Retrospective LLM-Based Complexity Evaluations

EIP complexity assessment

EIP-8279: Block Access List Byte Floor

Assessed in Hegotá. The score describes the EIP text available at the snapshot, not the EIP as it stands today.

ProspectiveHegotáSnapshot 2026-10-07EIP-8081: CFILayers: execution
LLM Completescore 24
Human Draft PRscore 22 · Checklist revision 2· ethspecs/pm #108 (draft)

Evaluated on: · Spec revision: 2026-10-07 · 6dac5e7491 · EIP-8081 list: CFI

Scope at the cutoff. EIP-8279 adds two per-transaction counters, `bal_data_bytes` and `floor_gas_used`, to EIP-7928 Block Access List (BAL) processing. Before an opcode inserts an entry into the BAL, it calls `meter_bal_data` with a fixed byte count for cold account or storage accesses, storage-value changes, value transfers, CREATE nonce and balance entries, and deployed code. That count, at 64 gas per byte, is added to the EIP-8131 static transaction floor. If the floor would exceed `tx.gas`, the operation raises OutOfGasError. The static floor seed also gains a fixed 51 BAL bytes per EIP-7702 authorization, which changes the transaction validity threshold. A storage slot returned to its pre-transaction value gets its 32 value bytes back. Final charging stays `tx.gasUsed = max(execution_gas_used, floor_gas_used)`. System calls and withdrawals are excluded from the meter.

24HighHigh
Evaluator
LLMChecklist v3
Confidence
Medium
Under-specified at assessment cutoff
Yes — 4 criteria affected
Plausible range
20–27 (Medium–High)
Snapshot
2026-10-07 · EIP revision 6dac5e7491 (2026-10-07)
Score bands · Checklist revision 3
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the LLM total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. EVM Gas rule changes3
  2. State-access ordering within opcode execution3
  3. Edge/boundary conditions3
  4. Cross-EIP interactions3

Under-specified at assessment cutoff: Yes

The EIP text available at the assessment cutoff left material behavior unresolved. The affected criteria and the plausible total range record that uncertainty.

Why: The pseudocode adds to `bal_data_bytes` before the OutOfGasError check and never rolls it back. The refund path recomputes `floor_gas_used` without a `tx.gas` check, so the floor could exceed `tx.gas`. Revert handling of per-slot value-charge tracking conflicts with the 'at most once per slot' wording. The meter's position relative to EIP-7928 pre-state and post-state gas validation is not given. It is also unclear whether resolving an EIP-7702 delegated target counts as a metered cold access.

Unresolved questions at the cutoff (5)
  • After a floor OutOfGasError, are the bytes already added to `bal_data_bytes` kept for later meter calls and refund recomputation?
  • Can the refund recompute set `floor_gas_used` above `tx.gas`, and if so, what gasUsed is charged?
  • Is per-slot value-charge tracking reverted with the frame? Does a committed O→Y write after a reverted O→X write meter 32 value bytes again?
  • Is `meter_bal_data` called before or after the EIP-7928 pre-state gas validation for each opcode?
  • Is resolving an EIP-7702 delegated target metered as a 20-byte cold account access?
Notable ambiguities noted by the assessor (6)
  • After a failed `meter_bal_data`, are the bytes that were added to `bal_data_bytes` kept? Can a later refund recompute push `floor_gas_used` above `tx.gas`?
  • An O→X write happens in a reverted frame, then a committed O→Y write follows. Are the 32 value bytes charged again, and is the per-slot charged flag reverted?
  • Is the floor check before or after EIP-7928 pre-state gas validation? This matters when the frame then OOGs and the floor binds.
  • Does resolving an EIP-7702 delegated target during CALL* meter 20 bytes as a cold account access?
  • The balance change of the CALL sender and accesses to warm-but-unrecorded addresses (precompiles) are not listed as metered triggers. This may break the claimed upper bound.
  • The specification refers to an `auth_bytes` term, but the defined name is `auth_bal_bytes`.

