Retrospective LLM-Based Complexity Evaluations

EIP complexity assessment

EIP-8151: Account Code Restricted ecRecover

Assessed in Hegotá. The score describes the EIP text available at the snapshot, not the EIP as it stands today.

ProspectiveHegotáSnapshot 2026-08-25PFI at snapshotLayers: execution
LLM Completescore 22
Human Pending· No STEEL checklist existed on the ethspecs/pm default branch or in any open pull request at the snapshot.

LLM assessment

Evaluated on: · Spec revision: 2026-08-25 · ac450a4ab2 · Inclusion status at snapshot: PFI

Scope at the cutoff. Execution-layer assessment of the sealed Draft snapshot of EIP-8151. The proposal changes the existing ecRecover precompile so successful recovery performs an EIP-2929-priced raw-code account access and suppresses recovered addresses whose code is neither empty nor an EIP-7702 delegation indicator. Consensus-layer behavior is out of scope; no such surface is specified.

22MediumMedium
Evaluator
LLMChecklist v2
Confidence
Medium
Under-specified at assessment cutoff
Yes — 2 criteria affected
Plausible range
21–23 (Medium–High)
Snapshot
2026-08-25 · EIP revision ac450a4ab2 (2026-08-25)
Score bands · Checklist revision 2
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the LLM total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. Modified precompiles3
  2. Security risks3
  3. Edge/boundary conditions3
  4. Cross-EIP interactions3

Under-specified at assessment cutoff: Yes

The EIP text available at the assessment cutoff left material behavior unresolved. The affected criteria and the plausible total range record that uncertainty.

Why: The proposal does not completely order recovery, gas sufficiency, accessed-address warming, and the raw-code read when a successful recovery has insufficient gas for the added EIP-2929 charge. The normative steps and split reference functions therefore do not fix the consensus-visible outcome at every gas boundary.

Plausible total

21–23
recorded score 22 · plausible tiers Medium, High

Unresolved questions at the cutoff (2)
  • If recovery succeeds but the call cannot pay the warm or cold surcharge, is recovered_address added to accessed_addresses before the call fails?
  • Is the raw-code read attempted only after the entire surcharge is confirmed available, and what access is recorded at each exact gas boundary?
Notable ambiguities noted by the assessor (2)
  • Special consideration: recovery success or failure, warm or cold status, static or non-static call context, permitted or disallowed code, later reversion or success, and exact gas sufficiency create a multiplicative test matrix rather than independent additive cases.
  • The normative specification composes dynamic gas and raw-code permission, while the reference implementation presents them separately and omits an integrated gas call from its ecRecover function.

