund mechanism is introduced.

Human No rationale recorded.

New transaction types000Agree
Show rationale

LLM No new EIP-2718 type.

Human No rationale recorded.

New or modified transaction validity mechanisms220Agree
Show rationale

LLM New static validity rules need dedicated cases, but they fit EIP-8141's existing static-constraint sequencing. This is level 2.

Human Amends EIP-8141's structural rules: `assert frame.mode < 3` becomes `< 4`, and `POST_TX` frames must form a contiguous trailing suffix or the transaction is invalid. Coordinated with EIP-8141 but no existing vectors to redesign.

New block / header fields000Agree
Show rationale

LLM None.

Human No rationale recorded.

Encoding changes (RLP/SSZ)000Agree
Show rationale

LLM Only new values within unchanged schemas.

Human No rationale recorded.

Block syncing changes000Agree
Show rationale

LLM No block decoding or structural rule changes.

Human No rationale recorded.

New fork activation mechanism000Agree
Show rationale

LLM Only rule selection at activation.

Human No rationale recorded.

Engine API changes000Agree
Show rationale

LLM No Engine API field or endpoint changes.

Human No rationale recorded.

Transition-tool interface changes000Agree
Show rationale

LLM No new transition-tool field or mechanism is needed. Frame mode values and receipts use existing EIP-8141 schemas.

Human No rationale recorded.

New invariant on pre-existing tests000Agree
Show rationale

LLM Baseline tests gain no new output to assert.

Human No rationale recorded.

New test-framework primitives220Agree
Show rationale

LLM The target's suite needs a new expectation abstraction: a model computing the expected net diff and its sorted indices, event and topic views, and receipt transformations after a POST_TX failure. The frame builder also needs a local extension for the new mode. Other families are unaffected, so this is level 2.

Human New primitives needed to build `POST_TX` frames and to express an expected transaction diff and event enumeration. The BAL expectation types are the closest existing analogue but do not cover balances, codehashes or event ordering.

Security risks220Agree
Show rationale

LLM The change alters EIP-8141's rollback and commit boundaries: which frames revert, payer charging, receipts, logs and state gas. Targeted adversarial integration cases are needed, for example payment approval placed after SENDER frames, atomic batches before POST_TX, and griefing through gas exhaustion. The interaction is bounded to frame execution, so this is level 2.

Human Introspection is inert: `POST_TX` is a `STATICCALL` that cannot modify state. But `TXDIFF` can still add arbitrary storage keys to the BAL reads, and we need to prove that this does not affect present usecases or future EIPs (the witness generation is affected by this).

Performance risks220Agree
Show rationale

LLM Targeted integrated benchmarks are needed for a bounded interaction. The worst case is a full-gas execution body that maximizes touched slots and logs, followed by POST_TX frames using TXTRACE/TXDIFF topic and address views, and possibly a whole-body revert. These check that index construction and flat 100-gas pricing hold. This is level 2.

Human `TXDIFF` 0x00–0x05 take an arbitrary address, so this is the first mechanism by which execution can read another account's storage slot. Those reads enter the BAL, so an assertion can populate the BAL with `(address, slot)` pairs the owning contract never touched, which breaks the assumption that a BAL entry implies interaction by that contract.

Edge/boundary conditions330Agree
Show rationale

LLM There are many independent boundary-sensitive rules: index bounds, topic counts, reserved operands, copy bounds, suffix rules, cold/warm, and net-change inclusion. Two are elevated matrices. First, POST_TX failure × frame position × atomic-batch state × number of POST_TX frames × validation-prefix boundary, which changes receipts and committed state. Second, diff-entry inclusion × create/selfdestruct/delegation × write-then-restore. This is level 3.

Human Elevated case counts. `TXTRACE` has 22 params and `TXDIFF` 11, each with index bounds; every *must be 0* operand halts on non-zero; `event_topic0`–`3` halt past `event_topic_count`; `EVENTDATACOPY` halts on both out-of-range index and `dataOffset + length`. Plus net-zero collapsing (modified-then-restored sets no entry and no flag bit), canonical uint160/uint256 sort order, `CREATE` leaving empty code, and EIP-7702 designators excluded from `contracts_deployed`.

Cryptography000Agree
Show rationale

LLM No cryptographic verification, signing or hashing rule changes.