Criterion breakdown

EIP-8279 Hegotá: LLM criterion scores and rationale
CriterionScoreWhy this scoreEvidence / uncertainty
EVM Gas rule changes3This adds a new accounting mechanism: a runtime floor accumulator with its own out-of-gas trigger. It also changes existing settlement results: any floor-bound transaction that touches state, and type-4 transactions whose floor dominates, now get a different gasUsed. That meets level 3.
  • eip.md · Data meter and floor accumulator Adds a new runtime per-transaction floor accumulator: `new_floor = static_floor + bal_data_bytes * 64`. If the new floor exceeds `tx.gas`, the operation raises OutOfGasError.
  • eip.md · Final charge `tx.gasUsed = max(execution_gas_used, tx_env.floor_gas_used)` now includes runtime BAL bytes.
  • eip.md · Static floor seed The static floor adds 64 × 51 gas per authorization on top of EIP-8131's `tx_floor`.
  • supporting/eip-8131.md · Charging Baseline: `tx.gasUsed = max(execution_gas_used, tx_floor)`, a floor computed only from transaction content.
Confidence: High
State-access ordering within opcode executionUnder-specified3A common new ordering step (the floor check before BAL insertion) is added for every account-accessing and storage-accessing opcode class. It changes which accesses get recorded: an access that passes EIP-7928 pre-state validation can still be left out of the BAL if the floor check fails. Baseline BAL expectations for floor-bound transactions must be revised. This meets level 3.
  • eip.md · Data meter and floor accumulator — "MUST be called BEFORE the matching BAL insertion or state mutation" Adds a new gate before BAL insertion. An OutOfGasError at that gate aborts the operation before the BAL entry exists.
  • eip.md · Runtime data metering Metering applies across a whole class of operations: BALANCE, EXT*, CALL*, SELFDESTRUCT, CREATE/CREATE2, SLOAD and SSTORE, plus value transfers and code deployment.
  • supporting/eip-7928.md · Gas Validation Before State Access Baseline two-phase rule: pre-state validation must pass before access. Once it passes, the target is included in the BAL.
Confidence: Medium
Uncertainty: The order of the floor check relative to EIP-7928 pre-state gas validation is not specified. Baseline revisions are limited to floor-bound transactions, so level 2 is plausible.
Edge/boundary conditions3Several boundary-sensitive mechanisms are involved: the runtime floor-vs-`tx.gas` check, the static validity threshold with auths, the execution/floor crossover in the final `max`, and SSTORE value charge and refund. The SSTORE mechanism has an elevated matrix of original/current/new value × cold/warm × frame revert × whether the floor binds. The runtime check interacts with opcode type and the static seed. That meets level 3.
  • eip.md · Data meter and floor accumulator — "if new_floor > tx_env.gas_limit" Adds a runtime floor-overflow boundary at exactly `tx.gas`.
  • eip.md · Final charge — "tx.gas >= max(intrinsic, static_floor)" Changes the validity boundary through the per-auth term.
  • eip.md · Runtime data metering — storage value bytes charged/refunded The SSTORE value-byte charge and refund depend on original, current and new values.
  • eip.md · Reverts Meter entries in reverted frames are not rewound, so outcomes depend on revert context.
Confidence: Medium
Cross-EIP interactions3The target couples EIP-8131 static floors, EIP-7928 BAL recording rules, EIP-7702 authorization and delegation handling, and EIP-3529 SSTORE refunds. Coordinated scenarios are needed that check BAL contents and floor gas together. That meets level 3.
  • eip.md · Abstract — "Neither EIP alone closes the bypass" Behaviour is coupled with EIP-8131's floor and EIP-7928's BAL.
  • eip.md · Runtime data metering — "mirrors EIP-7928 ... not the EIP-3529 SSTORE gas refund" Coordinated cases are needed with EIP-7928 no-op-write semantics and EIP-3529 refunds.
  • eip.md · Per-auth coverage is static Couples with EIP-7702 `set_delegation` and the authorization floor.
Confidence: High
Interacting EIPs: EIP-7928, EIP-8131, EIP-7702, EIP-3529, EIP-7623, EIP-7976, EIP-7981, EIP-4844, EIP-2935, EIP-4788, EIP-7002, EIP-7251
New EVM gas refundUnder-specified2The floor-byte refund depends on history (original vs current value, earlier charge state, revert behaviour), so it counts as complex under the rubric. Existing EIP-3529 refund rules and baseline refund expectations are unchanged. That is level 2.
  • eip.md · Runtime data metering — "`SSTORE` returning a slot to its pre-transaction value | −32 (refund)" Adds a byte refund to the floor meter. It depends on the slot's pre-transaction value and on whether it was charged earlier.
  • eip.md · Runtime data metering — "not the EIP-3529 SSTORE gas refund" The refund is explicitly separate from EIP-3529 refunds, which are unchanged.
Confidence: Medium
