Retrospective LLM-Based Complexity Evaluations

EIP complexity assessment

EIP-8151: Account Code Restricted ecRecover

Assessed in Hegotá. The score describes the EIP text available at the snapshot, not the EIP as it stands today.

ProspectiveHegotáSnapshot 2026-10-07EIP-8081: CFILayers: execution
LLM Completescore 18
Human Pending· No STEEL checklist existed on the ethspecs/pm default branch or in any open pull request at the snapshot.

LLM assessment

Evaluated on: · Spec revision: 2026-10-07 · 6dac5e7491 · EIP-8081 list: CFI

Scope at the cutoff. EIP-8151 changes the ecRecover precompile at address 0x01. After a successful ECDSA recovery, the precompile charges the EIP-2929 warm/cold account-access cost for the recovered address (+100 or +2600 on top of 3000) and adds that address to accessed_addresses. It then reads the address's raw code without following delegation. It returns the address only if that code is empty or exactly a 23-byte 0xef0100||address EIP-7702 delegation indicator; otherwise it returns 32 zero bytes. A failed recovery keeps the 3000 gas cost and does no state access. The goal is to stop an old ECDSA key from authorizing contract actions after the account moves to non-delegation code, in line with the EIP-3607/EIP-7702 transaction-origination rule.

18MediumMedium
Evaluator
LLMChecklist v3
Confidence
Medium
Under-specified at assessment cutoff
Yes — 5 criteria affected
Plausible range
17–24 (Medium–High)
Snapshot
2026-10-07 · EIP revision 6dac5e7491 (2026-10-07)
Score bands · Checklist revision 3
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the LLM total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. Modified precompiles3
  2. State-access ordering within opcode execution2
  3. Patterns affecting pre-existing tests2
  4. Security risks2

Under-specified at assessment cutoff: Yes

The EIP text available at the assessment cutoff left material behavior unresolved. The affected criteria and the plausible total range record that uncertainty.

Why: The spec says failure and rejection 'return 32 zero bytes', calling this the existing behavior. This conflicts with the baseline, where ecRecover failure gives empty output, and makes return-data size ambiguous. The spec also does not say whether the address stays warm when the extra access charge runs out of gas, or whether the recovered address is recorded in the block-level access list.

Unresolved questions at the cutoff (4)
  • Does ecRecover return empty output or 32 zero bytes on recovery failure and on the new code-check rejection (RETURNDATASIZE 0 or 32)?
  • If the caller supplies enough gas for 3000 but not for the warm/cold surcharge, is the address still added to accessed_addresses, and is the failure an ordinary out-of-gas?
  • Is the recovered address recorded in the Amsterdam block-level access list?
  • Is protocol-internal recovery (transaction sender, EIP-7702 authority) explicitly unaffected?
Notable ambiguities noted by the assessor (4)
  • Claim that existing ecRecover returns 32 zero bytes on failure versus baseline empty output.
  • The reference implementation mutates accessed_addresses inside the gas function, before execution and any out-of-gas check.
  • Interaction with Amsterdam block-level access lists is not addressed.
  • The rationale says ecRecover never signals failure, but the added gas makes out-of-gas failures possible for callers that pass a fixed gas amount.