Human No rationale recorded.

Cross-EIP interactions440Agree
Show rationale

LLM The target couples EIP-8141 frame execution with EIP-2929 access pricing, EIP-7928 BAL recording, EIP-7708 log semantics, EIP-6780 deletion timing and EIP-7702 designators. Coordinated scenarios across these interactions are needed, so this is level 3.

Human Strong interdependencies. **EIP-8141** is a hard dependency that this EIP *amends* — nothing here is testable without it, and EIP-8141 is itself Draft and assessed 🔴 38. **EIP-2929** (pricing, and `TXDIFF` mutates the access list), **EIP-7928** (BAL recording for live-state reads), **EIP-7702** (designators excluded from `contracts_deployed`), **EIP-4844** (blob fees folded into `gas_pre_charge`). <br><br>The "valid only inside a `POST_TX` frame" restriction then pulls in every transaction type as a negative case: the three opcodes must be shown to halt in legacy, **EIP-2930**, **EIP-1559**, **EIP-4844** and **EIP-7702** transactions, and in the `DEFAULT`, `VERIFY` and `SENDER` frame modes — roughly 3 x 8 coordinated cases, each owned by a different EIP's transaction format. With **EIP-2718** framing those types, 8 interacting EIPs gives +1 for 5 beyond the first 3.

Unspecified behavior requiring cross-client consensus220Agree
Show rationale

LLM Several localized observable outcomes have competing interpretations: the gas_pre_charge value, codehash for nonexistent accounts, warming side effects, and refund-counter and access-set handling on body revert. Clients must agree on these before expected results can be fixed, so this is level 2.

Human Previously unobservable behaviour becomes consensus-critical and has to be settled by discussion before vectors can be baselined: what counts as a change, how net-zero writes collapse, and the canonical enumeration order. Localized to the diff model.

Criterion legend and glossary

Every stacked bar, comparison matrix, and criterion table on this site uses the same criterion colours, abbreviations, and order. Colour marks the criterion group; the abbreviation and name identify the criterion. Scores are 0–3 per criterion (4 is exceptional; cross-EIP interactions is uncapped).

EVM surface

Opcodes, precompiles, and system contracts that are added or modified.

  • Added opcodes
    Introduces new opcodes
    Score anchors
    0
    No new opcodes are introduced.
    1
    A new simple opcode is introduced (no data portion, no complex stack mechanics, and a constant gas cost).
    2
    Multiple new simple opcodes are introduced, or a single new complex opcode is introduced (has data portion, or complex stack mechanics, or a dynamic gas cost).
    3
    Multiple new opcodes are introduced, and at least one of them is complex (has data portion, or complex stack mechanics, or a dynamic gas cost).
    • Cryptography opcodes are not considered complex by default. Refer to the "Cryptography" section for a separate assessment.
  • Modified opcodes
    Modifies pre-existing opcodes
    Score anchors
    0
    No pre-existing opcode modifications are introduced.
    3
    At least one pre-existing opcode's behavior is modified (not including gas changes) or a pre-existing opcode is deprecated.
  • Added precompiles
    Introduces new precompiles
    Score anchors
    0
    No new precompiles are introduced.
    1
    A new simple precompile is introduced (constant input length, constant gas cost).
    2
    Multiple new simple precompiles are introduced, or a single new complex precompile is introduced (dynamic input length or dynamic gas cost).
    3
    Multiple new precompiles are introduced, and at least one of them is complex (dynamic input length or dynamic gas cost).
    • Cryptography precompiles are not considered complex by default. Refer to the "Cryptography" for a separate assessment.
  • Modified precompiles
    Modifies pre-existing precompiles logic or gas-accounting
    Score anchors
    0
    No pre-existing precompiles are modified.
    1
    At least one pre-existing precompile has its gas schedule modified.
    2
    Multiple pre-existing precompiles have their gas schedule modified, or a single pre-existing precompile has its behavior modified.
    3
    The behavior of multiple pre-existing precompiles, or a single complex pre-existing precompile modified.
  • Added system contracts
    Introduces new system contract, stateful or not
    Score anchors
    0
    No new system contracts are introduced.
    1
    A new system contract is introduced that is not stateful nor does it trigger a new system action (e.g. requests to the consensus layer).
    2
    Multiple new system contracts are introduced or a single new system contract that is either stateful or triggers a new system action (e.g. requests to the consensus layer).
    3
    Multiple new system contracts are introduced and at least one of them is either stateful or triggers a new system action (e.g. requests to the consensus layer).
  • Modified system contracts
    Modifies pre-existing system contracts
    Score anchors
    0
    No modifications to pre-existing system contracts are introduced, directly or indirectly.
    1
    Does not directly modify any system contract, but its behavior has minor indirect effects on one or more system contracts.
    2
    Does not directly modify any system contract, but its behavior has major indirect effects on one or more system contracts.
    3
    At least one pre-existing system contract code or state is modified, which would involve irregular state transition or a similarly complex transition methodology.

