Retrospective LLM-Based Complexity Evaluations

EIP complexity assessment

EIP-8025: Optional Execution Proofs

Assessed in Hegotá. The score describes the EIP text available at the snapshot, not the EIP as it stands today.

ProspectiveHegotáSnapshot 2026-10-07EIP-8081: PFILayers: execution, consensus
LLM Completescore 25
Human Pending· No STEEL checklist existed on the ethspecs/pm default branch or in any open pull request at the snapshot.

LLM assessment

Evaluated on: · Spec revision: 2026-10-07 · 6dac5e7491 · EIP-8081 list: PFI

Scope at the cutoff. EIP-8025 adds opt-in execution proofs. Altruistic proving validators generate zk proofs that an execution payload is valid and gossip them on a new CL topic. Proof-verifying nodes check them as a supplementary signal while still re-executing, so consensus validity rules do not change. On the execution layer, the EIP defines a stateless guest program (`run_stateless_guest` / `verify_stateless_new_payload`) and a `WitnessState` backed by MPT trie nodes, code and ancestor headers. It also defines host-side witness construction from the block read/write tracker, and new SSZ schemas (`StatelessInput`, `ExecutionWitness`, an SSZ `NewPayloadRequest` built from progressive containers, `StatelessValidationResult`) with a 2-byte schema-ID prefix and a canonical-encoding requirement. Guest programs are expected to run the existing `blockchain_test_engine` fixtures.

25HighHigh
Evaluator
LLMChecklist v3
Confidence
Medium
Under-specified at assessment cutoff
Yes — 5 criteria affected
Plausible range
21–30 (Medium–High)
Snapshot
2026-10-07 · EIP revision 6dac5e7491 (2026-10-07)
Score bands · Checklist revision 3
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the LLM total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. Cross-EIP interactions4
  2. Encoding changes (RLP/SSZ)3
  3. New test-framework primitives3
  4. Edge/boundary conditions3

Under-specified at assessment cutoff: Yes

The EIP text available at the assessment cutoff left material behavior unresolved. The affected criteria and the plausible total range record that uncertainty.

Why: Several EL-relevant details are not specified in the supplied text. The guest output for a fork-timestamp mismatch is missing; the reference omits the check while production implementations must perform it. The mechanism by which the host or EL exports execution witnesses (any Engine API or t8n interface) is undefined. The `slot_number` payload field has no supplied defining EIP. The CL parameter `k` is still open.

Unresolved questions at the cutoff (4)
  • When the payload timestamp is outside the guest's fork, does the guest return a sentinel failure or a failure with retained root, chain_id and schema_id?
  • How does a stateful EL expose the execution witness to the prover or test filler: an Engine API, JSON-RPC or t8n output?
  • Which EIP defines `slot_number` in ExecutionPayload, and how is it validated?
  • Are superfluous witness nodes, codes or headers accepted, or must the witness be minimal?
Notable ambiguities noted by the assessor (5)
  • The EIP says it makes no consensus change, yet it introduces EL guest and witness logic that must be conformance-tested across all engine fixtures.
  • It is unclear whether running existing engine fixtures through the guest counts as reworking baseline tests or as new feature tests.
  • The reference guest omits the fork-timestamp comparison that production implementations MUST perform.
  • The normative specification is mostly delegated to external execution-specs and consensus-specs commits that were not supplied.
  • EIP-8282's motivation mentions a `0xB0` builder prefix while EIP-7732 lists `0x03`; this is a supporting-document inconsistency that does not affect the target.