Uncertainty: It is debatable whether a reduction of the floor accumulator counts as an 'EVM gas refund'. If it does not, the score would be 0.
Patterns affecting pre-existing tests2Rework is localized to several families: floor-bound calldata or access-list tests from EIP-8131/7623 that touch state, type-4 floor and validity boundary tests, and BAL tests built on floor-bound transactions. No common rewrite is needed across ordinary tests, because the floor rarely binds. That is level 2.
  • eip.md · Backwards Compatibility Minimum `tx.gas` changes only when the floor side already dominated, i.e. for calldata-heavy or BAL-heavy transactions.
  • eip.md · Static floor seed The per-authorization term changes the floor of type-4 transactions.
Confidence: Medium
Uncertainty: No test suite was supplied. The breadth is estimated from the specification.
New test-framework primitives2Tests need a new expectation helper. It must compute the runtime BAL-byte floor from an execution trace (cold accesses, value transfers, SSTORE original/current tracking, deployed code length) and combine it with the static floor. Fork floor calculators also need the per-auth term. This is a new expectation abstraction within the target's suite, which is level 2.
  • eip.md · Runtime data metering Computing expected gasUsed for floor-bound transactions requires modelling per-opcode BAL byte contributions, including SSTORE value tracking and refunds.
  • eip.md · Gas estimation `floor_gas_used` must be simulated alongside intrinsic gas.
Confidence: Medium
Uncertainty: Framework capabilities are not evidenced.
Security risks2The change couples transaction settlement to how the BAL builder records entries. The meter must stay an upper bound on EIP-7928 contents. Possible gaps include warm-but-unrecorded addresses, CALL-sender balance changes and delegation resolution. The meter must also never fire outside the EVM exception handler. This bounded interaction needs targeted differential fuzzing of the meter against actual BAL contents. That is level 2.
  • eip.md · Block-size bound The security claim is that every BAL byte is covered by the floor. Under-counting breaks the bound.
  • eip.md · Per-auth coverage is static — "would propagate uncaught and crash block processing" Metering at the wrong site can crash block processing.
  • supporting/eip-7928.md · Recording Semantics by Change Type BAL entries include CALL sender balances, precompiles and delegated targets. The meter must cover these (only the recipient's 32 balance bytes are listed for CALL).
Confidence: Medium
Unspecified behavior requiring cross-client consensusUnder-specified2Several localized outcomes are left open, and each changes gasUsed when the floor binds: the state after a failed meter, refund recompute bounds, revert handling of slot-charge tracking, ordering against EIP-7928 gas checks, and whether resolving an EIP-7702 delegated target meters 20 bytes. Clients must agree on these before expected values can be fixed. That is level 2.
  • eip.md · Data meter and floor accumulator — `tx_env.bal_data_bytes += num_bytes` before the check Bytes are added even when the check raises OutOfGasError and are not rolled back. Later meter calls, or the refund recompute, could then push `floor_gas_used` above `tx.gas`.
  • eip.md · Runtime data metering — "The refund subtracts from bal_data_bytes and recomputes floor_gas_used" The refund recompute has no `tx.gas` check, and its interaction with failed-meter bytes is undefined.
  • eip.md · Reverts — "value bytes charged inside a frame that later reverts are left in place" It is unclear whether the per-slot 'charged' state is reverted. This contradicts 'at most once per slot' for an O→X write in a reverted frame followed by a committed O→Y.
  • supporting/eip-7928.md · Gas Validation Before State Access The order of the floor meter relative to pre-state and post-state gas checks is unspecified. It is observable when the frame then OOGs and the floor binds.
Confidence: Medium
Uncertainty: Some of these outcomes may be intended to follow the pseudocode literally.
New or modified transaction validity mechanisms1Only a local bound changes in the existing floor validity condition (the per-auth term). The runtime check is an execution-time OOG, not a validity rule.
  • eip.md · Final charge — "Transaction validation continues to require tx.gas >= max(intrinsic, static_floor)" The existing validity condition now uses a static floor that includes 51 bytes × 64 gas per authorization.
  • supporting/eip-8131.md · Charging Baseline requirement: `tx.gas >= max(intrinsic, tx_floor)`.
Confidence: Medium
Performance risks1Component benchmarks of metering overhead are enough, together with checks that adversarial calldata+SLOAD blocks are capped. The change tightens a bound rather than adding resource coupling.