Criterion breakdown

EIP-8151 Hegotá: LLM criterion scores and rationale
CriterionScoreWhy this scoreEvidence / uncertainty
Modified precompiles3ecRecover has a behavior change (state-dependent output). Its gas becomes dynamic after the change, which makes it complex under this criterion. A complex precompile with a behavior change is level 3.
  • eip.md · Modified ecRecover Behavior Output now depends on the recovered account's raw code.
  • eip.md · Gas Cost Gas becomes dynamic: 3000, 3100 or 5600 depending on recovery outcome and warmth.
Confidence: High
State-access ordering within opcode executionUnder-specified2The precompile becomes a new state-accessing operation and needs an ordering rule: recover, then charge, then mark warm, then read code. Relevant combinations are cold/warm, recovery success/failure, out-of-gas in the precompile frame, and caller revert. No opcode class's common ordering changes, so this is level 2.
  • eip.md · Modified ecRecover Behavior, step 3 After recovery succeeds, charge 3000 plus the access cost, then check the raw code: a new state access with a defined charge-then-read sequence.
  • eip.md · Reference Implementation / ecrecover_gas The address is added to accessed_addresses inside the gas computation, before the code check.
Confidence: Medium
Uncertainty: The text does not say whether the recovered address is recorded in the Amsterdam block-level access list. Under the rubric's footnote on precompile internals, this could be argued down to 0–1.
Patterns affecting pre-existing testsUnder-specified2Gas expectations change for all ordinary successful-recovery cases in the ecRecover precompile family. Tests in other families that call 0x01 with exact gas, or later touch the recovered address, also need localized gas rework. There is no common rewrite across families, so this is level 2.
  • eip.md · Backwards Compatibility Every successful recovery now costs +100/+2600, and accounts with non-delegation code now get zero instead of the recovered address.
  • eip.md · Gas Cost recovered_address becomes warm for later operations in the same transaction.
Confidence: Medium
Uncertainty: If the 32-zero-byte wording is read literally for failure cases, existing failure-case return-data expectations also change (see UNSP).
Security risks2The precompile's purity and stable gas assumptions, which calling contracts and re-execution systems rely on, change. Adversarial checks are needed: the code-check bypass via the delegation-prefix boundary, the delegation-indicator allowance, and fixed-gas callers turning rejection into out-of-gas. The scope is a bounded precompile/caller interaction, so this is level 2.
  • eip.md · Security Considerations / Cross-Domain / L2 Fault Proof Implications ecRecover is no longer a pure function of (hash, v, r, s).
  • eip.md · Motivation Changes authorization results for permit-style contracts after migration.
  • eip.md · Backwards Compatibility Calls near their gas limit may now go out of gas, adding a failure path where the rationale claims ecRecover never fails.
Confidence: Medium
Edge/boundary conditionsUnder-specified2There are two boundary-sensitive mechanisms. (1) The code classification: empty, absent, length 22/23/24, prefix variants, delegation to zero/precompile/self. (2) The gas tiers 3000/3100/5600 with exact-gas out-of-gas boundaries. Their dimensions mostly separate (output depends on code; gas depends on warmth), so there is no elevated matrix. That is level 2.
  • eip.md · Account Code Check Permitted only if len==0, or len==23 with prefix ef0100; absent account counts as empty.
  • eip.md · Gas Cost Warm 100 vs cold 2600, and no extra charge on recovery failure.
Confidence: Medium
Uncertainty: Gas available × warmth × recovery success with out-of-gas outcomes could be argued to form an elevated matrix (level 3).
Cross-EIP interactionsUnder-specified2Coordinated cases are needed with EIP-2929 and EIP-7702. For EIP-2929: warmth from the tx sender, the access list or earlier opcodes sets ecRecover's cost, ecRecover's warming lowers later opcode costs, and warmth is rolled back on revert. For EIP-7702: authorization in a type-4 transaction followed by ecRecover, delegation clearing, and the boundaries of the 23-byte indicator. EIP-3607 needs only a consistency check. The scenarios are bounded, so this is level 2 rather than coupled restructuring.
  • eip.md · Gas Cost Reads and writes the EIP-2929 accessed_addresses set shared with other operations.
  • eip.md · Account Code Check Exempts EIP-7702 delegation indicators and does not follow delegation.
  • supporting/eip-7702.md · Behavior, steps 4 and 8 Authorization warms the authority and writes or clears the delegation indicator, both visible to the new check in the same transaction.
Confidence: Medium
Uncertainty: A type-4 transaction that both warms and delegates the authority, followed by ecRecover, couples two EIPs; this could be read as level 3.
Interacting EIPs: EIP-2929, EIP-7702, EIP-3607
Unspecified behavior requiring cross-client consensus2Under the established baseline, ecRecover failure gives empty output (RETURNDATASIZE 0), but the EIP's normative text says 32 zero bytes. That leaves competing observable outcomes for both the existing failure path and the new rejection path: a return-data size of 0 or 32. It also does not say whether the recovered address is warmed when the extra charge runs out of gas, or whether it enters the block-level access list. These localized competing outcomes need agreement before expected values can be fixed, which is level 2.
  • eip.md · Modified ecRecover Behavior, steps 2 and 5 States 'return 32 zero bytes' for failure and rejection, calling this 'the existing zero return value'.
  • eip.md · Rationale / Returning 32 Zero Bytes Asserts malformed v and failed recovery currently 'return 32 zero bytes with success = 1'.
  • eip.md · Reference Implementation Adds to accessed_addresses inside the gas function before any out-of-gas check; out-of-gas handling is not specified.
Confidence: Medium
Uncertainty: Treating baseline failure output as empty relies on general protocol knowledge rather than a supplied document. The block-level access list rules are not supplied, so that point is partly an evidence gap.