Criterion breakdown

EIP-8025 Hegotá: LLM criterion scores and rationale
CriterionScoreWhy this scoreEvidence / uncertainty
Cross-EIP interactionsExceptional4The guest's request root and its witness completeness couple behavior from several EIPs (blobs, three request system contracts plus builder requests, BAL, progressive SSZ). This requires coordinated scenarios across them and shared fixture vectors.
  • eip.md · Stateless input and output — "The `NewPayloadRequest` commits to ... versioned hashes ... typed execution requests" The request root and guest validation couple EIP-4844, 6110, 7002, 7251, 8282 and 7928 data.
  • eip.md · Stateless input and output — "use the progressive containers and lists of EIP-7688" The hash_tree_root binding depends on EIP-7688 merkleization.
  • supporting/eip-7928.md · Security Considerations — "storage reads performed by system calls are not paid for by block gas" System-call accesses (7002/7251/8282) must be present in the witness.
  • eip.md · Consensus Layer — "uses the execution-validation window introduced by EIP-7732" Timing dependency on EIP-7732.
Confidence: Medium
Interacting EIPs: EIP-4844, EIP-6110, EIP-7002, EIP-7251, EIP-7688, EIP-7732, EIP-7928, EIP-8282
Encoding changes (RLP/SSZ)3New serialized schemas and a codec are introduced for a protocol-specified EL proof interface.
  • eip.md · Stateless input and output — `StatelessInput`, `ExecutionWitness`, `StatelessValidationResult` Adds new SSZ schemas for the EL proof interface.
  • eip.md · SSZ encoding — 2-byte schema ID prefix 0x1501, canonical-only decoding Adds a new codec framing and strict canonical-encoding rule.
  • eip.md · Stateless input and output — `NewPayloadRequest`/`ExecutionPayload` as ProgressiveContainer Defines an SSZ schema for Engine API payload data, including `block_access_list` and builder request lists.
Confidence: High
New test-framework primitives3The target needs a shared framework facility (witness generation, `StatelessInput` packaging, a guest runner and result checking) that changes how all engine-fixture families are constructed and checked, not only target-specific tests.
  • eip.md · Test Cases — "Guest programs should run the `blockchain_test_engine` fixtures" A new execution facility is needed: running engine fixtures from every behavioral family through a stateless guest.
  • eip.md · SSZ encoding — `serialize_stateless_input` / canonical encoding Requires SSZ construction of `StatelessInput` with a schema prefix, plus mutation tooling for non-canonical and invalid inputs.
  • eip.md · Host-side input construction — witness construction steps 1–4 Requires a witness-generation primitive covering accessed nodes, sibling nodes for branch collapse, codes and the header window.
Confidence: Medium
Uncertainty: The actual availability of helpers in the referenced repositories cannot be verified.
Edge/boundary conditions3Several independent boundary-sensitive mechanisms are added. At least one has an elevated matrix: witness completeness depends jointly on write ordering, deletion-induced branch collapse and the presence of sibling nodes. Similarly, the header window interacts with BLOCKHASH depth and contiguity. Their combinations change the outcome and cannot be tested independently.
  • eip.md · Stateless input and output — bounds table Adds bounds: MAX_WITNESS_HEADERS 256, MAX_BYTES_PER_CODE 2^16, MAX_BYTES_PER_HEADER and MAX_BYTES_PER_WITNESS_NODE 2^10, MAX_EXTRA_DATA_BYTES 32.
  • eip.md · SSZ encoding — schema ID length check and canonical re-encode Boundaries at input length < 2, schema-ID mismatch, and offset gaps or trailing bytes.
  • eip.md · Host-side input construction — "apply each storage trie's insertions and updates before its deletions" Whether the witness contains the needed sibling node depends on the combination of insert, update and delete patterns and branch collapse.
  • eip.md · Stateless input and output — sentinel vs retained result Decode failure yields zeroed sentinels; validation failure keeps decoded values.
Confidence: Medium
Transition-tool interface changesUnder-specified2Filling fixtures with `StatelessInput`/witness data plausibly requires the state-transition tool to output a new witness artifact (state nodes, codes, headers) and the chain ID. That is a new capture mechanism. No tool evidence is supplied, so this is scored at level 2 rather than 3.
  • eip.md · Host-side input construction — `build_execution_witness` Producing a witness requires the executing host to export trie nodes, read bytecode and ancestor headers gathered during execution.
  • eip.md · Specification references — stateless_host / stateless_host_exec_witness The reference implementation has host modules for witness construction. The t8n interface itself is not described.
Confidence: Low
Uncertainty: No t8n interface evidence is supplied. The witness might be produced outside t8n (range 0) or as a new mechanism with multiple fields (range 3).
New invariant on pre-existing testsUnder-specified2Ordinary cases across many families gain a new checked output: the guest's validation result, request root and schema ID. The assertion covers Amsterdam engine fixtures only. There is no evidence that pre-fork vectors must be re-derived, so level 3 is not met.