Criterion breakdown

EIP-8151 Hegotá: LLM criterion scores and rationale
CriterionScoreWhy this scoreEvidence / uncertainty
Modified precompiles3This is a behavior modification to one now-complex precompile: its output, gas, state access, and transaction access status all depend on recovery and account state.
  • eip.md · Specification > Modified ecRecover Behavior The existing ecRecover precompile gains a state-dependent output rule, returning zero for recovered accounts with disallowed raw code.
  • eip.md · Specification > Gas Cost The precompile also gains dynamic warm/cold gas, an account-code read, and mutation of accessed_addresses on cold successful recovery.
Confidence: High
Uncertainty: The exact access/gas boundary is open, but the specified modification is complex regardless of that resolution.
Security risks3The proposal substantially changes security assumptions across a critical authorization primitive, immutable contracts, account-code migration, and cross-domain proof systems, requiring extensive state- and context-aware review and fuzzing.
  • eip.md · Motivation The change protects immutable signature-authorizing contracts from use of an old ECDSA key after an account migrates to non-delegation code.
  • eip.md · Security Considerations > Cross-Domain / L2 Fault Proof Implications Making ecRecover state-dependent can make fault-proof or cross-domain re-execution incorrect when the execution contexts have different state.
  • eip.md · Security Considerations > Application-Level ECDSA Verification Application-level recovery bypasses the new restriction, creating a security boundary between precompile and non-precompile verification.
Confidence: High
Uncertainty: The EIP describes the affected security surfaces clearly, although the package contains no implementation or test evidence by design.
Edge/boundary conditions3Multiple boundary-prone mechanisms form an elevated matrix: recovery success, code shape, warm/cold status, call context and reversion, and gas just below, at, or above the required charge must be crossed rather than tested independently.
  • eip.md · Specification > Modified ecRecover Behavior and Account Code Check Outcomes split across failed and successful recovery, absent or empty code, exactly 23-byte delegation code with the required prefix, and every other non-empty code value.
  • eip.md · Specification > Gas Cost Successful cases split again by warm/cold status and exact gas sufficiency, while failed recovery does not access state.
  • supporting/eip-2929.md · Specification Access status is transaction-wide and scope-sensitive, including reversion of accesses made inside a reverted scope.
Confidence: High
Uncertainty: Exact gas-boundary warming behavior is unspecified, but the elevated case matrix exists under any resolution.
Cross-EIP interactions3Coordinated vectors must cover EIP-2929 warm/cold accounting, EIP-3607 code restriction semantics, EIP-7702 raw delegation indicators, and changed EIP-2612-style authorization behavior. These are strong dependencies across multiple existing mechanisms, with four identified EIPs but no uncapped bonus beyond the base score.
  • eip.md · Front matter and Abstract EIP-8151 requires EIPs 2929, 3607, and 7702 and combines their account access, code restriction, and delegation-indicator rules.
  • eip.md · Motivation and Rationale > Protocol-Level Modification Existing ERC-2612-style permit authorization is an explicit affected use case because immutable contracts automatically observe changed ecRecover results.
  • supporting/eip-7702.md · Specification > Delegation indicator and Transaction origination EIP-7702 defines the exact 23-byte delegation form and the exception to EIP-3607 on which EIP-8151 relies.
Confidence: High
Uncertainty: EIP-2612's sealed supporting file is only a move notice, so its interaction is grounded in EIP-8151's own explicit permit discussion.
Interacting EIPs: EIP-2612, EIP-2929, EIP-3607, EIP-7702
State-access ordering within opcode executionUnder-specified2A new state-accessing operation is introduced within execution of calls to the precompile. Its position after successful recovery, and relative to dynamic charging and the code read, creates consensus-visible gas and access-set boundaries.
  • eip.md · Specification > Modified ecRecover Behavior, steps 1-3 Recovery failure performs no state access, whereas successful recovery incurs warm/cold account cost and then checks the recovered account's raw code.
  • supporting/eip-2929.md · Specification > Storage read changes The inherited mechanism normally charges gas and updates accessed_addresses at the time of access, with scope reversion behavior.
Confidence: Medium
Uncertainty: The text does not fully determine whether a recovered address becomes warm when the call cannot pay the added warm/cold charge.
Patterns affecting pre-existing tests2A considerable subset of pre-existing ecRecover success and gas vectors needs post-fork variants, but the rework remains concentrated in the ecRecover call category rather than diverse execution behavior.
  • eip.md · Backwards Compatibility Successful recovery always gains an account-access charge, disallowed coded accounts now yield zero, and near-limit calls can become out-of-gas.
  • eip.md · Rationale > Returning 32 Zero Bytes Existing deployed low-level staticcall wrappers and zero-result handling are explicitly considered because the changed precompile behavior reaches existing call patterns.
Confidence: Medium
Uncertainty: The sealed package contains no test inventory, so the size of the affected pre-existing subset cannot be counted directly.
Performance risks2Database and cache effects cannot be fully measured as an isolated pure precompile benchmark, but the added work is limited to successful ecRecover calls and one recovered-account access per invocation.
  • eip.md · Specification > Gas Cost Every successful ECDSA recovery now performs a raw account-code read with transaction-context-dependent warm/cold status.
  • eip.md · Security Considerations > Cross-Domain / L2 Fault Proof Implications The precompile ceases to be a pure function of its cryptographic inputs and depends on current state and transaction access status.
Confidence: Medium
Uncertainty: The package gives gas pricing but no workload measurements for ecRecover frequency or code-read cost.
Unspecified behavior requiring cross-client consensusUnder-specified2Client agreement is needed for a localized set of gas-sufficiency and warming cases before precise vectors can be baselined; the core return and account-code rules are otherwise explicit.
  • eip.md · Specification > Modified ecRecover Behavior, step 3 The normative sequence says to consume the dynamic charge and then check raw code, but does not state the access-set result when the added charge cannot be paid.
  • eip.md · Reference Implementation Gas calculation and permission checking are presented as separate functions and the shown ecRecover function does not compose the gas function, leaving exact boundary sequencing implicit.
  • supporting/eip-2929.md · Specification > Storage read changes EIP-2929 makes charging and access-set update timing consensus-relevant, so the missing composition affects baselining at exact gas boundaries.
Confidence: Medium
