Retrospective LLM-Based Complexity Evaluations

EIP complexity assessment

EIP-7997: Deterministic Factory Contract

Assessed in Amsterdam / Glamsterdam. The score describes the EIP text available at the assessment cutoff, not the EIP as it stands today.

RetrospectiveAmsterdam / GlamsterdamAssessment cutoff 2025-08-21Included by cutoffLayers: execution
LLM Completescore 12
Human Completescore 5 · Checklist revision 1· merged checklist

Evaluated on: · Spec revision: 2025-08-19 · f8be9ce27b

Scope at the cutoff. EIP-7997 (revision f8be9ce, Draft) sets the code of FACTORY_ADDRESS = 0x0B to a fixed bytecode when the EIP activates. The bytecode is a minimal factory written for the Constantinople instruction set, with no PUSH0. It reverts with empty data if calldata is shorter than 32 bytes. Otherwise it treats the first 32 bytes as the salt and the rest as initcode, then runs CREATE2 with all of the call's value. On success it returns the new address as a 32-byte word. On failure it reverts with the same return data. The EIP adds no opcode, precompile, transaction type, header field, gas rule or new cryptography. The work is a one-time code installation at activation, plus behavioural tests of a stateless system contract that wraps existing CREATE2 and RETURNDATA semantics.

12MediumMedium
Evaluator
LLMChecklist v3
Confidence
Medium
Under-specified at assessment cutoff
Yes — 6 criteria affected
Plausible range
12–19 (Medium)
Assessment cutoff
2025-08-21 · EIP revision f8be9ce27b (2025-08-19)
Score bands · Checklist revision 3
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the LLM total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. New fork activation mechanism3
  2. Cross-EIP interactions2
  3. Unspecified behavior requiring cross-client consensus2
  4. Added system contracts1

Under-specified at assessment cutoff: Yes

The EIP text available at the assessment cutoff left material behavior unresolved. The affected criteria and the plausible total range record that uncertainty.

Why: The revision specifies only the bytecode to install at 0x0B. It does not say whether 0x0B counts as a precompile for protocol rules (EIP-2929 default-warm set, EIP-7702 precompile-delegation rule). It does not give the account's nonce, balance or storage handling at activation. It does not address whether 0x0B is already occupied by a precompile in the baseline. Test Cases are TBD.

Unresolved questions at the cutoff (5)
  • Is 0x0B added to the set of addresses that are warm by default (EIP-2929), like precompiles?
  • Does EIP-7702 delegation to 0x0B count as delegating to a precompile (empty code) or to a normal contract?
  • What nonce is set at 0x0B on activation, and is any existing balance or storage kept or cleared?
  • How does the insertion interact with an existing precompile at 0x0B in the baseline, if there is one?
  • At which block does the insertion happen (first fork block), and how does that apply at genesis?
Notable ambiguities noted by the assessor (4)
  • The rationale says 0x0B is the next free address after existing precompiles. Under the Osaka baseline that address may already be an active precompile; the supplied text does not reconcile this.
  • 'System contract in the precompile range' leaves it unclear whether precompile-specific protocol rules (warm set, 7702 delegation handling) apply.
  • The account nonce at installation is unspecified, so post-deployment nonce expectations are ambiguous.
  • The Test Cases section is TBD, so no reference vectors exist.