  • eip.md · Test Cases — engine fixtures run by guest programs Engine fixtures across all behavioral families are consumed by the guest. The guest must output a `StatelessValidationResult` whose `successful_validation` matches the fixture's validity.
  • eip.md · Stateless input and output — `StatelessValidationResult` This is a new public output (request root, success flag, chain_id, schema_id) that did not exist before.
Confidence: Medium
Uncertainty: Because the feature is opt-in for clients, one could argue it is a new test consumer rather than an assertion on baseline tests. The range is 1–2.
Security risks2Proof-verifying CL nodes trust the guest's result. This is a bounded interaction that needs targeted fuzzing of witness verification, canonical decoding and schema, chain and fork binding. Since there is no fork-choice impact, it does not reach level 3.
  • eip.md · Guest validation — absence proofs and missing-node failure Guest soundness depends on witness verification rejecting forged or missing state.
  • eip.md · SSZ encoding — "MUST accept only the canonical SSZ encoding" Malleability boundary of the input codec.
  • eip.md · Guest validation — "Production implementations MUST perform this comparison" The fork/timestamp binding is required beyond the reference implementation.
  • eip.md · Security Considerations — Soundness Effects of a forged proof are limited to the verifying node's local view.
Confidence: Medium
Performance risks2Targeted integrated benchmarks are needed for EL execution combined with witness generation, and for worst-case witness size and guest execution under adversarial blocks. The mechanism is off the critical path and opt-in, so this is a bounded interaction rather than a baseline end-to-end change.
  • eip.md · Host-side input construction — witness capture including sibling nodes Adds an EL host workload per block: trie-node capture and post-state recomputation.
  • eip.md · Security Considerations — "O(n log² n)" proving cost Proving cost scales with the witnessed computation. Worst-case gas-limit blocks drive witness size and proving latency.
  • eip.md · Proof types and containers — MAX_PROOF_SIZE bandwidth budget Bandwidth bound for proof gossip, which is CL-side.
Confidence: Medium
Uncertainty: Proving-time targets are not stated.
Cryptography2Several proof and hashing validation rules are added to EL code: the SSZ merkleization commitment, MPT witness proof verification and header-chain hashing. All use established primitives (SHA-256 SSZ merkleization, keccak MPT). No novel cryptography runs on the EL; the zk proof system lives in the proof node.
  • eip.md · Guest validation — `compute_new_payload_request_root` The guest computes the SSZ `hash_tree_root` of `NewPayloadRequest` using progressive containers. This is a new hashing commitment rule on the EL side.
  • eip.md · Guest validation — `WitnessState` "A key reads as absent only when the witness contains the trie path that proves its absence" Adds MPT inclusion/exclusion proof verification against the parent state root.
  • eip.md · Guest validation — `validate_headers` Adds keccak header-chain contiguity verification.
Confidence: Medium
Uncertainty: No test resources for progressive-container hash_tree_root or witness verification are supplied (evidence gap). zk verification is outside the EL.
Patterns affecting pre-existing testsUnder-specified1Expected results of baseline tests do not change. Re-running existing engine fixtures through the guest mostly adds a consumption mode rather than reworking cases. Some localized rework is likely where fixtures need ancestor headers (BLOCKHASH depth) or a full pre-state to derive witnesses, so level 1 rather than 0.
  • eip.md · Test Cases — "Guest programs should run the `blockchain_test_engine` fixtures rather than `blockchain_test`" Existing engine fixtures are reused as guest inputs. Each one then needs a witness and a `StatelessInput` wrapping.
  • eip.md · Backwards Compatibility — "fully opt-in" Expected results for normal client execution are unchanged.
Confidence: Low
Uncertainty: It is unclear whether adapting existing fixtures for guest consumption counts as rework or as purely new feature tests. The plausible range is 0–2.
Unspecified behavior requiring cross-client consensusUnder-specified1The output for a payload whose timestamp falls outside the guest's fork is not specified exactly. The surrounding failure semantics point to one intended outcome.
  • eip.md · Guest validation — "its Amsterdam guest does not compare the payload timestamp with fork activation data. Production implementations MUST perform this comparison." The fork-timestamp check is required but not specified in the reference. The surrounding rule (failure after decoding retains decoded values and sets success to false) suggests one outcome.
  • eip.md · Proof engine interface — "The value of `k` will be pinned" `k` is open but CL-only.
Confidence: Medium