Uncertainty: The intended ordering may be apparent to implementers, but it is not fully determined by the sealed normative text and pseudocode.
EVM Gas rule changes1The proposal updates ecRecover to use an existing EIP-2929 account-access gas mechanism; it does not introduce a new gas-accounting model.
  • eip.md · Specification > Gas Cost Every successful recovery adds either 100 gas for a warm recovered address or 2600 gas for a cold one, while failed recovery remains at 3000 gas.
  • supporting/eip-2929.md · Specification > Storage read changes EIP-2929 defines the existing accessed-address warm/cold mechanism and its 100 and 2600 gas costs.
Confidence: High
Uncertainty: The warm/cold amounts and success/failure split are explicit; exact out-of-gas sequencing is recorded separately as under-specification.
New invariant on pre-existing tests1Existing tests that successfully invoke ecRecover gain a narrow new transaction-access invariant even when their original logic is unrelated to EIP-8151.
  • eip.md · Specification > Gas Cost A cold recovered address must be added to accessed_addresses and is warm for later operations in the transaction.
Confidence: Medium
Uncertainty: The package does not describe which pre-existing harness outputs expose the ephemeral accessed-address set.
Show 18 zero-score criteria
Zero-score criteria (Checklist revision 2)
CriterionScoreWhy this scoreEvidence / uncertainty
Added opcodes0No opcode is added.
  • eip.md · Specification The proposal defines no new opcode.
Uncertainty: No material uncertainty in the package.
Modified opcodes0No pre-existing opcode behavior is modified as such.
  • eip.md · Specification > Modified ecRecover Behavior The changed result and gas behavior are assigned to the ecRecover precompile, not to an opcode definition.
Uncertainty: Call-path ordering is scored separately from opcode-result modification.
Added precompiles0No precompile is added.
  • eip.md · Abstract ecRecover at address 0x01 is explicitly an existing precompile being modified.
Uncertainty: No material uncertainty in the package.
Added system contracts0No system contract is added.
  • eip.md · Abstract The proposal modifies the pre-existing ecRecover precompile at address 0x01; it does not deploy a contract.
Uncertainty: No material uncertainty in the package.
Modified system contracts0No pre-existing system contract is directly or indirectly modified.
  • eip.md · Specification All normative changes target precompile behavior and account reads; no system-contract code or state transition is described.
Uncertainty: Precompiles are assessed under their dedicated anchors.
Blob gas accounting changes0No blob gas accounting mechanism is added or changed.
  • eip.md · Specification The normative changes are confined to ecRecover behavior, account access, and execution-gas cost; no blob gas rule is specified.
Uncertainty: No material uncertainty in the package.
State gas accounting changes0Reading raw code is an account access, not a state write, and no state gas mechanism or rate changes.
  • eip.md · Specification > Gas Cost The only new charge is EIP-2929 execution gas for reading an account; the proposal specifies no state-writing gas or state-gas budget.
Uncertainty: No material uncertainty in the package.
New EVM gas refund0No EVM gas-refund mechanism is introduced.
  • eip.md · Specification > Gas Cost The proposal defines base and warm/cold charges only and contains no refund behavior.
Uncertainty: No material uncertainty in the package.
New transaction types0No new transaction type is introduced.
  • eip.md · Specification The proposal changes precompile execution and defines no transaction envelope.
Uncertainty: EIP-7702 is a dependency, not a transaction type introduced by EIP-8151.
New or modified transaction validity mechanisms0Existing transaction validity mechanisms are not changed.
  • eip.md · Backwards Compatibility The compatibility changes are precompile return data and execution out-of-gas behavior; no transaction validity or intrinsic-gas rule is specified.
Uncertainty: The proposal borrows EIP-3607's account-code restriction concept but does not alter EIP-3607 transaction validation.
New block / header fields0No new block or header field is introduced.
  • eip.md · Specification No block or header field is defined.
Uncertainty: No material uncertainty in the package.
Encoding changes (RLP/SSZ)0The proposal introduces no encoding change at a scored interface.
  • eip.md · Specification No transaction, block, interface, RLP, or SSZ encoding is changed.
Uncertainty: No material uncertainty in the package.
Block syncing changes0No block encoding or syncing validation mechanism is introduced.
  • eip.md · Specification The proposal changes execution of an existing precompile and defines no block RLP validation rule.
Uncertainty: No material uncertainty in the package.
New fork activation mechanism0Activation is an ordinary behavior switch without an activation-block mutation.
  • eip.md · Specification > Modified ecRecover Behavior The new rule starts at activation, but no state, internal variable, or irregular transition is initialized or modified at the activation block.
Uncertainty: No material uncertainty in the package.
Engine API changes0The Engine API is unchanged.
  • eip.md · Specification No Engine API endpoint, field, or communication mechanism is specified.
Uncertainty: No material uncertainty in the package.
Transition-tool interface changes0Existing state-transition inputs suffice; no interface field or mechanism is added.
  • eip.md · Specification > Account Code Check The rule consumes existing transaction state, raw account code, and accessed_addresses; no transition-tool input or output field is defined.
Uncertainty: No material uncertainty in the package.
New test-framework primitives0The package provides no requirement for a new test-framework primitive.
  • eip.md · Specification Cases are expressed with existing account code, call gas, recovery inputs, return bytes, and EIP-2929 access status; no new expectation or modifier abstraction is specified.
Uncertainty: No test-framework design is included, so this zero reflects the absence of a demonstrated primitive requirement in the sealed evidence.
Cryptography0No cryptographic algorithm or recovery functionality is introduced or modified.
  • eip.md · Specification > Modified ecRecover Behavior, step 1 ECDSA public-key recovery is performed as currently specified; only the recovered address's state eligibility and gas treatment change.
Uncertainty: No material uncertainty in the package.
Assessment provenance
Assessed EIP revision
ethereum/EIPs@ac450a4ab2 EIPS/eip-8151.md committed 2026-08-25 · information cutoff 2026-08-25T11:56:58Z
Current master · File history · blob f893235a7e · sha256 9bf6c7143e5a
Rubric
Checklist revision 2 · ethspecs/pm@3d8c0128c5
Evaluator
gpt-5.6-sol at xhigh reasoning effort · isolation bubblewrap_one_eip_capsule_v1
Source record
Frozen research record research/tasks/08-hegota-prospective-complexity-assessment/outputs/assessments/hegota-pfi-2026-08-26/eip-8151.yaml · sha256 cf4ed273e02a
Supporting documents in the sealed package
supporting/eip-2612.md, supporting/eip-2929.md, supporting/eip-3607.md, supporting/eip-7702.md
Criterion legend and glossary