Criterion breakdown

EIP-7997 Amsterdam / Glamsterdam: LLM criterion scores and rationale
CriterionScoreWhy this scoreEvidence / uncertainty
New fork activation mechanism3Code installation at 0x0B is mandated by the protocol at activation and is not done by an ordinary transaction. It is a one-time state transition at the fork block, unlike ordinary post-fork processing. Tests must cover the transition: absent before, present from the activation block onward, with balance and nonce handled correctly.
  • eip.md · Specification / Factory Contract 'Upon activation of this EIP, set the code of FACTORY_ADDRESS to ...'
  • eip.md · Rationale / Precompile-range system contract 'an irregular insertion of the code into a special address seems necessary'.
Confidence: High
Uncertainty: The EIP does not say what happens to 0x0B's existing balance, nonce or storage, or how activation behaves at genesis versus mid-chain.
Cross-EIP interactionsUnder-specified2Coordinated cross-EIP cases are needed. EIP-1014: addresses derived with sender 0x0B, repeated salt/initcode collisions, and the factory's nonce increment. EIP-211: revert data from failed initcode passed through via RETURNDATACOPY, and the empty buffer on success. EIP-7702: EOAs delegating to 0x0B, and delegated accounts calling the factory. These are bounded, not a coupled restructuring of shared vectors, so level 2.
  • eip.md · Preamble 'requires: 211, 1014'.
  • supporting/eip-1014.md · Clarifications Collision behaviour: creation fails if the target has a nonzero nonce or code; CREATE2 address is derived from the sender address.
  • supporting/eip-211.md · Specification CREATE2 returns an empty buffer on success and failure data on failure; the factory re-emits it.
  • supporting/eip-7702.md · Delegation indicator / Precompiles The rule for delegating to precompile addresses may or may not cover 0x0B.
Confidence: Medium
Uncertainty: Unnumbered interactions may also need cases: EIP-2929 warm status, initcode size and word-cost limits, the 0xEF code-prefix ban, static-context CREATE2 failure, and a possible baseline precompile collision.
Interacting EIPs: EIP-1014, EIP-211, EIP-7702
Unspecified behavior requiring cross-client consensusUnder-specified2There are localized competing outcomes. (a) Is 0x0B in the EIP-2929 default-warm precompile set, which changes call costs? (b) Does EIP-7702 delegation to 0x0B run empty code or the factory code? (c) What are the account nonce and existing balance at activation? A zero nonce works for CREATE2, while a nonce of 1 matches contract conventions; this affects the nonce after deployments. (d) A possible collision with an existing baseline precompile at 0x0B. Each produces observable consensus results and needs agreement before expected values can be fixed.
  • eip.md · Abstract 'inserted as a system contract in the precompile range'. The EIP does not say whether 0x0B counts as a precompile for protocol rules.
  • supporting/eip-7702.md · Delegation indicator / Precompiles 'When a precompile address is the target of a delegation, the retrieved code is considered empty'. Whether this applies to 0x0B is unresolved.
  • eip.md · Specification / Factory Contract Only code is specified. Nonce, balance and storage handling of 0x0B at activation are not stated.
  • eip.md · Rationale / Precompile-range system contract Assumes 0x0B is free, without addressing any existing precompile at that address in the baseline.
Confidence: Medium
Uncertainty: Point (d) relies on general knowledge of the baseline precompile map rather than the supplied text. Without (d) the level is still 2 because of (a) and (b).
Added system contracts1Exactly one protocol-designated stateless contract (no persistent storage), with no protocol effect beyond the ordinary call result.
  • eip.md · Abstract 'A minimal CREATE2 factory is inserted as a system contract in the precompile range'.
  • eip.md · Specification / Factory Contract The bytecode uses no SSTORE/SLOAD; its only effect is an ordinary CREATE2 and returning or reverting data.
Confidence: High
Uncertainty: The factory's account nonce changes with each successful CREATE2, but that is not storage.
Patterns affecting pre-existing testsUnder-specified1On the EIP's premise, baseline tests that treat 0x0B as an empty or non-existent account need new expected values. Examples are EXTCODESIZE/EXTCODEHASH/EXTCODECOPY, calls to the address, and tests that iterate over precompile-range addresses. This rework is confined to particular address-parameter cases.
  • eip.md · Specification / Factory Contract 'set the code of FACTORY_ADDRESS to ...' makes 0x0B a code-bearing account in the fork.
  • eip.md · Rationale / Precompile-range system contract 0x0B is chosen as 'the next lowest address after existing precompiles'.
Confidence: Low
Uncertainty: From general knowledge of the baseline, 0x0B may already be an active precompile in Osaka (the BLS12-381 range). The supplied text does not mention this. If the address is occupied, the rework could cover a whole precompile family (up to level 2).
New test-framework primitives1The framework needs a local extension: fork-dependent pre-allocation of the factory account in genesis, and fork-transition expectations that the code appears at activation. These are extensions of existing pre-alloc and transition-fork primitives, not a new abstraction.
  • eip.md · Rationale / Precompile-range system contract 'an irregular insertion of the code into a special address seems necessary'.
Confidence: Medium
Uncertainty: Actual framework support was not evidenced.
Security risksUnder-specified1Security conditions can be checked locally: the exact installed bytecode, correct revert and return-data handling, value forwarding, and correct failure on address collision. Other components' assumptions do not change. Frontrunning is application-level.
  • eip.md · Security Considerations / Frontrunnable deployments Deployments of environment-reading contracts may be frontrun; this is an application-level concern.
  • eip.md · Rationale / No frontrunning protection The permissionless salt is a deliberate design choice.
Confidence: Medium
Uncertainty: If 0x0B is treated as a precompile for EIP-7702 delegation or warm-set purposes, or collides with an existing precompile, the impact goes beyond a local check (up to level 2).