Uncertainty: It is unclear whether a fork mismatch should produce a sentinel or a retained-value failure; the range is 1–2. The source of `slot_number` is an evidence gap.
Show 17 zero-score criteria
Zero-score criteria (Checklist revision 3)
CriterionScoreWhy this scoreEvidence / uncertainty
Added opcodes0None.
  • eip.md · Execution Layer No instructions are added.
Modified opcodes0Instruction semantics are unchanged; only the data source in a stateless context differs.
  • eip.md · Stateless input and output — "serves `BLOCKHASH` from their hashes" In the guest, BLOCKHASH data comes from witness headers, but its specified semantics are unchanged.
Added precompiles0None.
  • eip.md · Execution Layer No precompiles are added.
Modified precompiles0None.
  • eip.md · Execution Layer No precompile changes.
Added system contracts0None added.
  • eip.md · Execution Layer No system contract is introduced.
Modified system contracts0No system contract rules change. System-call state must be witnessed, but that is not a modification.
  • eip.md · Execution Layer Existing system contracts run unchanged within the guest.
EVM Gas rule changes0No execution-gas charging, metering or limit rule is introduced or changed.
  • eip.md · Guest validation — "uses the same `new_payload` path as the execution engine" The guest reuses the unchanged payload execution path; no gas accounting is altered.
  • eip.md · Backwards Compatibility — "does not change consensus validity rules" The EIP explicitly leaves consensus rules, including gas, unchanged.
State-access ordering within opcode execution0Witness recording observes accesses but does not change when any opcode accesses state or charges gas. BAL contents are unchanged.
  • eip.md · Host-side input construction — "block-level read/write tracker" Witness construction reuses the existing access tracker. It changes neither instruction access order nor BAL membership.
Uncertainty: Witness completeness depends on accesses recorded in the baseline order. That is a witness-construction concern, not an ordering change.
Blob gas accounting changes0No blob-gas pricing or limit rule changes.
  • eip.md · Guest validation — `is_valid_versioned_hashes` Existing blob checks are only reused inside the guest.
State gas accounting changes0No state-gas accounting changes.
  • eip.md · Abstract — "does not change consensus validity rules" No state-gas mechanism is introduced.
New EVM gas refund0No new refund.
  • eip.md · Execution Layer The EL changes are limited to a stateless guest, witness and serialization; no refund mechanism is added.
New transaction types0None.
  • eip.md · Execution Layer No transaction envelope is added.
New or modified transaction validity mechanisms0No consensus transaction-validity change.
  • eip.md · Backwards Compatibility — "does not change consensus validity rules" Transaction validity is unchanged.
New block / header fields0No header or block field is added by the target.
  • eip.md · Execution Layer No EL header member is added. `slot_number` appears in the SSZ payload, but its definition is not attributed to this EIP.
Uncertainty: `slot_number`'s defining EIP is not supplied; it is assumed to come from another proposal.
Block syncing changes0Header RLP decoding happens inside the guest's witness handling, not in block import or sync.
  • eip.md · Backwards Compatibility No change to execution-block RLP decoding or structural validation in block import.
New fork activation mechanism0No activation-specific EL state transition.
  • eip.md · SSZ encoding — schema ID fork byte Fork-specific schema selection only; no state migration.
Engine API changesUnder-specified0No Engine API endpoint or field change is specified. How the host obtains the witness from the EL is left unspecified.
  • eip.md · Proof engine interface — "API shape is modelled on the Engine API" ProofEngine is a separate CL-side interface, not an Engine API change.
  • eip.md · Stateless input and output — `NewPayloadRequest` SSZ definition Engine API request data is given an SSZ form for hashing. No new Engine API method or field is specified.
  • supporting/eip-7732.md · Engine API — "No changes needed." The prerequisite needs no Engine API change.
Uncertainty: An endpoint for exporting execution witnesses may be needed but is not specified. The `slot_number` payload field's origin is not in the supplied documents. The range is 0–2.
Assessment provenance
Assessed EIP revision
ethereum/EIPs@6dac5e7491 EIPS/eip-8025.md committed 2026-10-07 · information cutoff 2026-10-07T22:23:55Z
Current master · File history · blob e53336d66f · sha256 c358101a47c8
Rubric
Checklist revision 3 · ethspecs/pm@fe2f793b03
Evaluator
Opus 5.5 (claude-opus-5-5) at high effort, one tool-less call per EIP · isolation bubblewrap_claude_p_no_tools_v1
Source record
Frozen research record research/tasks/10-opus-v3-reassessment/prospective/outputs/assessments/hegota-2026-10-08/eip-8025.yaml · sha256 5f8f26f4469d
Supporting documents supplied with the EIP
supporting/eip-4844.md, supporting/eip-6110.md, supporting/eip-7002.md, supporting/eip-7251.md, supporting/eip-7688.md, supporting/eip-7732.md, supporting/eip-7928.md, supporting/eip-8282.md
Criterion legend and glossary