EVM Gas rule changesUnder-specified1The existing EIP-2929 warm/cold rule is applied at a new site: the ecRecover precompile's gas schedule. This changes the expected gas of a baseline operation (every successful ecRecover) without defining a new accounting mechanism. That fits level 1.
  • eip.md · Gas Cost Successful recovery adds 100 (warm) or 2600 (cold) gas following EIP-2929 and warms recovered_address; failed recovery stays at 3000.
  • eip.md · Rationale / EIP-2929 Gas Accounting Reuses the existing warm/cold access pattern to 'avoid introducing a new gas model'.
  • supporting/eip-2929.md · Storage read changes Defines the existing accessed_addresses warm/cold charging rule being applied at the new site.
Confidence: Medium
Uncertainty: Making precompile gas depend on state and recovery outcome could be treated as a new accounting mechanism that also changes baseline gas results (level 3).
New test-framework primitives1Existing primitives need local extensions: a state- and warmth-aware ecRecover gas calculator, and pre-state accounts with code at key-derived addresses that sign ecRecover inputs. No new shared abstraction is needed, so this is level 1.
  • eip.md · Gas Cost Precompile gas now depends on recovery outcome and warm/cold status.
  • supporting/eip-3607.md · Test Cases Shows the pattern of placing code at an address derived from a known private key.
Confidence: Medium
Uncertainty: Whether existing helpers already cover this is not evidenced; the score could be 0.
Performance risks1ecRecover becomes a CPU-plus-IO workload. An attacker can recover many distinct cold addresses, but each read is priced like an existing cold account access with 3000 gas on top. Benchmarking the combined precompile path should cover it without changing end-to-end assumptions, so this is level 1.
  • eip.md · Gas Cost Successful recovery now triggers an account code read priced at the standard 2600 cold access.
  • supporting/eip-2929.md · Motivation The 2600 cold access cost was calibrated for state-access IO.
Confidence: Medium
Uncertainty: Block-level access list growth from recovered addresses is unspecified and could call for integrated benchmarks (level 2).
Show 18 zero-score criteria
Zero-score criteria (Checklist revision 3)
CriterionScoreWhy this scoreEvidence / uncertainty
Added opcodes0No opcode is added.
  • eip.md · Specification No new instruction.
Modified opcodes0Precompile behavior changing behind an unchanged instruction does not count as an opcode modification.
  • eip.md · Modified ecRecover Behavior Only precompile behavior changes; CALL/STATICCALL semantics are unchanged.
Added precompiles0No new precompile address.
  • eip.md · Abstract Modifies the existing precompile at 0x01.
Added system contracts0No system contract is added.
  • eip.md · Specification Only a native precompile is changed.
Modified system contracts0No system contract is modified.
  • eip.md · Specification No system contract is referenced.
Blob gas accounting changes0No blob-gas rule is affected.
  • eip.md · Gas Cost Only execution-gas changes for ecRecover; nothing on blobs.
State gas accounting changes0Only a state read and an access charge are added. Per the rubric, access charges belong under GAS, not state-gas accounting.
  • eip.md · Account Code Check Read-only access to raw code; no state writes.
New EVM gas refund0No refund mechanism is introduced.
  • eip.md · Gas Cost No refund is described.
New transaction types0No new transaction envelope.
  • eip.md · Specification No transaction type is introduced.
New or modified transaction validity mechanisms0Transaction validity and intrinsic gas are unchanged. Precompile outputs are excluded from this criterion.
  • eip.md · Motivation EIP-3607/7702 already govern transaction authority; this EIP changes only the precompile.
  • supporting/eip-7702.md · Behavior, step 3/5 Authorization processing has its own recovery and code check, separate from the precompile.
Uncertainty: The text does not explicitly say that protocol-internal recovery (tx sender, 7702 authority) is unaffected, but the EIP scopes itself to the precompile.
New block / header fields0No header member is added.
  • eip.md · Specification No header field is added.
Encoding changes (RLP/SSZ)0No codec or schema change.
  • eip.md · Specification No serialized schema changes.
Block syncing changes0Only an execution-rule change.
  • eip.md · Specification No block decoding or structural validation change.
New fork activation mechanism0No activation-specific state transition.
  • eip.md · Modified ecRecover Behavior 'Starting at the activation': a rule selection only, with no state migration.
Engine API changes0No Engine API change.
  • eip.md · Specification No Engine API is mentioned or changed.
Transition-tool interface changes0No transition-tool field or mechanism change is required.
  • eip.md · Specification Changes are internal to precompile execution, using existing state and access-set inputs.
New invariant on pre-existing tests0Changed gas and output values count as rework (PAT), not new assertions.
  • eip.md · Specification No new log, header, receipt field or protocol-mandated write is introduced.
Cryptography0The cryptographic primitive and its validation rules are unchanged. The new gate is a state check after recovery.
  • eip.md · Modified ecRecover Behavior, step 1 ECDSA recovery is performed 'as currently specified'.
Uncertainty: The change could be read as altering the signature-verification outcome rule (level 1).
Assessment provenance
Assessed EIP revision
ethereum/EIPs@6dac5e7491 EIPS/eip-8151.md committed 2026-10-07 · information cutoff 2026-10-07T22:23:55Z
Current master · File history · blob fdca74467a · sha256 47ee87b138dc
Rubric
Checklist revision 3 · ethspecs/pm@fe2f793b03
Evaluator
Opus 5.5 (claude-opus-5-5) at high effort, one tool-less call per EIP · isolation bubblewrap_claude_p_no_tools_v1
Source record
Frozen research record research/tasks/10-opus-v3-reassessment/prospective/outputs/assessments/hegota-2026-10-08/eip-8151.yaml · sha256 d087a1a6f468
Supporting documents supplied with the EIP
supporting/eip-20.md, supporting/eip-2612.md, supporting/eip-2929.md, supporting/eip-3607.md, supporting/eip-7702.md
Criterion legend and glossary