Edge/boundary conditions1One new boundary-sensitive rule: the 32-byte minimum calldata length (31 bytes reverts empty; 32 bytes is an empty-initcode deployment; 33+ bytes carries initcode). Other limits that tests should exercise through the factory are inherited, not changed: initcode size, value, collisions and the CREATE2 failure path.
  • eip.md · Rationale / Input validation 'The factory reverts if the input is smaller than 32 bytes'.
  • eip.md · Specification / Factory Contract 'push 32 calldatasize lt jumpi @throw'; initcodesize = calldatasize - 32.
Confidence: High
Show 20 zero-score criteria
Zero-score criteria (Checklist revision 3)
CriterionScoreWhy this scoreEvidence / uncertainty
Added opcodes0No new instruction.
  • eip.md · Rationale / Constantinople target, avoidance of PUSH0 The factory uses only existing Constantinople-era opcodes.
Modified opcodes0No instruction semantics change; calling new contract code does not count.
  • eip.md · Specification / Factory Contract CREATE2, RETURNDATASIZE and RETURNDATACOPY are used unchanged.
Added precompiles0EVM system contracts are excluded; no native precompile is added.
  • eip.md · Abstract Described as a system contract with EVM bytecode in the precompile range, not a native function.
Uncertainty: Clients may need to decide whether 0x0B is treated as a 'precompile' for EIP-2929 warm-set and EIP-7702 delegation purposes. That question is recorded under UNSP.
Modified precompilesUnder-specified0As written, the EIP changes no existing precompile.
  • eip.md · Rationale / Precompile-range system contract Assumes 0x0B is 'the next lowest address after existing precompiles', i.e. unoccupied.
Uncertainty: From baseline protocol knowledge, Osaka may already have a precompile at 0x0B (BLS12-381 range). Installing code there would then collide with, or replace, a complex precompile. The supplied text does not address this, so the plausible range is 0–3.
Modified system contracts0Deploying a new system contract is not a modification.
  • eip.md · Specification No existing system contract is referenced or changed.
EVM Gas rule changesUnder-specified0No execution-gas accounting rule changes. Gas used by factory calls comes from ordinary charges for existing instructions, including the CREATE2 hashcost from EIP-1014.
  • eip.md · Specification / Factory Contract Only installs bytecode; the factory uses existing instructions under existing gas rules. No gas parameter or accounting rule is defined.
Uncertainty: The EIP calls 0x0B a 'system contract in the precompile range' but does not say whether it joins the set of addresses that are warm by default under EIP-2929, as precompiles are. If it did, the access cost for calling 0x0B would change (level 0–1).
State-access ordering within opcode execution0No instruction's state-access or gas-charge ordering changes, and no new ordering rule is introduced. Changed contract internals do not modify how an instruction orders its accesses.
  • eip.md · Specification / Factory Contract No instruction's sequence is changed; the factory only calls CREATE2 internally.
Blob gas accounting changes0No blob-gas accounting changes.
  • eip.md · Specification No blob-related content.
State gas accounting changes0Using an unchanged state-writing operation (CREATE2) does not introduce state-gas accounting.
  • eip.md · Specification / Factory Contract Deployment goes through unchanged CREATE2; no state-gas mechanism is defined.
New EVM gas refund0No new refund mechanism.
  • eip.md · Specification No refund rule is defined.
New transaction types0No new transaction envelope.
  • eip.md · Rationale / Not a new transaction type A new creation transaction type was explicitly rejected in favour of a system contract.
New or modified transaction validity mechanisms0No consensus transaction-validity change.
  • eip.md · Specification No transaction validity or intrinsic-gas rule is defined.
New block / header fields0No header or block member added.
  • eip.md · Specification No header or block field.
Encoding changes (RLP/SSZ)0No schema or codec change.
  • eip.md · Specification No serialized schema is changed.
Block syncing changes0No block RLP or structural validation change.
  • eip.md · Specification No block structure or decoding change.
Engine API changes0No Engine API change.
  • eip.md · Specification No Engine API content.
Transition-tool interface changes0Fork-aware behaviour (installing code at activation) needs no new t8n field or exchange mechanism.
  • eip.md · Specification / Factory Contract The activation code insertion happens inside the client at the fork; no new input or output field is defined.
Uncertainty: No t8n evidence was supplied. Whether the tool applies the insertion at the transition block, or expects it in the supplied alloc, is a design choice.
New invariant on pre-existing tests0Baseline tests gain no new output to assert. The installed account appears in pre-state or allocation; it is not a new output produced while tests run.
  • eip.md · Specification / Factory Contract A one-time code installation; no new log, receipt or header output.
Uncertainty: Fixtures that start at the fork must include the factory account in genesis, which changes state roots. This is closer to fixture construction than to a new assertion (at most level 1).
Performance risks0Everything the factory does was already possible through user-deployed factories; no workload or resource bound changes.
  • eip.md · Specification / Factory Contract The factory simply wraps CREATE2; its costs are paid under existing gas rules.
Cryptography0Unchanged hashing is reused; no cryptographic mechanism changes.
  • supporting/eip-1014.md · Specification CREATE2 address derivation keccak256(0xff ++ address ++ salt ++ keccak256(init_code)) is unchanged and reused.
Assessment provenance
Assessed EIP revision
ethereum/EIPs@f8be9ce27b EIPS/eip-7997.md committed 2025-08-19 · information cutoff 2025-08-21T13:34:18Z
Current master · File history · blob 9bd8766f32 · sha256 8fec7a727f75
Rubric
Checklist revision 3 · ethspecs/pm@fe2f793b03
Evaluator
Opus 5.5 (claude-opus-5-5) at high effort, one tool-less call per EIP · isolation bubblewrap_claude_p_no_tools_v1
Source record
Frozen research record research/tasks/10-opus-v3-reassessment/retrospective/outputs/assessments/amsterdam/eip-7997.yaml · sha256 d8eb22a75c61
Supporting documents supplied with the EIP
supporting/eip-155.md, supporting/eip-211.md, supporting/eip-1014.md, supporting/eip-5792.md, supporting/eip-7702.md