  • eip.md · Abstract — "block content is capped at block_gas_limit / 64 ≈ 0.89 MB" The worst-case block plus BAL size bound is reduced.
  • eip.md · Runtime data metering Adds per-opcode metering and per-slot original-value tracking on hot paths.
Confidence: Medium
Uncertainty: Validating the reduced worst-case block size could need integrated block-building measurements (level 2).
Show 17 zero-score criteria
Zero-score criteria (Checklist revision 3)
CriterionScoreWhy this scoreEvidence / uncertainty
Added opcodes0No new instructions.
  • eip.md · Runtime data metering Only existing opcodes are metered.
Modified opcodesUnder-specified0The only change at instruction level is an additional out-of-gas halt that comes from gas accounting. Under the rubric, gas-only and ordering-only changes do not count.
  • eip.md · Data meter and floor accumulator Opcodes gain an out-of-gas condition driven by the floor accumulator. Stack, memory and return semantics are unchanged.
  • eip.md · Counter, not a reservation Execution gas accounting is untouched. The meter only updates counters and checks against `tx.gas`.
Uncertainty: The floor OutOfGasError is a new exceptional-halt condition that does not depend on the frame's gas. If treated as a semantic change, the score would be 3.
Added precompiles0None.
  • eip.md · Specification No precompiles are introduced.
Modified precompiles0None.
  • eip.md · Specification No precompile changes.
Added system contracts0No new system contracts.
  • eip.md · System transactions and withdrawals Mentions existing system contracts only.
Modified system contracts0Contract rules and surrounding protocol behavior are unchanged. The exclusion leaves baseline behavior intact.
  • eip.md · System transactions and withdrawals — "do NOT consume from a per-transaction floor" System calls are excluded from metering, so their behavior is unchanged.
Blob gas accounting changes0No blob-gas charging, pricing or limits change.
  • eip.md · Static floor seed Blob versioned hashes enter the floor only through EIP-8131's `tx_floor`. This EIP leaves blob-gas pricing unchanged.
State gas accounting changes0The rubric places BAL data-size charges under GAS. No state-gas mechanism changes.
  • eip.md · Runtime data metering SSTORE value bytes and deployed code bytes are charged as BAL data bytes at the floor rate, not as state-growth gas.
New transaction types0None.
  • eip.md · Data meter and floor accumulator Explicitly introduces no new transaction type.
New block / header fields0None.
  • eip.md · Specification No header fields are added.
Encoding changes (RLP/SSZ)0No serialized schema changes.
  • eip.md · Data meter and floor accumulator — "no new transaction field or type is introduced" No schema changes.
Block syncing changes0Only execution and gas rules change. Block decoding and structural validation are unchanged.
  • eip.md · Data meter and floor accumulator No block structure or RLP changes.
New fork activation mechanism0No activation-specific state transition.
  • eip.md · Backwards Compatibility — "Hard fork." Rule activation only. No state migration.
Engine API changes0None.
  • eip.md · Specification No Engine API changes are described.
Transition-tool interface changes0No input or output fields need to change. gasUsed is already reported.
  • eip.md · Data meter and floor accumulator The counters are internal per-transaction state and are not part of any interface.
Uncertainty: Tooling might choose to expose `floor_gas_used` for debugging, but the specification does not require it.
New invariant on pre-existing tests0No new header, receipt or log output is added. Effects show up only in existing gasUsed values.
  • eip.md · Data meter and floor accumulator — "Neither is part of the signed transaction, RLP-encoded, gossiped, or persisted" The new counters are internal. No new outputs exist.
Cryptography0No cryptographic changes.
  • eip.md · Specification No cryptographic operations are introduced or changed.
Assessment provenance
Assessed EIP revision
ethereum/EIPs@6dac5e7491 EIPS/eip-8279.md committed 2026-10-07 · information cutoff 2026-10-07T22:23:55Z
Current master · File history · blob 43a44216d4 · sha256 90d09fbcdadd
Rubric
Checklist revision 3 · ethspecs/pm@fe2f793b03
Evaluator
Opus 5.5 (claude-opus-5-5) at high effort, one tool-less call per EIP · isolation bubblewrap_claude_p_no_tools_v1
Source record
Frozen research record research/tasks/10-opus-v3-reassessment/prospective/outputs/assessments/hegota-2026-10-08/eip-8279.yaml · sha256 7b8f0c0bd763
Supporting documents supplied with the EIP
supporting/eip-2935.md, supporting/eip-3529.md, supporting/eip-4788.md, supporting/eip-4844.md, supporting/eip-7002.md, supporting/eip-7251.md, supporting/eip-7623.md, supporting/eip-7702.md, supporting/eip-7928.md, supporting/eip-7976.md, supporting/eip-7981.md, supporting/eip-8131.md