Every stacked bar, comparison matrix, and criterion table on this site uses the same criterion colours, abbreviations, and order. Colour marks the criterion group; the abbreviation and name identify the criterion. Scores are 0–3 per criterion (4 is exceptional; cross-EIP interactions is uncapped).

EVM surface

Opcodes, precompiles, and system contracts that are added or modified.

  • Added opcodes
    Introduces new opcodes
    Score anchors
    0
    No new opcodes are introduced.
    1
    A new simple opcode is introduced (no data portion, no complex stack mechanics, and a constant gas cost).
    2
    Multiple new simple opcodes are introduced, or a single new complex opcode is introduced (has data portion, or complex stack mechanics, or a dynamic gas cost).
    3
    Multiple new opcodes are introduced, and at least one of them is complex (has data portion, or complex stack mechanics, or a dynamic gas cost).
    • Cryptography opcodes are not considered complex by default. Refer to the "Cryptography" section for a separate assessment.
  • Modified opcodes
    Modifies pre-existing opcodes
    Score anchors
    0
    No pre-existing opcode modifications are introduced.
    3
    At least one pre-existing opcode's behavior is modified (not including gas changes) or a pre-existing opcode is deprecated.
  • Added precompiles
    Introduces new precompiles
    Score anchors
    0
    No new precompiles are introduced.
    1
    A new simple precompile is introduced (constant input length, constant gas cost).
    2
    Multiple new simple precompiles are introduced, or a single new complex precompile is introduced (dynamic input length or dynamic gas cost).
    3
    Multiple new precompiles are introduced, and at least one of them is complex (dynamic input length or dynamic gas cost).
    • Cryptography precompiles are not considered complex by default. Refer to the "Cryptography" for a separate assessment.
  • Modified precompiles
    Modifies pre-existing precompiles logic or gas-accounting
    Score anchors
    0
    No pre-existing precompiles are modified.
    1
    At least one pre-existing precompile has its gas schedule modified.
    2
    Multiple pre-existing precompiles have their gas schedule modified, or a single pre-existing precompile has its behavior modified.
    3
    The behavior of multiple pre-existing precompiles, or a single complex pre-existing precompile modified.
  • Added system contracts
    Introduces new system contract, stateful or not
    Score anchors
    0
    No new system contracts are introduced.
    1
    A new system contract is introduced that is not stateful nor does it trigger a new system action (e.g. requests to the consensus layer).
    2
    Multiple new system contracts are introduced or a single new system contract that is either stateful or triggers a new system action (e.g. requests to the consensus layer).
    3
    Multiple new system contracts are introduced and at least one of them is either stateful or triggers a new system action (e.g. requests to the consensus layer).
  • Modified system contracts
    Modifies pre-existing system contracts
    Score anchors
    0
    No modifications to pre-existing system contracts are introduced, directly or indirectly.
    1
    Does not directly modify any system contract, but its behavior has minor indirect effects on one or more system contracts.
    2
    Does not directly modify any system contract, but its behavior has major indirect effects on one or more system contracts.
    3
    At least one pre-existing system contract code or state is modified, which would involve irregular state transition or a similarly complex transition methodology.