Every stacked bar, comparison matrix, and criterion table on this site uses the same criterion colours, abbreviations, and order. Colour marks the criterion group; the abbreviation and name identify the criterion. Scores are 0–3 per criterion (4 is exceptional; cross-EIP interactions is uncapped).

EVM surface

Opcodes, precompiles, and system contracts that are added or modified.

  • Added opcodes
    Introduces new opcodes
    Score anchors
    0
    No new opcodes are introduced.
    1
    A new simple opcode is introduced (no data portion, no complex stack mechanics, and a constant gas cost).
    2
    Multiple new simple opcodes are introduced, or a single new complex opcode is introduced (has data portion, or complex stack mechanics, or a dynamic gas cost).
    3
    Multiple new opcodes are introduced, and at least one of them is complex (has data portion, or complex stack mechanics, or a dynamic gas cost).
    • Cryptography opcodes are not considered complex by default. Refer to the "Cryptography" section for a separate assessment.
  • Modified opcodes
    Modifies pre-existing opcodes
    Score anchors
    0
    No pre-existing opcode modifications are introduced.
    3
    At least one pre-existing opcode's behavior is modified (not including gas changes) or a pre-existing opcode is deprecated.
  • Added precompiles
    Introduces new precompiles
    Score anchors
    0
    No new precompiles are introduced.
    1
    A new simple precompile is introduced (constant input length, constant gas cost).
    2
    Multiple new simple precompiles are introduced, or a single new complex precompile is introduced (dynamic input length or dynamic gas cost).
    3
    Multiple new precompiles are introduced, and at least one of them is complex (dynamic input length or dynamic gas cost).
    • Cryptography precompiles are not considered complex by default. Refer to the "Cryptography" for a separate assessment.
  • Modified precompiles
    Modifies pre-existing precompiles logic or gas-accounting
    Score anchors
    0
    No pre-existing precompiles are modified.
    1
    At least one pre-existing precompile has its gas schedule modified.
    2
    Multiple pre-existing precompiles have their gas schedule modified, or a single pre-existing precompile has its behavior modified.
    3
    The behavior of multiple pre-existing precompiles, or a single complex pre-existing precompile modified.
  • Added system contracts
    Introduces new system contract, stateful or not
    Score anchors
    0
    No new system contracts are introduced.
    1
    A new system contract is introduced that is not stateful nor does it trigger a new system action (e.g. requests to the consensus layer).
    2
    Multiple new system contracts are introduced or a single new system contract that is either stateful or triggers a new system action (e.g. requests to the consensus layer).
    3
    Multiple new system contracts are introduced and at least one of them is either stateful or triggers a new system action (e.g. requests to the consensus layer).
  • Modified system contracts
    Modifies pre-existing system contracts
    Score anchors
    0
    No modifications to pre-existing system contracts are introduced, directly or indirectly.
    1
    Does not directly modify any system contract, but its behavior has minor indirect effects on one or more system contracts.
    2
    Does not directly modify any system contract, but its behavior has major indirect effects on one or more system contracts.
    3
    At least one pre-existing system contract code or state is modified, which would involve irregular state transition or a similarly complex transition methodology.