Gas and accounting

Execution, blob, and state gas rules, refunds, and where charges happen inside opcodes.

  • EVM Gas rule changes
    New EVM gas accounting rules
    Score anchors
    0
    No gas accounting changes.
    1
    Existing gas accounting mechanism is updated.
    2
    A new gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State-access ordering within opcode execution · not in checklist revision 1
    Changes *where inside an opcode's execution* state is accessed, or where gas is charged relative to that access. Because a state access is recorded in the block-level access list only if execution had enough gas to reach it, this ordering is consensus-critical: moving it changes the BAL at every gas boundary of every affected opcode.
    Score anchors
    0
    No change to where state is accessed, or to where gas is charged relative to a state access, within any opcode.
    1
    A single opcode's state-access or gas-charge ordering changes.
    2
    Multiple opcodes' ordering changes, or a new state-accessing operation is introduced whose position in the order must be settled.
    3
    The ordering rule changes for a whole class of state-accessing opcodes at once, or what counts as a recordable state access is redefined — requiring existing BAL vectors to be re-derived across opcodes and forks.
    • Distinct from "Modified opcodes", which asks whether an opcode's **result** changed. This row asks about the **path to the result**, which is observable even when the result is identical. An EIP can be 0 on that row and 3 on this one.
    • Score changes **to** the ordering. Do not score the fact that state accesses are observable — they always are.
    • Each boundary must be re-tested against every other dimension that can change the answer (cold/warm, static/non-static, delegated/direct, revert/success), so the case count grows multiplicatively rather than additively. Note this explicitly under Special Considerations.
  • Blob gas accounting changes
    New Blob gas accounting rules which potentially affect pre-existing tests
    Score anchors
    0
    No blob gas accounting changes.
    1
    Existing blob gas accounting mechanism is updated.
    2
    A new blob gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new blob gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State gas accounting changes · not in checklist revision 1
    New state gas accounting rules. State gas is the cost of *writing* state, as opposed to accessing or executing it: `StateGasCosts`, `COST_PER_STATE_BYTE`, the block-level state gas budget, and the spill path into execution gas.
    Score anchors
    0
    No state gas accounting changes.
    1
    An existing state gas cost or `STATE_BYTES_PER_*` rate is adjusted.
    2
    A new state-gas-charging site is introduced, or the block-level state gas budget or reservoir allocation is modified.
    3
    A new state gas charging mechanism is introduced, or the spill interaction between state gas and execution gas is modified, affecting existing gas tests.
    • Harder to test than blob gas: the spill path means state gas cannot be metered independently of execution gas, and some costs (e.g. `NEW_ACCOUNT`) are state-dependent.
  • New EVM gas refund
    New gas-refund mechanism
    Score anchors
    0
    No new gas-refund mechanisms are introduced.
    1
    A new simple gas-refund mechanism is introduced that does not affect either existing tests or existing gas-refund mechanisms.
    2
    A new complex gas-refund mechanism is introduced or a simple mechanism that affects existing tests or existing gas-refund mechanisms.
    3
    A new complex gas-refund mechanism is introduced that affects existing tests or existing gas-refund mechanisms.

Blocks, transactions, and encoding

Transaction types and validity, block and header fields, encodings, syncing, and activation-time changes.