Every stacked bar, comparison matrix, and criterion table on this site uses the same criterion colours, abbreviations, and order. Colour marks the criterion group; the abbreviation and name identify the criterion. Scores are 0–3 per criterion (4 is exceptional; cross-EIP interactions is uncapped).

EVM surface

Opcodes, precompiles, and system contracts that are added or modified.

  • Added opcodes
    Introduces new opcodes
    Score anchors
    0
    No new opcodes are introduced.
    1
    A new simple opcode is introduced (no data portion, no complex stack mechanics, and a constant gas cost).
    2
    Multiple new simple opcodes are introduced, or a single new complex opcode is introduced (has data portion, or complex stack mechanics, or a dynamic gas cost).
    3
    Multiple new opcodes are introduced, and at least one of them is complex (has data portion, or complex stack mechanics, or a dynamic gas cost).
    • Cryptography opcodes are not considered complex by default. Refer to the "Cryptography" section for a separate assessment.
  • Modified opcodes
    Modifies pre-existing opcodes
    Score anchors
    0
    No pre-existing opcode modifications are introduced.
    3
    At least one pre-existing opcode's behavior is modified (not including gas changes) or a pre-existing opcode is deprecated.
  • Added precompiles
    Introduces new precompiles
    Score anchors
    0
    No new precompiles are introduced.
    1
    A new simple precompile is introduced (constant input length, constant gas cost).
    2
    Multiple new simple precompiles are introduced, or a single new complex precompile is introduced (dynamic input length or dynamic gas cost).
    3
    Multiple new precompiles are introduced, and at least one of them is complex (dynamic input length or dynamic gas cost).
    • Cryptography precompiles are not considered complex by default. Refer to the "Cryptography" for a separate assessment.
  • Modified precompiles
    Modifies pre-existing precompiles logic or gas-accounting
    Score anchors
    0
    No pre-existing precompiles are modified.
    1
    At least one pre-existing precompile has its gas schedule modified.
    2
    Multiple pre-existing precompiles have their gas schedule modified, or a single pre-existing precompile has its behavior modified.
    3
    The behavior of multiple pre-existing precompiles, or a single complex pre-existing precompile modified.
  • Added system contracts
    Introduces new system contract, stateful or not
    Score anchors
    0
    No new system contracts are introduced.
    1
    A new system contract is introduced that is not stateful nor does it trigger a new system action (e.g. requests to the consensus layer).
    2
    Multiple new system contracts are introduced or a single new system contract that is either stateful or triggers a new system action (e.g. requests to the consensus layer).
    3
    Multiple new system contracts are introduced and at least one of them is either stateful or triggers a new system action (e.g. requests to the consensus layer).
  • Modified system contracts
    Modifies pre-existing system contracts
    Score anchors
    0
    No modifications to pre-existing system contracts are introduced, directly or indirectly.
    1
    Does not directly modify any system contract, but its behavior has minor indirect effects on one or more system contracts.
    2
    Does not directly modify any system contract, but its behavior has major indirect effects on one or more system contracts.
    3
    At least one pre-existing system contract code or state is modified, which would involve irregular state transition or a similarly complex transition methodology.