Gas and accounting

Execution, blob, and state gas rules, refunds, and where charges happen inside opcodes.

  • EVM Gas rule changes
    New EVM gas accounting rules
    Score anchors
    0
    No gas accounting changes.
    1
    Existing gas accounting mechanism is updated.
    2
    A new gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State-access ordering within opcode execution · not in checklist revision 1
    Changes *where inside an opcode's execution* state is accessed, or where gas is charged relative to that access. Because a state access is recorded in the block-level access list only if execution had enough gas to reach it, this ordering is consensus-critical: moving it changes the BAL at every gas boundary of every affected opcode.
    Score anchors
    0
    No change to where state is accessed, or to where gas is charged relative to a state access, within any opcode.
    1
    A single opcode's state-access or gas-charge ordering changes.
    2
    Multiple opcodes' ordering changes, or a new state-accessing operation is introduced whose position in the order must be settled.
    3
    The ordering rule changes for a whole class of state-accessing opcodes at once, or what counts as a recordable state access is redefined — requiring existing BAL vectors to be re-derived across opcodes and forks.
    • Distinct from "Modified opcodes", which asks whether an opcode's **result** changed. This row asks about the **path to the result**, which is observable even when the result is identical. An EIP can be 0 on that row and 3 on this one.
    • Score changes **to** the ordering. Do not score the fact that state accesses are observable — they always are.
    • Each boundary must be re-tested against every other dimension that can change the answer (cold/warm, static/non-static, delegated/direct, revert/success), so the case count grows multiplicatively rather than additively. Note this explicitly under Special Considerations.
  • Blob gas accounting changes
    New Blob gas accounting rules which potentially affect pre-existing tests
    Score anchors
    0
    No blob gas accounting changes.
    1
    Existing blob gas accounting mechanism is updated.
    2
    A new blob gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new blob gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State gas accounting changes · not in checklist revision 1
    New state gas accounting rules. State gas is the cost of *writing* state, as opposed to accessing or executing it: `StateGasCosts`, `COST_PER_STATE_BYTE`, the block-level state gas budget, and the spill path into execution gas.
    Score anchors
    0
    No state gas accounting changes.
    1
    An existing state gas cost or `STATE_BYTES_PER_*` rate is adjusted.
    2
    A new state-gas-charging site is introduced, or the block-level state gas budget or reservoir allocation is modified.
    3
    A new state gas charging mechanism is introduced, or the spill interaction between state gas and execution gas is modified, affecting existing gas tests.
    • Harder to test than blob gas: the spill path means state gas cannot be metered independently of execution gas, and some costs (e.g. `NEW_ACCOUNT`) are state-dependent.
  • New EVM gas refund
    New gas-refund mechanism
    Score anchors
    0
    No new gas-refund mechanisms are introduced.
    1
    A new simple gas-refund mechanism is introduced that does not affect either existing tests or existing gas-refund mechanisms.
    2
    A new complex gas-refund mechanism is introduced or a simple mechanism that affects existing tests or existing gas-refund mechanisms.
    3
    A new complex gas-refund mechanism is introduced that affects existing tests or existing gas-refund mechanisms.

Blocks, transactions, and encoding

Transaction types and validity, block and header fields, encodings, syncing, and activation-time changes.