Evaluated on: Not recorded

22MediumMedium
Evaluator
HumanChecklist v2
Confidence
Not recorded
Under-specified at assessment cutoff
Not recorded in the checklist
Checklist published
2026-08-17
Score bands · Checklist revision 2
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the Human total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. EVM Gas rule changes3
  2. Edge/boundary conditions3
  3. Cross-EIP interactions3
  4. State-access ordering within opcode execution2

Criterion breakdown

EIP-8279 Hegotá: Human criterion scores and rationale
CriterionScoreWhy this scoreNotes
EVM Gas rule changes3A new floor mechanism folded into `tx.gasUsed = max(execution_gas_used, floor_gas_used)`, extending the floor family that the eip7623/eip7976/eip7981 suites actively test. Measured: an EELS prototype flips 384 fixture executions across the eip7623/7976/2780/8037/7778/7934/7954 gas suites.—
Edge/boundary conditions3Nine runtime trigger rows x cold/warm x revert behavior x slot charge/refund toggling x the exact floor-binding boundary (`tx.gas == floor`) x the 7702 static seed — at least one mechanism with an elevated case count.—
Cross-EIP interactions3Four coordination targets: EIP-7928 (the substrate being priced), the EIP-7623/7976/8131 calldata-floor chain (one mechanism), EIP-7702 (the static seed), and EIP-8037 (the gas-dimension split) — short of the six needed for an increment. EIP-2929 cold tracking and EIP-4758's trigger change are touchpoints, not coordinated test matrices.—
State-access ordering within opcode execution2One uniform new abort point sits before every recordable access, and its position had to be settled (an access that aborts on the floor check must not commit its bytes, or settlement exceeds the gas limit). Measured: no existing BAL vectors change at all, so the re-derivation that anchors a 3 never materializes.—
New or modified transaction validity mechanisms2Validation becomes `tx.gas >= max(intrinsic, static_floor)` with the new per-auth BAL term; existing validity tests in the 8131/7981 family need limited updates.—
Patterns affecting pre-existing tests2The floor rarely binds for typical transactions. Measured: 384 of ~61,800 fixture executions fail, but they collapse to 11 test functions, all in floor/gas-boundary suites — a considerable but contrived category, dominated (336) by the two calldata-floor `test_transaction_validity` functions whose exact-boundary transactions now abort.—
Security risks2A DoS-bound mechanism: an implementation error either reopens the 1.5 MB block-size bypass or aborts valid transactions; interacts with core gas metering; targeted review and fuzzing.—
Performance risks2The meter itself is cheap, but the EIP redefines worst-case block composition — the bloatnet/worst-case benchmark suites that target exactly these vectors must be re-derived.—
New EVM gas refund1The −32-byte meter refund for restored slots is deliberately distinct from the EIP-3529 gas refund and never touches the refund counter; a simple mechanism whose complexity is already scored under the gas-rule and ordering rows.—
New test-framework primitives1The intrinsic/data-floor calculators already model the EIP-7623 floor family; they gain the per-authorization static seed term and byte-floor constants. Measured: the prototype suite needed only a small test-local scaffold helper beyond those extensions.—
Unspecified behavior requiring cross-client consensus1Two details are unwritten — the fit with EIP-8037's two gas dimensions, and whether an aborting access counts its bytes — but both have an obvious intended reading that held up in the prototype (the byte floor extends the calldata floor inside the existing settlement `max`; the aborted access never commits).—
Show 17 zero-score criteria
Zero-score criteria (Checklist revision 2)
CriterionScoreWhy this scoreNotes
Added opcodes0No rationale recorded.—
Modified opcodes0No rationale recorded.—
Added precompiles0No rationale recorded.—
Modified precompiles0No rationale recorded.—
Added system contracts0No rationale recorded.—
Modified system contracts0No rationale recorded.—
Blob gas accounting changes0No rationale recorded.—
State gas accounting changes0No rationale recorded.—
New transaction types0No rationale recorded.—
New block / header fields0No rationale recorded.—
Encoding changes (RLP/SSZ)0No rationale recorded.—
Block syncing changes0No rationale recorded.—
New fork activation mechanism0No rationale recorded.—
Engine API changes0No rationale recorded.—
Transition-tool interface changes0No rationale recorded.—
New invariant on pre-existing tests0No rationale recorded.—
Cryptography0No rationale recorded.—
Assessment provenance
Rubric
Checklist revision 2 · ethspecs/pm@3d8c0128c5
Evaluator
STEEL team · ethspecs/pm complexity_assessments
Source record
Open draft pull request #108: Add EIP-8279 complexity assessment · checklist at 9674b1fd58 · updated 2026-08-17
blob 7c3e42a49a · sha256 a26230f73a46
Research record
research/tasks/09-hegota-human-assessment-snapshot/outputs/assessments/eip-8279.yaml · sha256 ecdc047d8ba4

The LLM applied checklist revision 3 and the human reviewers revision 2 to EIP-8279 in Hegotá. Revision 3 phrases the same criteria more precisely; differences cover the 28 criteria both revisions share, and each total keeps its own revision. Δ is LLM minus Human.

Using the latest scored LLM evaluation for this checklist: 2026-10-08 · spec 2026-10-07 · 6dac5e7491. The Human and LLM assessments may use different spec revisions.

LLM24High
Human22Medium
Δ total+2Tiers differ: High vs Medium
Criteria22/28agree exactly · 6 differ by 1 · 0 differ by 2+

Complexity profiles side by side

LLM
Human

Largest disagreements: State-access ordering within opcode execution (+1), New EVM gas refund (+1), New test-framework primitives (+1), New or modified transaction validity mechanisms (−1), Performance risks (−1)

Per-criterion scores, Human versus LLM, ordered by the size of the difference
CriterionLLMHumanΔAgreementRationale from each source
State-access ordering within opcode execution32+1Differ by 1
Show rationale

LLM A common new ordering step (the floor check before BAL insertion) is added for every account-accessing and storage-accessing opcode class. It changes which accesses get recorded: an access that passes EIP-7928 pre-state validation can still be left out of the BAL if the floor check fails. Baseline BAL expectations for floor-bound transactions must be revised. This meets level 3.