Gas and accounting

Execution, blob, and state gas rules, refunds, and where charges happen inside opcodes.

  • EVM Gas rule changes
    New EVM gas accounting rules
    Score anchors
    0
    No gas accounting changes.
    1
    Existing gas accounting mechanism is updated.
    2
    A new gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State-access ordering within opcode execution · not in checklist revision 1
    Changes *where inside an opcode's execution* state is accessed, or where gas is charged relative to that access. Because a state access is recorded in the block-level access list only if execution had enough gas to reach it, this ordering is consensus-critical: moving it changes the BAL at every gas boundary of every affected opcode.
    Score anchors
    0
    No change to where state is accessed, or to where gas is charged relative to a state access, within any opcode.
    1
    A single opcode's state-access or gas-charge ordering changes.
    2
    Multiple opcodes' ordering changes, or a new state-accessing operation is introduced whose position in the order must be settled.
    3
    The ordering rule changes for a whole class of state-accessing opcodes at once, or what counts as a recordable state access is redefined — requiring existing BAL vectors to be re-derived across opcodes and forks.
    • Distinct from "Modified opcodes", which asks whether an opcode's **result** changed. This row asks about the **path to the result**, which is observable even when the result is identical. An EIP can be 0 on that row and 3 on this one.
    • Score changes **to** the ordering. Do not score the fact that state accesses are observable — they always are.
    • Each boundary must be re-tested against every other dimension that can change the answer (cold/warm, static/non-static, delegated/direct, revert/success), so the case count grows multiplicatively rather than additively. Note this explicitly under Special Considerations.
  • Blob gas accounting changes
    New Blob gas accounting rules which potentially affect pre-existing tests
    Score anchors
    0
    No blob gas accounting changes.
    1
    Existing blob gas accounting mechanism is updated.
    2
    A new blob gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new blob gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State gas accounting changes · not in checklist revision 1
    New state gas accounting rules. State gas is the cost of *writing* state, as opposed to accessing or executing it: `StateGasCosts`, `COST_PER_STATE_BYTE`, the block-level state gas budget, and the spill path into execution gas.
    Score anchors
    0
    No state gas accounting changes.
    1
    An existing state gas cost or `STATE_BYTES_PER_*` rate is adjusted.
    2
    A new state-gas-charging site is introduced, or the block-level state gas budget or reservoir allocation is modified.
    3
    A new state gas charging mechanism is introduced, or the spill interaction between state gas and execution gas is modified, affecting existing gas tests.
    • Harder to test than blob gas: the spill path means state gas cannot be metered independently of execution gas, and some costs (e.g. `NEW_ACCOUNT`) are state-dependent.
  • New EVM gas refund
    New gas-refund mechanism
    Score anchors
    0
    No new gas-refund mechanisms are introduced.
    1
    A new simple gas-refund mechanism is introduced that does not affect either existing tests or existing gas-refund mechanisms.
    2
    A new complex gas-refund mechanism is introduced or a simple mechanism that affects existing tests or existing gas-refund mechanisms.
    3
    A new complex gas-refund mechanism is introduced that affects existing tests or existing gas-refund mechanisms.

Blocks, transactions, and encoding

Transaction types and validity, block and header fields, encodings, syncing, and activation-time changes.