Evaluated on: Not recorded · Spec revision: 2025-11-05 · ec05b85e53

5LowLow
Evaluator
HumanChecklist v1
Confidence
Not recorded
Under-specified at assessment cutoff
Not recorded in the checklist
Checklist published
2026-01-07 · EIP at ec05b85e53
Score bands · Checklist revision 1
  • Low <10
  • Medium 10–19
  • High ≥20

24 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 72.

Complexity profile

Each segment is one criterion's contribution to the Human total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. Added system contracts2
  2. Security risks2
  3. New fork activation mechanism1

Criterion breakdown

EIP-7997 Amsterdam / Glamsterdam: Human criterion scores and rationale
CriterionScoreWhy this scoreNotes
Added system contracts2A new system contract is added in the precompile range.—
Security risks2There is an open frontrunning risk that has not been solved. Whether this qualifies as security risk or inconvenience is subjective.—
New fork activation mechanism1The EIP adds a new system contract at the next fork. It does not affect state but it might be called an 'internal variable' depending on how this is defined exactly.—
Show 21 zero-score criteria
Zero-score criteria (Checklist revision 1)
CriterionScoreWhy this scoreNotes
Added opcodes0No rationale recorded.—
Modified opcodes0No rationale recorded.—
Added precompiles0No rationale recorded.—
Modified precompiles0No rationale recorded.—
Modified system contracts0No rationale recorded.—
EVM Gas rule changes0No rationale recorded.—
Blob gas accounting changes0No rationale recorded.—
New EVM gas refund0No rationale recorded.—
New transaction types0No rationale recorded.—
New or modified transaction validity mechanisms0No rationale recorded.—
New block / header fields0No rationale recorded.—
Encoding changes (RLP/SSZ)0No rationale recorded.—
Block syncing changes0No rationale recorded.—
Engine API changes0No rationale recorded.—
Engine API encoding changes0No rationale recorded.—
Transition-tool interface changes0No rationale recorded.—
Patterns affecting pre-existing tests0No rationale recorded.—
Performance risks0No rationale recorded.—
Edge/boundary conditions0No rationale recorded.—
Cryptography0No rationale recorded.—
Cross-EIP interactions0No rationale recorded.—
Assessment provenance
Assessed EIP revision
ethereum/EIPs@ec05b85e53 EIPS/eip-7997.md committed 2025-11-05
EIP master revision at the time of the human checklist commit; the checklist itself does not pin an EIP revision.
Current master · File history · blob 3ac0f2270c · sha256 41984b52620b
Rubric
Checklist revision 1 · ethspecs/pm@d936bcb349
Evaluator
STEEL team · ethspecs/pm complexity_assessments
Source record
Merged checklist ethspecs/pm@676285451c complexity_assessments/EIPs/EIP-7997.md · committed 2026-01-07
blob 0b3e3f4698 · sha256 bf037d294985
Research record
research/tasks/05c-amsterdam-human-assessment-alignment/inputs/human/eip-7997.yaml · sha256 848d3ee0d3a5

The LLM applied checklist revision 3 and the human reviewers revision 1 to EIP-7997 in Amsterdam / Glamsterdam. Revision 3 phrases the same criteria more precisely; differences cover the 23 criteria both revisions share, and each total keeps its own revision. Δ is LLM minus Human.

LLM12Medium
Human5Low
Δ total+7Tiers differ: Medium vs Low
Criteria17/23agree exactly · 4 differ by 1 · 2 differ by 2+
Confounded comparison. The human checklist evaluated the EIP as it stood when the checklist was written; the LLM evaluated the sealed historical revision. Input alignment: substantive drift; human hindsight exposure: low exposure.
Exposure evidence

The assessment is grounded in proposal mechanisms and a disclosed security concern, with no implementation, devnet, or test-outcome evidence.

Substantive intervening revisions: Rewrites the Abstract and two Motivation paragraphs, and - the substantive part - adds a prose normative specification of the factory's behaviour ahead of the bytecode: when called, the account invokes CREATE2 (linking EIP-1014) with salt = first 32 bytes of input, init code = the remaining input and value = the call's value; the call reverts with empty return data if input is shorter than 32 bytes; if CREATE2 outputs 0 the call reverts with the creation frame's return data. The bytecode is retained and is now described as implementing that specification. |…

Complexity profiles side by side

LLM
Human

Largest disagreements: New fork activation mechanism (+2), Cross-EIP interactions (+2), Patterns affecting pre-existing tests (+1), Edge/boundary conditions (+1), Added system contracts (−1)

Per-criterion scores, Human versus LLM, ordered by the size of the difference
CriterionLLMHumanΔAgreementRationale from each source
New fork activation mechanism31+2Differ by 2+
Show rationale

LLM Code installation at 0x0B is mandated by the protocol at activation and is not done by an ordinary transaction. It is a one-time state transition at the fork block, unlike ordinary post-fork processing. Tests must cover the transition: absent before, present from the activation block onward, with balance and nonce handled correctly.

Human The EIP adds a new system contract at the next fork. It does not affect state but it might be called an 'internal variable' depending on how this is defined exactly.

Cross-EIP interactions20+2Differ by 2+
Show rationale

LLM Coordinated cross-EIP cases are needed. EIP-1014: addresses derived with sender 0x0B, repeated salt/initcode collisions, and the factory's nonce increment. EIP-211: revert data from failed initcode passed through via RETURNDATACOPY, and the empty buffer on success. EIP-7702: EOAs delegating to 0x0B, and delegated accounts calling the factory. These are bounded, not a coupled restructuring of shared vectors, so level 2.