Human One uniform new abort point sits before every recordable access, and its position had to be settled (an access that aborts on the floor check must not commit its bytes, or settlement exceeds the gas limit). Measured: no existing BAL vectors change at all, so the re-derivation that anchors a 3 never materializes.

New EVM gas refund21+1Differ by 1
Show rationale

LLM The floor-byte refund depends on history (original vs current value, earlier charge state, revert behaviour), so it counts as complex under the rubric. Existing EIP-3529 refund rules and baseline refund expectations are unchanged. That is level 2.

Human The −32-byte meter refund for restored slots is deliberately distinct from the EIP-3529 gas refund and never touches the refund counter; a simple mechanism whose complexity is already scored under the gas-rule and ordering rows.

New or modified transaction validity mechanisms12−1Differ by 1
Show rationale

LLM Only a local bound changes in the existing floor validity condition (the per-auth term). The runtime check is an execution-time OOG, not a validity rule.

Human Validation becomes `tx.gas >= max(intrinsic, static_floor)` with the new per-auth BAL term; existing validity tests in the 8131/7981 family need limited updates.

New test-framework primitives21+1Differ by 1
Show rationale

LLM Tests need a new expectation helper. It must compute the runtime BAL-byte floor from an execution trace (cold accesses, value transfers, SSTORE original/current tracking, deployed code length) and combine it with the static floor. Fork floor calculators also need the per-auth term. This is a new expectation abstraction within the target's suite, which is level 2.

Human The intrinsic/data-floor calculators already model the EIP-7623 floor family; they gain the per-authorization static seed term and byte-floor constants. Measured: the prototype suite needed only a small test-local scaffold helper beyond those extensions.

Performance risks12−1Differ by 1
Show rationale

LLM Component benchmarks of metering overhead are enough, together with checks that adversarial calldata+SLOAD blocks are capped. The change tightens a bound rather than adding resource coupling.

Human The meter itself is cheap, but the EIP redefines worst-case block composition — the bloatnet/worst-case benchmark suites that target exactly these vectors must be re-derived.

Unspecified behavior requiring cross-client consensus21+1Differ by 1
Show rationale

LLM Several localized outcomes are left open, and each changes gasUsed when the floor binds: the state after a failed meter, refund recompute bounds, revert handling of slot-charge tracking, ordering against EIP-7928 gas checks, and whether resolving an EIP-7702 delegated target meters 20 bytes. Clients must agree on these before expected values can be fixed. That is level 2.

Human Two details are unwritten — the fit with EIP-8037's two gas dimensions, and whether an aborting access counts its bytes — but both have an obvious intended reading that held up in the prototype (the byte floor extends the calldata floor inside the existing settlement `max`; the aborted access never commits).

Added opcodes000Agree
Show rationale

LLM No new instructions.

Human No rationale recorded.

Modified opcodes000Agree
Show rationale

LLM The only change at instruction level is an additional out-of-gas halt that comes from gas accounting. Under the rubric, gas-only and ordering-only changes do not count.

Human No rationale recorded.

Added precompiles000Agree
Show rationale

LLM None.

Human No rationale recorded.

Modified precompiles000Agree
Show rationale

LLM None.

Human No rationale recorded.

Added system contracts000Agree
Show rationale

LLM No new system contracts.

Human No rationale recorded.

Modified system contracts000Agree
Show rationale

LLM Contract rules and surrounding protocol behavior are unchanged. The exclusion leaves baseline behavior intact.

Human No rationale recorded.

EVM Gas rule changes330Agree
Show rationale

LLM This adds a new accounting mechanism: a runtime floor accumulator with its own out-of-gas trigger. It also changes existing settlement results: any floor-bound transaction that touches state, and type-4 transactions whose floor dominates, now get a different gasUsed. That meets level 3.

Human A new floor mechanism folded into `tx.gasUsed = max(execution_gas_used, floor_gas_used)`, extending the floor family that the eip7623/eip7976/eip7981 suites actively test. Measured: an EELS prototype flips 384 fixture executions across the eip7623/7976/2780/8037/7778/7934/7954 gas suites.

Blob gas accounting changes000Agree
Show rationale

LLM No blob-gas charging, pricing or limits change.

Human No rationale recorded.

State gas accounting changes000Agree
Show rationale

LLM The rubric places BAL data-size charges under GAS. No state-gas mechanism changes.

Human No rationale recorded.

New transaction types000Agree
Show rationale

LLM None.

Human No rationale recorded.

New block / header fields000Agree
Show rationale

LLM None.

Human No rationale recorded.

Encoding changes (RLP/SSZ)000Agree
Show rationale

LLM No serialized schema changes.

Human No rationale recorded.

Block syncing changes000Agree
Show rationale

LLM Only execution and gas rules change. Block decoding and structural validation are unchanged.

Human No rationale recorded.

New fork activation mechanism000Agree
Show rationale

LLM No activation-specific state transition.

Human No rationale recorded.

Engine API changes000Agree
Show rationale

LLM None.