  • New transaction types
    Introduces a new transaction type
    Score anchors
    0
    No new transaction types are introduced.
    3
    A new transaction type is introduced.
  • New or modified transaction validity mechanisms
    Creates new or modifies pre-existing transaction types' validation mechanisms
    Score anchors
    0
    No changes are introduced to the validity rules of existing transaction types or to their intrinsic gas cost calculation.
    1
    Minor adjustments are introduced to validity rules or intrinsic gas cost calculation, but they do not significantly affect existing tests.
    2
    Changes to validity rules or intrinsic gas cost calculation affect existing tests, but require only limited updates to test cases and no redesign of the testing infrastructure.
    3
    Changes to validity rules or intrinsic gas cost calculation require extensive rework or redesign of the tests or testing infrastructure.
  • New block / header fields
    Introduces new block or block header fields
    Score anchors
    0
    No new block or header fields are introduced.
    3
    A new block or header field is introduced.
  • Encoding changes (RLP/SSZ)
    Introduces encoding changes at the transaction/block/interfaces level
    Score anchors
    0
    No encoding changes are introduced at the transaction, block, or interfaces levels.
    3
    An encoding change is introduced at transaction, block or interfaces level (e.g. RLP -> SSZ).
    • "Interfaces level" includes the Engine API. Score an Engine API encoding change (e.g. JSON -> SSZ) here.
  • Block syncing changes
    Modifies block RLP validation mechanisms that require test client syncing.
    Score anchors
    0
    No new RLP validation mechanism is introduced.
    1
    A single simple RLP validation mechanism is introduced.
    2
    Multiple simple RLP validation mechanisms are introduced or a single complex one.
    3
    Multiple RLP validation mechanisms are introduced and at least one of them is deemed complex.
  • New fork activation mechanism
    Modifies state, internal variables, or similar, at the fork activation block
    Score anchors
    0
    No state modifications, internal variables or similar are modified at the fork activation block.
    3
    Either a state modification or internal variables are modified at the fork activation block.
    • Initialization of new internal variable is not considered a modification.

Client interfaces

Engine API and transition-tool interface changes.

  • Engine API changes
    Introduces new fields to the Engine API directives
    Score anchors
    0
    No new fields or communication mechanisms are introduced to the Engine API.
    1
    A single new field is introduced in one of the Engine API endpoints.
    2
    Multiple fields are introduced to one or multiple Engine API end points, or a new Engine API end-point is introduced.
    3
    Multiple fields are introduced to one or multiple Engine API end points and a new Engine API end-point is introduced.
  • Engine API encoding changes · Checklist revision 1 only
    Engine API encoding changes (the revision-1 template defines no anchor text for this row).
  • Transition-tool interface changes
    Modifies or adds new fields to the transition tool interface.
    Score anchors
    0
    No modifications to the transition tool interface are required.
    1
    A single new field needs to be introduced to the transition tool interface.
    2
    Multiple new fields or a new mechanism has to be introduced to the transition tool interface.
    3
    Multiple new fields and a new mechanism has to be introduced to the transition tool interface.
    • Special consideration must be paid to this section if the EIP introduces a mechanism that requires the state transition tool to be aware whether the block it is processing is the fork-activation block.

Testing impact

Rework, new invariants, and new primitives required in the test framework.

  • Patterns affecting pre-existing tests
    Implements a new validation mechanism or rule that translates in reworking pre-existing tests
    Score anchors
    0
    No pre-existing tests are affected by this change.
    1
    Minor subset of existing tests are affected by this change.
    2
    Considerable subset of existing tests are affected by this change but involves only a contrived category of tests.
    3
    Major subset of existing tests are affected, including diverse category of tests (benchmarks, static, multiple forks, etc.).
  • New invariant on pre-existing tests · not in checklist revision 1
    Tests that are **not about this EIP** must nonetheless assert something this EIP produces. Their logic does not change; they gain a new thing to check.
    Score anchors
    0
    Pre-existing tests assert nothing new.
    1
    A narrow, contrived category of pre-existing tests gains a new assertion.
    2
    A broad category gains a new assertion, applied mechanically.
    3
    Every test in the fork gains the assertion regardless of what it tests, and pre-fork vectors must be re-derived to satisfy it.
    • Paired with the row above, and easy to confuse with it. "Patterns affecting pre-existing tests" asks whether existing tests must be **reworked**; this row asks whether they must **additionally assert something new**. Score both — an EIP can be low on one and high on the other.
  • New test-framework primitives · not in checklist revision 1
    Requires new abstractions in the test framework itself — expectation types, modifiers, helpers — beyond writing test functions with what already exists.
    Score anchors
    0
    Existing test primitives suffice.
    1
    Existing primitives need minor extension.
    2
    New expectation or modifier primitives are required, reusable within this EIP's own test suite.
    3
    New framework-level primitives are required that become a permanent part of the framework and are used by other EIPs' tests.