Human No rationale recorded.

Added system contracts12−1Differ by 1
Show rationale

LLM Exactly one protocol-designated stateless contract (no persistent storage), with no protocol effect beyond the ordinary call result.

Human A new system contract is added in the precompile range.

Patterns affecting pre-existing tests10+1Differ by 1
Show rationale

LLM On the EIP's premise, baseline tests that treat 0x0B as an empty or non-existent account need new expected values. Examples are EXTCODESIZE/EXTCODEHASH/EXTCODECOPY, calls to the address, and tests that iterate over precompile-range addresses. This rework is confined to particular address-parameter cases.

Human No rationale recorded.

Security risks12−1Differ by 1
Show rationale

LLM Security conditions can be checked locally: the exact installed bytecode, correct revert and return-data handling, value forwarding, and correct failure on address collision. Other components' assumptions do not change. Frontrunning is application-level.

Human There is an open frontrunning risk that has not been solved. Whether this qualifies as security risk or inconvenience is subjective.

Edge/boundary conditions10+1Differ by 1
Show rationale

LLM One new boundary-sensitive rule: the 32-byte minimum calldata length (31 bytes reverts empty; 32 bytes is an empty-initcode deployment; 33+ bytes carries initcode). Other limits that tests should exercise through the factory are inherited, not changed: initcode size, value, collisions and the CREATE2 failure path.

Human No rationale recorded.

Added opcodes000Agree
Show rationale

LLM No new instruction.

Human No rationale recorded.

Modified opcodes000Agree
Show rationale

LLM No instruction semantics change; calling new contract code does not count.

Human No rationale recorded.

Added precompiles000Agree
Show rationale

LLM EVM system contracts are excluded; no native precompile is added.

Human No rationale recorded.

Modified precompiles000Agree
Show rationale

LLM As written, the EIP changes no existing precompile.

Human No rationale recorded.

Modified system contracts000Agree
Show rationale

LLM Deploying a new system contract is not a modification.

Human No rationale recorded.

EVM Gas rule changes000Agree
Show rationale

LLM No execution-gas accounting rule changes. Gas used by factory calls comes from ordinary charges for existing instructions, including the CREATE2 hashcost from EIP-1014.

Human No rationale recorded.

Blob gas accounting changes000Agree
Show rationale

LLM No blob-gas accounting changes.

Human No rationale recorded.

New EVM gas refund000Agree
Show rationale

LLM No new refund mechanism.

Human No rationale recorded.

New transaction types000Agree
Show rationale

LLM No new transaction envelope.

Human No rationale recorded.

New or modified transaction validity mechanisms000Agree
Show rationale

LLM No consensus transaction-validity change.

Human No rationale recorded.

New block / header fields000Agree
Show rationale

LLM No header or block member added.

Human No rationale recorded.

Encoding changes (RLP/SSZ)000Agree
Show rationale

LLM No schema or codec change.

Human No rationale recorded.

Block syncing changes000Agree
Show rationale

LLM No block RLP or structural validation change.

Human No rationale recorded.

Engine API changes000Agree
Show rationale

LLM No Engine API change.

Human No rationale recorded.

Transition-tool interface changes000Agree
Show rationale

LLM Fork-aware behaviour (installing code at activation) needs no new t8n field or exchange mechanism.

Human No rationale recorded.

Performance risks000Agree
Show rationale

LLM Everything the factory does was already possible through user-deployed factories; no workload or resource bound changes.

Human No rationale recorded.

Cryptography000Agree
Show rationale

LLM Unchanged hashing is reused; no cryptographic mechanism changes.

Human No rationale recorded.

State-access ordering within opcode execution0n/a—Only in revision 3
Show rationale

LLM No instruction's state-access or gas-charge ordering changes, and no new ordering rule is introduced. Changed contract internals do not modify how an instruction orders its accesses.

Human No rationale recorded.

State gas accounting changes0n/a—Only in revision 3
Show rationale

LLM Using an unchanged state-writing operation (CREATE2) does not introduce state-gas accounting.

Human No rationale recorded.

Engine API encoding changesn/a0—Only in revision 1—
New invariant on pre-existing tests0n/a—Only in revision 3
Show rationale

LLM Baseline tests gain no new output to assert. The installed account appears in pre-state or allocation; it is not a new output produced while tests run.

Human No rationale recorded.

New test-framework primitives1n/a—Only in revision 3
Show rationale

LLM The framework needs a local extension: fork-dependent pre-allocation of the factory account in genesis, and fork-transition expectations that the code appears at activation. These are extensions of existing pre-alloc and transition-fork primitives, not a new abstraction.

Human No rationale recorded.

Unspecified behavior requiring cross-client consensus2n/a—Only in revision 3
Show rationale

LLM There are localized competing outcomes. (a) Is 0x0B in the EIP-2929 default-warm precompile set, which changes call costs? (b) Does EIP-7702 delegation to 0x0B run empty code or the factory code? (c) What are the account nonce and existing balance at activation? A zero nonce works for CREATE2, while a nonce of 1 matches contract conventions; this affects the nonce after deployments. (d) A possible collision with an existing baseline precompile at 0x0B. Each produces observable consensus results and needs agreement before expected values can be fixed.