Human No rationale recorded.

Transition-tool interface changes000Agree
Show rationale

LLM No input or output fields need to change. gasUsed is already reported.

Human No rationale recorded.

Patterns affecting pre-existing tests220Agree
Show rationale

LLM Rework is localized to several families: floor-bound calldata or access-list tests from EIP-8131/7623 that touch state, type-4 floor and validity boundary tests, and BAL tests built on floor-bound transactions. No common rewrite is needed across ordinary tests, because the floor rarely binds. That is level 2.

Human The floor rarely binds for typical transactions. Measured: 384 of ~61,800 fixture executions fail, but they collapse to 11 test functions, all in floor/gas-boundary suites — a considerable but contrived category, dominated (336) by the two calldata-floor `test_transaction_validity` functions whose exact-boundary transactions now abort.

New invariant on pre-existing tests000Agree
Show rationale

LLM No new header, receipt or log output is added. Effects show up only in existing gasUsed values.

Human No rationale recorded.

Security risks220Agree
Show rationale

LLM The change couples transaction settlement to how the BAL builder records entries. The meter must stay an upper bound on EIP-7928 contents. Possible gaps include warm-but-unrecorded addresses, CALL-sender balance changes and delegation resolution. The meter must also never fire outside the EVM exception handler. This bounded interaction needs targeted differential fuzzing of the meter against actual BAL contents. That is level 2.

Human A DoS-bound mechanism: an implementation error either reopens the 1.5 MB block-size bypass or aborts valid transactions; interacts with core gas metering; targeted review and fuzzing.

Edge/boundary conditions330Agree
Show rationale

LLM Several boundary-sensitive mechanisms are involved: the runtime floor-vs-`tx.gas` check, the static validity threshold with auths, the execution/floor crossover in the final `max`, and SSTORE value charge and refund. The SSTORE mechanism has an elevated matrix of original/current/new value × cold/warm × frame revert × whether the floor binds. The runtime check interacts with opcode type and the static seed. That meets level 3.

Human Nine runtime trigger rows x cold/warm x revert behavior x slot charge/refund toggling x the exact floor-binding boundary (`tx.gas == floor`) x the 7702 static seed — at least one mechanism with an elevated case count.

Cryptography000Agree
Show rationale

LLM No cryptographic changes.

Human No rationale recorded.

Cross-EIP interactions330Agree
Show rationale

LLM The target couples EIP-8131 static floors, EIP-7928 BAL recording rules, EIP-7702 authorization and delegation handling, and EIP-3529 SSTORE refunds. Coordinated scenarios are needed that check BAL contents and floor gas together. That meets level 3.

Human Four coordination targets: EIP-7928 (the substrate being priced), the EIP-7623/7976/8131 calldata-floor chain (one mechanism), EIP-7702 (the static seed), and EIP-8037 (the gas-dimension split) — short of the six needed for an increment. EIP-2929 cold tracking and EIP-4758's trigger change are touchpoints, not coordinated test matrices.

Criterion legend and glossary

Every stacked bar, comparison matrix, and criterion table on this site uses the same criterion colours, abbreviations, and order. Colour marks the criterion group; the abbreviation and name identify the criterion. Scores are 0–3 per criterion (4 is exceptional; cross-EIP interactions is uncapped).

EVM surface

Opcodes, precompiles, and system contracts that are added or modified.

  • Added opcodes
    Introduces new opcodes
    Score anchors
    0
    No new opcodes are introduced.
    1
    A new simple opcode is introduced (no data portion, no complex stack mechanics, and a constant gas cost).
    2
    Multiple new simple opcodes are introduced, or a single new complex opcode is introduced (has data portion, or complex stack mechanics, or a dynamic gas cost).
    3
    Multiple new opcodes are introduced, and at least one of them is complex (has data portion, or complex stack mechanics, or a dynamic gas cost).
    • Cryptography opcodes are not considered complex by default. Refer to the "Cryptography" section for a separate assessment.
  • Modified opcodes
    Modifies pre-existing opcodes
    Score anchors
    0
    No pre-existing opcode modifications are introduced.
    3
    At least one pre-existing opcode's behavior is modified (not including gas changes) or a pre-existing opcode is deprecated.
  • Added precompiles
    Introduces new precompiles
    Score anchors
    0
    No new precompiles are introduced.
    1
    A new simple precompile is introduced (constant input length, constant gas cost).
    2
    Multiple new simple precompiles are introduced, or a single new complex precompile is introduced (dynamic input length or dynamic gas cost).
    3
    Multiple new precompiles are introduced, and at least one of them is complex (dynamic input length or dynamic gas cost).
    • Cryptography precompiles are not considered complex by default. Refer to the "Cryptography" for a separate assessment.
  • Modified precompiles
    Modifies pre-existing precompiles logic or gas-accounting
    Score anchors
    0
    No pre-existing precompiles are modified.
    1
    At least one pre-existing precompile has its gas schedule modified.
    2
    Multiple pre-existing precompiles have their gas schedule modified, or a single pre-existing precompile has its behavior modified.
    3
    The behavior of multiple pre-existing precompiles, or a single complex pre-existing precompile modified.
  • Added system contracts
    Introduces new system contract, stateful or not
    Score anchors
    0
    No new system contracts are introduced.
    1
    A new system contract is introduced that is not stateful nor does it trigger a new system action (e.g. requests to the consensus layer).
    2
    Multiple new system contracts are introduced or a single new system contract that is either stateful or triggers a new system action (e.g. requests to the consensus layer).
    3
    Multiple new system contracts are introduced and at least one of them is either stateful or triggers a new system action (e.g. requests to the consensus layer).
  • Modified system contracts
    Modifies pre-existing system contracts
    Score anchors
    0
    No modifications to pre-existing system contracts are introduced, directly or indirectly.
    1
    Does not directly modify any system contract, but its behavior has minor indirect effects on one or more system contracts.
    2
    Does not directly modify any system contract, but its behavior has major indirect effects on one or more system contracts.
    3
    At least one pre-existing system contract code or state is modified, which would involve irregular state transition or a similarly complex transition methodology.