Risk and validation

Security, performance, boundary conditions, and cryptography that need validation.

  • Security risks
    Introduces or modifies mechanisms that could compromise the security of the chain, users, validators, or other stakeholders, if not implemented properly.
    Score anchors
    0
    No new mechanisms are introduced that could pose a security risk.
    1
    The introduced mechanisms are self-contained, can be validated in isolation, and do not alter existing invariants that could pose a security risk for any stakeholders.
    2
    The introduced mechanisms interact with a limited number of existing components, slightly altering their security assumptions and requiring a targeted security review or fuzzing.
    3
    The introduced mechanisms interact with multiple existing components, including critical ones, substantially altering their security assumptions and requiring an extensive security review and fuzzing.
  • Performance risks
    Introduces or modifies mechanisms and requires performance validation.
    Score anchors
    0
    No new mechanisms are introduced that require performance validation.
    1
    The introduced mechanisms can be benchmarked in isolation and do not affect existing performance behavior.
    2
    The introduced mechanisms cannot be fully benchmarked in isolation, but they only have a limited impact on the existing performance benchmarks.
    3
    The introduced mechanisms cannot be benchmarked in isolation and have a substantial impact on existing performance benchmarks or have complex interactions with existing mechanisms.
  • Edge/boundary conditions
    Feature contains edge/boundary conditions.
    Score anchors
    0
    No discernible edge cases or boundary conditions are introduced.
    1
    A single edge-case or boundary-condition prone mechanism is introduced.
    2
    Multiple edge-case or boundary-condition prone mechanisms are introduced, but none of them requires an elevated number of cases to test.
    3
    Multiple edge-case or boundary-condition prone mechanisms are introduced and at least one of them requires an elevated number of cases to test.
  • Cryptography
    Introduces new cryptography mechanisms or modifies existing functionality that involves cryptography
    Score anchors
    0
    No cryptography mechanisms are introduced.
    1
    A new cryptography mechanism is introduced but it is a well known mechanism that is known to have vast resources to aid on its testing.
    2
    Multiple new cryptography mechanisms are introduced that are well-known or a single but novel mechanism is introduced that is either untested or has limited resources.
    3
    Multiple new cryptography mechanisms are introduced and at least one of them is a novel mechanism.

Coordination

Cross-EIP interactions and behavior that clients must agree on before tests exist.

  • Cross-EIP interactions
    Introduces or modifies mechanisms that affect other EIPs in either the same or past forks.
    Score anchors
    0
    Fully self-contained EIP that does not depend on, modify, or conflict with any other EIP.
    1
    The EIP interacts with one or more other EIPs in a non-critical and limited way but can be tested independently for the most part.
    2
    The EIP depends on or modifies one or more other EIPs such that coordinated testing and consideration is required, but interactions are limited in scope and not complex.
    3
    The EIP has strong interdependencies with multiple EIPs, requiring extensive coordinated cross-EIP testing as well as potential re-design of existing test vectors.
    • +1 for every 3 additional interacting EIPs beyond the first 3, each of which requires its own coordinated test cases. List the EIPs in the rationale.
    • This row is intentionally uncapped, unlike every other anchor: each interacting EIP is another axis of the test matrix, so a ceiling would make a 12-EIP product indistinguishable from a 3-EIP one.
  • Unspecified behavior requiring cross-client consensus · not in checklist revision 1
    The EIP text does not determine the answer for cases a test can construct. Clients must agree on a previously unspecified detail before tests can be baselined. The cost here is coordination and re-baselining, not test writing.
    Score anchors
    0
    The EIP text determines the answer for every case a test could construct.
    1
    A few details are unspecified but have an obvious intended reading.
    2
    Details require client agreement before tests can be written, but they are localized.
    3
    A previously unspecified *and previously unobservable* behavior becomes consensus-critical; expect tests to be re-baselined on each round of EIP amendment.
    • Score this from the EIP's state at assessment time: whether it has client implementations, whether it has been through a devnet, and how many open questions remain on its discussion thread.