Human No rationale recorded.

Criterion legend and glossary

Every stacked bar, comparison matrix, and criterion table on this site uses the same criterion colours, abbreviations, and order. Colour marks the criterion group; the abbreviation and name identify the criterion. Scores are 0–3 per criterion (4 is exceptional; cross-EIP interactions is uncapped).

EVM surface

Opcodes, precompiles, and system contracts that are added or modified.

  • Added opcodes
    Introduces new opcodes
    Score anchors
    0
    No new opcodes are introduced.
    1
    A new simple opcode is introduced (no data portion, no complex stack mechanics, and a constant gas cost).
    2
    Multiple new simple opcodes are introduced, or a single new complex opcode is introduced (has data portion, or complex stack mechanics, or a dynamic gas cost).
    3
    Multiple new opcodes are introduced, and at least one of them is complex (has data portion, or complex stack mechanics, or a dynamic gas cost).
    • Cryptography opcodes are not considered complex by default. Refer to the "Cryptography" section for a separate assessment.
  • Modified opcodes
    Modifies pre-existing opcodes
    Score anchors
    0
    No pre-existing opcode modifications are introduced.
    3
    At least one pre-existing opcode's behavior is modified (not including gas changes) or a pre-existing opcode is deprecated.
  • Added precompiles
    Introduces new precompiles
    Score anchors
    0
    No new precompiles are introduced.
    1
    A new simple precompile is introduced (constant input length, constant gas cost).
    2
    Multiple new simple precompiles are introduced, or a single new complex precompile is introduced (dynamic input length or dynamic gas cost).
    3
    Multiple new precompiles are introduced, and at least one of them is complex (dynamic input length or dynamic gas cost).
    • Cryptography precompiles are not considered complex by default. Refer to the "Cryptography" for a separate assessment.
  • Modified precompiles
    Modifies pre-existing precompiles logic or gas-accounting
    Score anchors
    0
    No pre-existing precompiles are modified.
    1
    At least one pre-existing precompile has its gas schedule modified.
    2
    Multiple pre-existing precompiles have their gas schedule modified, or a single pre-existing precompile has its behavior modified.
    3
    The behavior of multiple pre-existing precompiles, or a single complex pre-existing precompile modified.
  • Added system contracts
    Introduces new system contract, stateful or not
    Score anchors
    0
    No new system contracts are introduced.
    1
    A new system contract is introduced that is not stateful nor does it trigger a new system action (e.g. requests to the consensus layer).
    2
    Multiple new system contracts are introduced or a single new system contract that is either stateful or triggers a new system action (e.g. requests to the consensus layer).
    3
    Multiple new system contracts are introduced and at least one of them is either stateful or triggers a new system action (e.g. requests to the consensus layer).
  • Modified system contracts
    Modifies pre-existing system contracts
    Score anchors
    0
    No modifications to pre-existing system contracts are introduced, directly or indirectly.
    1
    Does not directly modify any system contract, but its behavior has minor indirect effects on one or more system contracts.
    2
    Does not directly modify any system contract, but its behavior has major indirect effects on one or more system contracts.
    3
    At least one pre-existing system contract code or state is modified, which would involve irregular state transition or a similarly complex transition methodology.

Gas and accounting

Execution, blob, and state gas rules, refunds, and where charges happen inside opcodes.

  • EVM Gas rule changes
    New EVM gas accounting rules
    Score anchors
    0
    No gas accounting changes.
    1
    Existing gas accounting mechanism is updated.
    2
    A new gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State-access ordering within opcode execution · not in checklist revision 1
    Changes *where inside an opcode's execution* state is accessed, or where gas is charged relative to that access. Because a state access is recorded in the block-level access list only if execution had enough gas to reach it, this ordering is consensus-critical: moving it changes the BAL at every gas boundary of every affected opcode.
    Score anchors
    0
    No change to where state is accessed, or to where gas is charged relative to a state access, within any opcode.
    1
    A single opcode's state-access or gas-charge ordering changes.
    2
    Multiple opcodes' ordering changes, or a new state-accessing operation is introduced whose position in the order must be settled.
    3
    The ordering rule changes for a whole class of state-accessing opcodes at once, or what counts as a recordable state access is redefined — requiring existing BAL vectors to be re-derived across opcodes and forks.
    • Distinct from "Modified opcodes", which asks whether an opcode's **result** changed. This row asks about the **path to the result**, which is observable even when the result is identical. An EIP can be 0 on that row and 3 on this one.
    • Score changes **to** the ordering. Do not score the fact that state accesses are observable — they always are.
    • Each boundary must be re-tested against every other dimension that can change the answer (cold/warm, static/non-static, delegated/direct, revert/success), so the case count grows multiplicatively rather than additively. Note this explicitly under Special Considerations.
  • Blob gas accounting changes
    New Blob gas accounting rules which potentially affect pre-existing tests
    Score anchors
    0
    No blob gas accounting changes.
    1
    Existing blob gas accounting mechanism is updated.
    2
    A new blob gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new blob gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State gas accounting changes · not in checklist revision 1
    New state gas accounting rules. State gas is the cost of *writing* state, as opposed to accessing or executing it: `StateGasCosts`, `COST_PER_STATE_BYTE`, the block-level state gas budget, and the spill path into execution gas.
    Score anchors
    0
    No state gas accounting changes.
    1
    An existing state gas cost or `STATE_BYTES_PER_*` rate is adjusted.
    2
    A new state-gas-charging site is introduced, or the block-level state gas budget or reservoir allocation is modified.
    3
    A new state gas charging mechanism is introduced, or the spill interaction between state gas and execution gas is modified, affecting existing gas tests.
    • Harder to test than blob gas: the spill path means state gas cannot be metered independently of execution gas, and some costs (e.g. `NEW_ACCOUNT`) are state-dependent.
  • New EVM gas refund
    New gas-refund mechanism
    Score anchors
    0
    No new gas-refund mechanisms are introduced.
    1
    A new simple gas-refund mechanism is introduced that does not affect either existing tests or existing gas-refund mechanisms.
    2
    A new complex gas-refund mechanism is introduced or a simple mechanism that affects existing tests or existing gas-refund mechanisms.
    3
    A new complex gas-refund mechanism is introduced that affects existing tests or existing gas-refund mechanisms.