  • New transaction types
    Introduces a new transaction type
    Score anchors
    0
    No new transaction types are introduced.
    3
    A new transaction type is introduced.
  • New or modified transaction validity mechanisms
    Creates new or modifies pre-existing transaction types' validation mechanisms
    Score anchors
    0
    No changes are introduced to the validity rules of existing transaction types or to their intrinsic gas cost calculation.
    1
    Minor adjustments are introduced to validity rules or intrinsic gas cost calculation, but they do not significantly affect existing tests.
    2
    Changes to validity rules or intrinsic gas cost calculation affect existing tests, but require only limited updates to test cases and no redesign of the testing infrastructure.
    3
    Changes to validity rules or intrinsic gas cost calculation require extensive rework or redesign of the tests or testing infrastructure.
  • New block / header fields
    Introduces new block or block header fields
    Score anchors
    0
    No new block or header fields are introduced.
    3
    A new block or header field is introduced.
  • Encoding changes (RLP/SSZ)
    Introduces encoding changes at the transaction/block/interfaces level
    Score anchors
    0
    No encoding changes are introduced at the transaction, block, or interfaces levels.
    3
    An encoding change is introduced at transaction, block or interfaces level (e.g. RLP -> SSZ).
    • "Interfaces level" includes the Engine API. Score an Engine API encoding change (e.g. JSON -> SSZ) here.
  • Block syncing changes
    Modifies block RLP validation mechanisms that require test client syncing.
    Score anchors
    0
    No new RLP validation mechanism is introduced.
    1
    A single simple RLP validation mechanism is introduced.
    2
    Multiple simple RLP validation mechanisms are introduced or a single complex one.
    3
    Multiple RLP validation mechanisms are introduced and at least one of them is deemed complex.
  • New fork activation mechanism
    Modifies state, internal variables, or similar, at the fork activation block
    Score anchors
    0
    No state modifications, internal variables or similar are modified at the fork activation block.
    3
    Either a state modification or internal variables are modified at the fork activation block.
    • Initialization of new internal variable is not considered a modification.

Client interfaces

Engine API and transition-tool interface changes.

  • Engine API changes
    Introduces new fields to the Engine API directives
    Score anchors
    0
    No new fields or communication mechanisms are introduced to the Engine API.
    1
    A single new field is introduced in one of the Engine API endpoints.
    2
    Multiple fields are introduced to one or multiple Engine API end points, or a new Engine API end-point is introduced.
    3
    Multiple fields are introduced to one or multiple Engine API end points and a new Engine API end-point is introduced.
  • Engine API encoding changes · Checklist revision 1 only
    Engine API encoding changes (the revision-1 template defines no anchor text for this row).
  • Transition-tool interface changes
    Modifies or adds new fields to the transition tool interface.
    Score anchors
    0
    No modifications to the transition tool interface are required.
    1
    A single new field needs to be introduced to the transition tool interface.
    2
    Multiple new fields or a new mechanism has to be introduced to the transition tool interface.
    3
    Multiple new fields and a new mechanism has to be introduced to the transition tool interface.
    • Special consideration must be paid to this section if the EIP introduces a mechanism that requires the state transition tool to be aware whether the block it is processing is the fork-activation block.

Testing impact

Rework, new invariants, and new primitives required in the test framework.

  • Patterns affecting pre-existing tests
    Implements a new validation mechanism or rule that translates in reworking pre-existing tests
    Score anchors
    0
    No pre-existing tests are affected by this change.
    1
    Minor subset of existing tests are affected by this change.
    2
    Considerable subset of existing tests are affected by this change but involves only a contrived category of tests.
    3
    Major subset of existing tests are affected, including diverse category of tests (benchmarks, static, multiple forks, etc.).
  • New invariant on pre-existing tests · not in checklist revision 1
    Tests that are **not about this EIP** must nonetheless assert something this EIP produces. Their logic does not change; they gain a new thing to check.
    Score anchors
    0
    Pre-existing tests assert nothing new.
    1
    A narrow, contrived category of pre-existing tests gains a new assertion.
    2
    A broad category gains a new assertion, applied mechanically.
    3
    Every test in the fork gains the assertion regardless of what it tests, and pre-fork vectors must be re-derived to satisfy it.
    • Paired with the row above, and easy to confuse with it. "Patterns affecting pre-existing tests" asks whether existing tests must be **reworked**; this row asks whether they must **additionally assert something new**. Score both — an EIP can be low on one and high on the other.
  • New test-framework primitives · not in checklist revision 1
    Requires new abstractions in the test framework itself — expectation types, modifiers, helpers — beyond writing test functions with what already exists.
    Score anchors
    0
    Existing test primitives suffice.
    1
    Existing primitives need minor extension.
    2
    New expectation or modifier primitives are required, reusable within this EIP's own test suite.
    3
    New framework-level primitives are required that become a permanent part of the framework and are used by other EIPs' tests.