Gas and accounting

Execution, blob, and state gas rules, refunds, and where charges happen inside opcodes.

  • EVM Gas rule changes
    New EVM gas accounting rules
    Score anchors
    0
    No gas accounting changes.
    1
    Existing gas accounting mechanism is updated.
    2
    A new gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State-access ordering within opcode execution · Checklist revision 2 only
    Changes *where inside an opcode's execution* state is accessed, or where gas is charged relative to that access. Because a state access is recorded in the block-level access list only if execution had enough gas to reach it, this ordering is consensus-critical: moving it changes the BAL at every gas boundary of every affected opcode.
    Score anchors
    0
    No change to where state is accessed, or to where gas is charged relative to a state access, within any opcode.
    1
    A single opcode's state-access or gas-charge ordering changes.
    2
    Multiple opcodes' ordering changes, or a new state-accessing operation is introduced whose position in the order must be settled.
    3
    The ordering rule changes for a whole class of state-accessing opcodes at once, or what counts as a recordable state access is redefined — requiring existing BAL vectors to be re-derived across opcodes and forks.
    • Distinct from "Modified opcodes", which asks whether an opcode's **result** changed. This row asks about the **path to the result**, which is observable even when the result is identical. An EIP can be 0 on that row and 3 on this one.
    • Score changes **to** the ordering. Do not score the fact that state accesses are observable — they always are.
    • Each boundary must be re-tested against every other dimension that can change the answer (cold/warm, static/non-static, delegated/direct, revert/success), so the case count grows multiplicatively rather than additively. Note this explicitly under Special Considerations.
  • Blob gas accounting changes
    New Blob gas accounting rules which potentially affect pre-existing tests
    Score anchors
    0
    No blob gas accounting changes.
    1
    Existing blob gas accounting mechanism is updated.
    2
    A new blob gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new blob gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State gas accounting changes · Checklist revision 2 only
    New state gas accounting rules. State gas is the cost of *writing* state, as opposed to accessing or executing it: `StateGasCosts`, `COST_PER_STATE_BYTE`, the block-level state gas budget, and the spill path into execution gas.
    Score anchors
    0
    No state gas accounting changes.
    1
    An existing state gas cost or `STATE_BYTES_PER_*` rate is adjusted.
    2
    A new state-gas-charging site is introduced, or the block-level state gas budget or reservoir allocation is modified.
    3
    A new state gas charging mechanism is introduced, or the spill interaction between state gas and execution gas is modified, affecting existing gas tests.
    • Harder to test than blob gas: the spill path means state gas cannot be metered independently of execution gas, and some costs (e.g. `NEW_ACCOUNT`) are state-dependent.
  • New EVM gas refund
    New gas-refund mechanism
    Score anchors
    0
    No new gas-refund mechanisms are introduced.
    1
    A new simple gas-refund mechanism is introduced that does not affect either existing tests or existing gas-refund mechanisms.
    2
    A new complex gas-refund mechanism is introduced or a simple mechanism that affects existing tests or existing gas-refund mechanisms.
    3
    A new complex gas-refund mechanism is introduced that affects existing tests or existing gas-refund mechanisms.

Blocks, transactions, and encoding

Transaction types and validity, block and header fields, encodings, syncing, and activation-time changes.