Blocks, transactions, and encoding

Transaction types and validity, block and header fields, encodings, syncing, and activation-time changes.

  • New transaction types
    Introduces a new transaction type
    Score anchors
    0
    No new transaction types are introduced.
    3
    A new transaction type is introduced.
  • New or modified transaction validity mechanisms
    Creates new or modifies pre-existing transaction types' validation mechanisms
    Score anchors
    0
    No changes are introduced to the validity rules of existing transaction types or to their intrinsic gas cost calculation.
    1
    Minor adjustments are introduced to validity rules or intrinsic gas cost calculation, but they do not significantly affect existing tests.
    2
    Changes to validity rules or intrinsic gas cost calculation affect existing tests, but require only limited updates to test cases and no redesign of the testing infrastructure.
    3
    Changes to validity rules or intrinsic gas cost calculation require extensive rework or redesign of the tests or testing infrastructure.
  • New block / header fields
    Introduces new block or block header fields
    Score anchors
    0
    No new block or header fields are introduced.
    3
    A new block or header field is introduced.
  • Encoding changes (RLP/SSZ)
    Introduces encoding changes at the transaction/block/interfaces level
    Score anchors
    0
    No encoding changes are introduced at the transaction, block, or interfaces levels.
    3
    An encoding change is introduced at transaction, block or interfaces level (e.g. RLP -> SSZ).
    • "Interfaces level" includes the Engine API. Score an Engine API encoding change (e.g. JSON -> SSZ) here.
  • Block syncing changes
    Modifies block RLP validation mechanisms that require test client syncing.
    Score anchors
    0
    No new RLP validation mechanism is introduced.
    1
    A single simple RLP validation mechanism is introduced.
    2
    Multiple simple RLP validation mechanisms are introduced or a single complex one.
    3
    Multiple RLP validation mechanisms are introduced and at least one of them is deemed complex.
  • New fork activation mechanism
    Modifies state, internal variables, or similar, at the fork activation block
    Score anchors
    0
    No state modifications, internal variables or similar are modified at the fork activation block.
    3
    Either a state modification or internal variables are modified at the fork activation block.
    • Initialization of new internal variable is not considered a modification.

Client interfaces

Engine API and transition-tool interface changes.

  • Engine API changes
    Introduces new fields to the Engine API directives
    Score anchors
    0
    No new fields or communication mechanisms are introduced to the Engine API.
    1
    A single new field is introduced in one of the Engine API endpoints.
    2
    Multiple fields are introduced to one or multiple Engine API end points, or a new Engine API end-point is introduced.
    3
    Multiple fields are introduced to one or multiple Engine API end points and a new Engine API end-point is introduced.
  • Engine API encoding changes · Checklist revision 1 only
    Engine API encoding changes (the revision-1 template defines no anchor text for this row).
  • Transition-tool interface changes
    Modifies or adds new fields to the transition tool interface.
    Score anchors
    0
    No modifications to the transition tool interface are required.
    1
    A single new field needs to be introduced to the transition tool interface.
    2
    Multiple new fields or a new mechanism has to be introduced to the transition tool interface.
    3
    Multiple new fields and a new mechanism has to be introduced to the transition tool interface.
    • Special consideration must be paid to this section if the EIP introduces a mechanism that requires the state transition tool to be aware whether the block it is processing is the fork-activation block.

Testing impact

Rework, new invariants, and new primitives required in the test framework.