  • New transaction types
    Introduces a new transaction type
    Score anchors
    0
    No new transaction types are introduced.
    3
    A new transaction type is introduced.
  • New or modified transaction validity mechanisms
    Creates new or modifies pre-existing transaction types' validation mechanisms
    Score anchors
    0
    No changes are introduced to the validity rules of existing transaction types or to their intrinsic gas cost calculation.
    1
    Minor adjustments are introduced to validity rules or intrinsic gas cost calculation, but they do not significantly affect existing tests.
    2
    Changes to validity rules or intrinsic gas cost calculation affect existing tests, but require only limited updates to test cases and no redesign of the testing infrastructure.
    3
    Changes to validity rules or intrinsic gas cost calculation require extensive rework or redesign of the tests or testing infrastructure.
  • New block / header fields
    Introduces new block or block header fields
    Score anchors
    0
    No new block or header fields are introduced.
    3
    A new block or header field is introduced.
  • Encoding changes (RLP/SSZ)
    Introduces encoding changes at the transaction/block/interfaces level
    Score anchors
    0
    No encoding changes are introduced at the transaction, block, or interfaces levels.
    3
    An encoding change is introduced at transaction, block or interfaces level (e.g. RLP -> SSZ).
    • "Interfaces level" includes the Engine API. Score an Engine API encoding change (e.g. JSON -> SSZ) here.
  • Block syncing changes
    Modifies block RLP validation mechanisms that require test client syncing.
    Score anchors
    0
    No new RLP validation mechanism is introduced.
    1
    A single simple RLP validation mechanism is introduced.
    2
    Multiple simple RLP validation mechanisms are introduced or a single complex one.
    3
    Multiple RLP validation mechanisms are introduced and at least one of them is deemed complex.
  • New fork activation mechanism
    Modifies state, internal variables, or similar, at the fork activation block
    Score anchors
    0
    No state modifications, internal variables or similar are modified at the fork activation block.
    3
    Either a state modification or internal variables are modified at the fork activation block.
    • Initialization of new internal variable is not considered a modification.

Client interfaces

Engine API and transition-tool interface changes.

  • Engine API changes
    Introduces new fields to the Engine API directives
    Score anchors
    0
    No new fields or communication mechanisms are introduced to the Engine API.
    1
    A single new field is introduced in one of the Engine API endpoints.
    2
    Multiple fields are introduced to one or multiple Engine API end points, or a new Engine API end-point is introduced.
    3
    Multiple fields are introduced to one or multiple Engine API end points and a new Engine API end-point is introduced.
  • Engine API encoding changes · Checklist revision 1 only
    Engine API encoding changes (the revision-1 template defines no anchor text for this row).
  • Transition-tool interface changes
    Modifies or adds new fields to the transition tool interface.
    Score anchors
    0
    No modifications to the transition tool interface are required.
    1
    A single new field needs to be introduced to the transition tool interface.
    2
    Multiple new fields or a new mechanism has to be introduced to the transition tool interface.
    3
    Multiple new fields and a new mechanism has to be introduced to the transition tool interface.
    • Special consideration must be paid to this section if the EIP introduces a mechanism that requires the state transition tool to be aware whether the block it is processing is the fork-activation block.

Testing impact

Rework, new invariants, and new primitives required in the test framework.

  • Patterns affecting pre-existing tests
    Implements a new validation mechanism or rule that translates in reworking pre-existing tests
    Score anchors
    0
    No pre-existing tests are affected by this change.
    1
    Minor subset of existing tests are affected by this change.
    2
    Considerable subset of existing tests are affected by this change but involves only a contrived category of tests.
    3
    Major subset of existing tests are affected, including diverse category of tests (benchmarks, static, multiple forks, etc.).
  • New invariant on pre-existing tests · not in checklist revision 1
    Tests that are **not about this EIP** must nonetheless assert something this EIP produces. Their logic does not change; they gain a new thing to check.
    Score anchors
    0
    Pre-existing tests assert nothing new.
    1
    A narrow, contrived category of pre-existing tests gains a new assertion.
    2
    A broad category gains a new assertion, applied mechanically.
    3
    Every test in the fork gains the assertion regardless of what it tests, and pre-fork vectors must be re-derived to satisfy it.
    • Paired with the row above, and easy to confuse with it. "Patterns affecting pre-existing tests" asks whether existing tests must be **reworked**; this row asks whether they must **additionally assert something new**. Score both — an EIP can be low on one and high on the other.
  • New test-framework primitives · not in checklist revision 1
    Requires new abstractions in the test framework itself — expectation types, modifiers, helpers — beyond writing test functions with what already exists.
    Score anchors
    0
    Existing test primitives suffice.
    1
    Existing primitives need minor extension.
    2
    New expectation or modifier primitives are required, reusable within this EIP's own test suite.
    3
    New framework-level primitives are required that become a permanent part of the framework and are used by other EIPs' tests.