  • New transaction types
    Introduces a new transaction type
    Score anchors
    0
    No new transaction types are introduced.
    3
    A new transaction type is introduced.
  • New or modified transaction validity mechanisms
    Creates new or modifies pre-existing transaction types' validation mechanisms
    Score anchors
    0
    No changes are introduced to the validity rules of existing transaction types or to their intrinsic gas cost calculation.
    1
    Minor adjustments are introduced to validity rules or intrinsic gas cost calculation, but they do not significantly affect existing tests.
    2
    Changes to validity rules or intrinsic gas cost calculation affect existing tests, but require only limited updates to test cases and no redesign of the testing infrastructure.
    3
    Changes to validity rules or intrinsic gas cost calculation require extensive rework or redesign of the tests or testing infrastructure.
  • New block / header fields
    Introduces new block or block header fields
    Score anchors
    0
    No new block or header fields are introduced.
    3
    A new block or header field is introduced.
  • Encoding changes (RLP/SSZ)
    Introduces encoding changes at the transaction/block/interfaces level
    Score anchors
    0
    No encoding changes are introduced at the transaction, block, or interfaces levels.
    3
    An encoding change is introduced at transaction, block or interfaces level (e.g. RLP -> SSZ).
    • "Interfaces level" includes the Engine API. Score an Engine API encoding change (e.g. JSON -> SSZ) here.
  • Block syncing changes
    Modifies block RLP validation mechanisms that require test client syncing.
    Score anchors
    0
    No new RLP validation mechanism is introduced.
    1
    A single simple RLP validation mechanism is introduced.
    2
    Multiple simple RLP validation mechanisms are introduced or a single complex one.
    3
    Multiple RLP validation mechanisms are introduced and at least one of them is deemed complex.
  • New fork activation mechanism
    Modifies state, internal variables, or similar, at the fork activation block
    Score anchors
    0
    No state modifications, internal variables or similar are modified at the fork activation block.
    3
    Either a state modification or internal variables are modified at the fork activation block.
    • Initialization of new internal variable is not considered a modification.

Client interfaces

Engine API and transition-tool interface changes.

  • Engine API changes
    Introduces new fields to the Engine API directives
    Score anchors
    0
    No new fields or communication mechanisms are introduced to the Engine API.
    1
    A single new field is introduced in one of the Engine API endpoints.
    2
    Multiple fields are introduced to one or multiple Engine API end points, or a new Engine API end-point is introduced.
    3
    Multiple fields are introduced to one or multiple Engine API end points and a new Engine API end-point is introduced.
  • Engine API encoding changes · Checklist revision 1 only
    Engine API encoding changes (the revision-1 template defines no anchor text for this row).
  • Transition-tool interface changes
    Modifies or adds new fields to the transition tool interface.
    Score anchors
    0
    No modifications to the transition tool interface are required.
    1
    A single new field needs to be introduced to the transition tool interface.
    2
    Multiple new fields or a new mechanism has to be introduced to the transition tool interface.
    3
    Multiple new fields and a new mechanism has to be introduced to the transition tool interface.
    • Special consideration must be paid to this section if the EIP introduces a mechanism that requires the state transition tool to be aware whether the block it is processing is the fork-activation block.

Testing impact

Rework, new invariants, and new primitives required in the test framework.

  • Patterns affecting pre-existing tests
    Implements a new validation mechanism or rule that translates in reworking pre-existing tests
    Score anchors
    0
    No pre-existing tests are affected by this change.
    1
    Minor subset of existing tests are affected by this change.
    2
    Considerable subset of existing tests are affected by this change but involves only a contrived category of tests.
    3
    Major subset of existing tests are affected, including diverse category of tests (benchmarks, static, multiple forks, etc.).
  • New invariant on pre-existing tests · Checklist revision 2 only
    Tests that are **not about this EIP** must nonetheless assert something this EIP produces. Their logic does not change; they gain a new thing to check.
    Score anchors
    0
    Pre-existing tests assert nothing new.
    1
    A narrow, contrived category of pre-existing tests gains a new assertion.
    2
    A broad category gains a new assertion, applied mechanically.
    3
    Every test in the fork gains the assertion regardless of what it tests, and pre-fork vectors must be re-derived to satisfy it.
    • Paired with the row above, and easy to confuse with it. "Patterns affecting pre-existing tests" asks whether existing tests must be **reworked**; this row asks whether they must **additionally assert something new**. Score both — an EIP can be low on one and high on the other.
  • New test-framework primitives · Checklist revision 2 only
    Requires new abstractions in the test framework itself — expectation types, modifiers, helpers — beyond writing test functions with what already exists.
    Score anchors
    0
    Existing test primitives suffice.
    1
    Existing primitives need minor extension.
    2
    New expectation or modifier primitives are required, reusable within this EIP's own test suite.
    3
    New framework-level primitives are required that become a permanent part of the framework and are used by other EIPs' tests.