  • Patterns affecting pre-existing tests
    Implements a new validation mechanism or rule that translates in reworking pre-existing tests
    Score anchors
    0
    No pre-existing tests are affected by this change.
    1
    Minor subset of existing tests are affected by this change.
    2
    Considerable subset of existing tests are affected by this change but involves only a contrived category of tests.
    3
    Major subset of existing tests are affected, including diverse category of tests (benchmarks, static, multiple forks, etc.).
  • New invariant on pre-existing tests · not in checklist revision 1
    Tests that are **not about this EIP** must nonetheless assert something this EIP produces. Their logic does not change; they gain a new thing to check.
    Score anchors
    0
    Pre-existing tests assert nothing new.
    1
    A narrow, contrived category of pre-existing tests gains a new assertion.
    2
    A broad category gains a new assertion, applied mechanically.
    3
    Every test in the fork gains the assertion regardless of what it tests, and pre-fork vectors must be re-derived to satisfy it.
    • Paired with the row above, and easy to confuse with it. "Patterns affecting pre-existing tests" asks whether existing tests must be **reworked**; this row asks whether they must **additionally assert something new**. Score both — an EIP can be low on one and high on the other.
  • New test-framework primitives · not in checklist revision 1
    Requires new abstractions in the test framework itself — expectation types, modifiers, helpers — beyond writing test functions with what already exists.
    Score anchors
    0
    Existing test primitives suffice.
    1
    Existing primitives need minor extension.
    2
    New expectation or modifier primitives are required, reusable within this EIP's own test suite.
    3
    New framework-level primitives are required that become a permanent part of the framework and are used by other EIPs' tests.

Risk and validation

Security, performance, boundary conditions, and cryptography that need validation.

  • Security risks
    Introduces or modifies mechanisms that could compromise the security of the chain, users, validators, or other stakeholders, if not implemented properly.
    Score anchors
    0
    No new mechanisms are introduced that could pose a security risk.
    1
    The introduced mechanisms are self-contained, can be validated in isolation, and do not alter existing invariants that could pose a security risk for any stakeholders.
    2
    The introduced mechanisms interact with a limited number of existing components, slightly altering their security assumptions and requiring a targeted security review or fuzzing.
    3
    The introduced mechanisms interact with multiple existing components, including critical ones, substantially altering their security assumptions and requiring an extensive security review and fuzzing.
  • Performance risks
    Introduces or modifies mechanisms and requires performance validation.
    Score anchors
    0
    No new mechanisms are introduced that require performance validation.
    1
    The introduced mechanisms can be benchmarked in isolation and do not affect existing performance behavior.
    2
    The introduced mechanisms cannot be fully benchmarked in isolation, but they only have a limited impact on the existing performance benchmarks.
    3
    The introduced mechanisms cannot be benchmarked in isolation and have a substantial impact on existing performance benchmarks or have complex interactions with existing mechanisms.
  • Edge/boundary conditions
    Feature contains edge/boundary conditions.
    Score anchors
    0
    No discernible edge cases or boundary conditions are introduced.
    1
    A single edge-case or boundary-condition prone mechanism is introduced.
    2
    Multiple edge-case or boundary-condition prone mechanisms are introduced, but none of them requires an elevated number of cases to test.
    3
    Multiple edge-case or boundary-condition prone mechanisms are introduced and at least one of them requires an elevated number of cases to test.
  • Cryptography
    Introduces new cryptography mechanisms or modifies existing functionality that involves cryptography
    Score anchors
    0
    No cryptography mechanisms are introduced.
    1
    A new cryptography mechanism is introduced but it is a well known mechanism that is known to have vast resources to aid on its testing.
    2
    Multiple new cryptography mechanisms are introduced that are well-known or a single but novel mechanism is introduced that is either untested or has limited resources.
    3
    Multiple new cryptography mechanisms are introduced and at least one of them is a novel mechanism.

Coordination

Cross-EIP interactions and behavior that clients must agree on before tests exist.

  • Cross-EIP interactions
    Introduces or modifies mechanisms that affect other EIPs in either the same or past forks.
    Score anchors
    0
    Fully self-contained EIP that does not depend on, modify, or conflict with any other EIP.
    1
    The EIP interacts with one or more other EIPs in a non-critical and limited way but can be tested independently for the most part.
    2
    The EIP depends on or modifies one or more other EIPs such that coordinated testing and consideration is required, but interactions are limited in scope and not complex.
    3
    The EIP has strong interdependencies with multiple EIPs, requiring extensive coordinated cross-EIP testing as well as potential re-design of existing test vectors.
    • +1 for every 3 additional interacting EIPs beyond the first 3, each of which requires its own coordinated test cases. List the EIPs in the rationale.
    • This row is intentionally uncapped, unlike every other anchor: each interacting EIP is another axis of the test matrix, so a ceiling would make a 12-EIP product indistinguishable from a 3-EIP one.
  • Unspecified behavior requiring cross-client consensus · not in checklist revision 1
    The EIP text does not determine the answer for cases a test can construct. Clients must agree on a previously unspecified detail before tests can be baselined. The cost here is coordination and re-baselining, not test writing.
    Score anchors
    0
    The EIP text determines the answer for every case a test could construct.
    1
    A few details are unspecified but have an obvious intended reading.
    2
    Details require client agreement before tests can be written, but they are localized.
    3
    A previously unspecified *and previously unobservable* behavior becomes consensus-critical; expect tests to be re-baselined on each round of EIP amendment.
    • Score this from the EIP's state at assessment time: whether it has client implementations, whether it has been through a devnet, and how many open questions remain on its discussion thread.