Risk and validation

Security, performance, boundary conditions, and cryptography that need validation.

  • Security risks
    Introduces or modifies mechanisms that could compromise the security of the chain, users, validators, or other stakeholders, if not implemented properly.
    Score anchors
    0
    No new mechanisms are introduced that could pose a security risk.
    1
    The introduced mechanisms are self-contained, can be validated in isolation, and do not alter existing invariants that could pose a security risk for any stakeholders.
    2
    The introduced mechanisms interact with a limited number of existing components, slightly altering their security assumptions and requiring a targeted security review or fuzzing.
    3
    The introduced mechanisms interact with multiple existing components, including critical ones, substantially altering their security assumptions and requiring an extensive security review and fuzzing.
  • Performance risks
    Introduces or modifies mechanisms and requires performance validation.
    Score anchors
    0
    No new mechanisms are introduced that require performance validation.
    1
    The introduced mechanisms can be benchmarked in isolation and do not affect existing performance behavior.
    2
    The introduced mechanisms cannot be fully benchmarked in isolation, but they only have a limited impact on the existing performance benchmarks.
    3
    The introduced mechanisms cannot be benchmarked in isolation and have a substantial impact on existing performance benchmarks or have complex interactions with existing mechanisms.
  • Edge/boundary conditions
    Feature contains edge/boundary conditions.
    Score anchors
    0
    No discernible edge cases or boundary conditions are introduced.
    1
    A single edge-case or boundary-condition prone mechanism is introduced.
    2
    Multiple edge-case or boundary-condition prone mechanisms are introduced, but none of them requires an elevated number of cases to test.
    3
    Multiple edge-case or boundary-condition prone mechanisms are introduced and at least one of them requires an elevated number of cases to test.
  • Cryptography
    Introduces new cryptography mechanisms or modifies existing functionality that involves cryptography
    Score anchors
    0
    No cryptography mechanisms are introduced.
    1
    A new cryptography mechanism is introduced but it is a well known mechanism that is known to have vast resources to aid on its testing.
    2
    Multiple new cryptography mechanisms are introduced that are well-known or a single but novel mechanism is introduced that is either untested or has limited resources.
    3
    Multiple new cryptography mechanisms are introduced and at least one of them is a novel mechanism.

Coordination

Cross-EIP interactions and behavior that clients must agree on before tests exist.

  • Cross-EIP interactions
    Introduces or modifies mechanisms that affect other EIPs in either the same or past forks.
    Score anchors
    0
    Fully self-contained EIP that does not depend on, modify, or conflict with any other EIP.
    1
    The EIP interacts with one or more other EIPs in a non-critical and limited way but can be tested independently for the most part.
    2
    The EIP depends on or modifies one or more other EIPs such that coordinated testing and consideration is required, but interactions are limited in scope and not complex.
    3
    The EIP has strong interdependencies with multiple EIPs, requiring extensive coordinated cross-EIP testing as well as potential re-design of existing test vectors.
    • +1 for every 3 additional interacting EIPs beyond the first 3, each of which requires its own coordinated test cases. List the EIPs in the rationale.
    • This row is intentionally uncapped, unlike every other anchor: each interacting EIP is another axis of the test matrix, so a ceiling would make a 12-EIP product indistinguishable from a 3-EIP one.
  • Unspecified behavior requiring cross-client consensus · not in checklist revision 1
    The EIP text does not determine the answer for cases a test can construct. Clients must agree on a previously unspecified detail before tests can be baselined. The cost here is coordination and re-baselining, not test writing.
    Score anchors
    0
    The EIP text determines the answer for every case a test could construct.
    1
    A few details are unspecified but have an obvious intended reading.
    2
    Details require client agreement before tests can be written, but they are localized.
    3
    A previously unspecified *and previously unobservable* behavior becomes consensus-critical; expect tests to be re-baselined on each round of EIP amendment.
    • Score this from the EIP's state at assessment time: whether it has client implementations, whether it has been through a devnet, and how many open questions remain on its discussion thread.