Risk and validation

Security, performance, boundary conditions, and cryptography that need validation.

  • Security risks
    Introduces or modifies mechanisms that could compromise the security of the chain, users, validators, or other stakeholders, if not implemented properly.
    Score anchors
    0
    No new mechanisms are introduced that could pose a security risk.
    1
    The introduced mechanisms are self-contained, can be validated in isolation, and do not alter existing invariants that could pose a security risk for any stakeholders.
    2
    The introduced mechanisms interact with a limited number of existing components, slightly altering their security assumptions and requiring a targeted security review or fuzzing.
    3
    The introduced mechanisms interact with multiple existing components, including critical ones, substantially altering their security assumptions and requiring an extensive security review and fuzzing.
  • Performance risks
    Introduces or modifies mechanisms and requires performance validation.
    Score anchors
    0
    No new mechanisms are introduced that require performance validation.
    1
    The introduced mechanisms can be benchmarked in isolation and do not affect existing performance behavior.
    2
    The introduced mechanisms cannot be fully benchmarked in isolation, but they only have a limited impact on the existing performance benchmarks.
    3
    The introduced mechanisms cannot be benchmarked in isolation and have a substantial impact on existing performance benchmarks or have complex interactions with existing mechanisms.
  • Edge/boundary conditions
    Feature contains edge/boundary conditions.
    Score anchors
    0
    No discernible edge cases or boundary conditions are introduced.
    1
    A single edge-case or boundary-condition prone mechanism is introduced.
    2
    Multiple edge-case or boundary-condition prone mechanisms are introduced, but none of them requires an elevated number of cases to test.
    3
    Multiple edge-case or boundary-condition prone mechanisms are introduced and at least one of them requires an elevated number of cases to test.
  • Cryptography
    Introduces new cryptography mechanisms or modifies existing functionality that involves cryptography
    Score anchors
    0
    No cryptography mechanisms are introduced.
    1
    A new cryptography mechanism is introduced but it is a well known mechanism that is known to have vast resources to aid on its testing.
    2
    Multiple new cryptography mechanisms are introduced that are well-known or a single but novel mechanism is introduced that is either untested or has limited resources.
    3
    Multiple new cryptography mechanisms are introduced and at least one of them is a novel mechanism.

Coordination

Cross-EIP interactions and behavior that clients must agree on before tests exist.

  • Cross-EIP interactions
    Introduces or modifies mechanisms that affect other EIPs in either the same or past forks.
    Score anchors
    0
    Fully self-contained EIP that does not depend on, modify, or conflict with any other EIP.
    1
    The EIP interacts with one or more other EIPs in a non-critical and limited way but can be tested independently for the most part.
    2
    The EIP depends on or modifies one or more other EIPs such that coordinated testing and consideration is required, but interactions are limited in scope and not complex.
    3
    The EIP has strong interdependencies with multiple EIPs, requiring extensive coordinated cross-EIP testing as well as potential re-design of existing test vectors.
    • +1 for every 3 additional interacting EIPs beyond the first 3, each of which requires its own coordinated test cases. List the EIPs in the rationale.
    • This row is intentionally uncapped, unlike every other anchor: each interacting EIP is another axis of the test matrix, so a ceiling would make a 12-EIP product indistinguishable from a 3-EIP one.
  • Unspecified behavior requiring cross-client consensus · Checklist revision 2 only
    The EIP text does not determine the answer for cases a test can construct. Clients must agree on a previously unspecified detail before tests can be baselined. The cost here is coordination and re-baselining, not test writing.
    Score anchors
    0
    The EIP text determines the answer for every case a test could construct.
    1
    A few details are unspecified but have an obvious intended reading.
    2
    Details require client agreement before tests can be written, but they are localized.
    3
    A previously unspecified *and previously unobservable* behavior becomes consensus-critical; expect tests to be re-baselined on each round of EIP amendment.
    • Score this from the EIP's state at assessment time: whether it has client implementations, whether it has been through a devnet, and how many open questions remain on its discussion thread.