Risk and validation

Security, performance, boundary conditions, and cryptography that need validation.

  • Security risks
    Introduces or modifies mechanisms that could compromise the security of the chain, users, validators, or other stakeholders, if not implemented properly.
    Score anchors
    0
    No new mechanisms are introduced that could pose a security risk.
    1
    The introduced mechanisms are self-contained, can be validated in isolation, and do not alter existing invariants that could pose a security risk for any stakeholders.
    2
    The introduced mechanisms interact with a limited number of existing components, slightly altering their security assumptions and requiring a targeted security review or fuzzing.
    3
    The introduced mechanisms interact with multiple existing components, including critical ones, substantially altering their security assumptions and requiring an extensive security review and fuzzing.
  • Performance risks
    Introduces or modifies mechanisms and requires performance validation.
    Score anchors
    0
    No new mechanisms are introduced that require performance validation.
    1
    The introduced mechanisms can be benchmarked in isolation and do not affect existing performance behavior.
    2
    The introduced mechanisms cannot be fully benchmarked in isolation, but they only have a limited impact on the existing performance benchmarks.
    3
    The introduced mechanisms cannot be benchmarked in isolation and have a substantial impact on existing performance benchmarks or have complex interactions with existing mechanisms.
  • Edge/boundary conditions
    Feature contains edge/boundary conditions.
    Score anchors
    0
    No discernible edge cases or boundary conditions are introduced.
    1
    A single edge-case or boundary-condition prone mechanism is introduced.
    2
    Multiple edge-case or boundary-condition prone mechanisms are introduced, but none of them requires an elevated number of cases to test.
    3
    Multiple edge-case or boundary-condition prone mechanisms are introduced and at least one of them requires an elevated number of cases to test.
  • Cryptography
    Introduces new cryptography mechanisms or modifies existing functionality that involves cryptography
    Score anchors
    0
    No cryptography mechanisms are introduced.
    1
    A new cryptography mechanism is introduced but it is a well known mechanism that is known to have vast resources to aid on its testing.
    2
    Multiple new cryptography mechanisms are introduced that are well-known or a single but novel mechanism is introduced that is either untested or has limited resources.
    3
    Multiple new cryptography mechanisms are introduced and at least one of them is a novel mechanism.

Coordination

Cross-EIP interactions and behavior that clients must agree on before tests exist.

  • Cross-EIP interactions
    Introduces or modifies mechanisms that affect other EIPs in either the same or past forks.
    Score anchors
    0
    Fully self-contained EIP that does not depend on, modify, or conflict with any other EIP.
    1
    The EIP interacts with one or more other EIPs in a non-critical and limited way but can be tested independently for the most part.
    2
    The EIP depends on or modifies one or more other EIPs such that coordinated testing and consideration is required, but interactions are limited in scope and not complex.
    3
    The EIP has strong interdependencies with multiple EIPs, requiring extensive coordinated cross-EIP testing as well as potential re-design of existing test vectors.
    • +1 for every 3 additional interacting EIPs beyond the first 3, each of which requires its own coordinated test cases. List the EIPs in the rationale.
    • This row is intentionally uncapped, unlike every other anchor: each interacting EIP is another axis of the test matrix, so a ceiling would make a 12-EIP product indistinguishable from a 3-EIP one.
  • Unspecified behavior requiring cross-client consensus · not in checklist revision 1
    The EIP text does not determine the answer for cases a test can construct. Clients must agree on a previously unspecified detail before tests can be baselined. The cost here is coordination and re-baselining, not test writing.
    Score anchors
    0
    The EIP text determines the answer for every case a test could construct.
    1
    A few details are unspecified but have an obvious intended reading.
    2
    Details require client agreement before tests can be written, but they are localized.
    3
    A previously unspecified *and previously unobservable* behavior becomes consensus-critical; expect tests to be re-baselined on each round of EIP amendment.
    • Score this from the EIP's state at assessment time: whether it has client implementations, whether it has been through a devnet, and how many open questions remain on its discussion thread.