Gas and accounting

Execution, blob, and state gas rules, refunds, and where charges happen inside opcodes.

  • EVM Gas rule changes
    New EVM gas accounting rules
    Score anchors
    0
    No gas accounting changes.
    1
    Existing gas accounting mechanism is updated.
    2
    A new gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State-access ordering within opcode execution · not in checklist revision 1
    Changes *where inside an opcode's execution* state is accessed, or where gas is charged relative to that access. Because a state access is recorded in the block-level access list only if execution had enough gas to reach it, this ordering is consensus-critical: moving it changes the BAL at every gas boundary of every affected opcode.
    Score anchors
    0
    No change to where state is accessed, or to where gas is charged relative to a state access, within any opcode.
    1
    A single opcode's state-access or gas-charge ordering changes.
    2
    Multiple opcodes' ordering changes, or a new state-accessing operation is introduced whose position in the order must be settled.
    3
    The ordering rule changes for a whole class of state-accessing opcodes at once, or what counts as a recordable state access is redefined — requiring existing BAL vectors to be re-derived across opcodes and forks.
    • Distinct from "Modified opcodes", which asks whether an opcode's **result** changed. This row asks about the **path to the result**, which is observable even when the result is identical. An EIP can be 0 on that row and 3 on this one.
    • Score changes **to** the ordering. Do not score the fact that state accesses are observable — they always are.
    • Each boundary must be re-tested against every other dimension that can change the answer (cold/warm, static/non-static, delegated/direct, revert/success), so the case count grows multiplicatively rather than additively. Note this explicitly under Special Considerations.
  • Blob gas accounting changes
    New Blob gas accounting rules which potentially affect pre-existing tests
    Score anchors
    0
    No blob gas accounting changes.
    1
    Existing blob gas accounting mechanism is updated.
    2
    A new blob gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new blob gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State gas accounting changes · not in checklist revision 1
    New state gas accounting rules. State gas is the cost of *writing* state, as opposed to accessing or executing it: `StateGasCosts`, `COST_PER_STATE_BYTE`, the block-level state gas budget, and the spill path into execution gas.
    Score anchors
    0
    No state gas accounting changes.
    1
    An existing state gas cost or `STATE_BYTES_PER_*` rate is adjusted.
    2
    A new state-gas-charging site is introduced, or the block-level state gas budget or reservoir allocation is modified.
    3
    A new state gas charging mechanism is introduced, or the spill interaction between state gas and execution gas is modified, affecting existing gas tests.
    • Harder to test than blob gas: the spill path means state gas cannot be metered independently of execution gas, and some costs (e.g. `NEW_ACCOUNT`) are state-dependent.
  • New EVM gas refund
    New gas-refund mechanism
    Score anchors
    0
    No new gas-refund mechanisms are introduced.
    1
    A new simple gas-refund mechanism is introduced that does not affect either existing tests or existing gas-refund mechanisms.
    2
    A new complex gas-refund mechanism is introduced or a simple mechanism that affects existing tests or existing gas-refund mechanisms.
    3
    A new complex gas-refund mechanism is introduced that affects existing tests or existing gas-refund mechanisms.

Blocks, transactions, and encoding

Transaction types and validity, block and header fields, encodings, syncing, and activation-time changes.

  • New transaction types
    Introduces a new transaction type
    Score anchors
    0
    No new transaction types are introduced.
    3
    A new transaction type is introduced.
  • New or modified transaction validity mechanisms
    Creates new or modifies pre-existing transaction types' validation mechanisms
    Score anchors
    0
    No changes are introduced to the validity rules of existing transaction types or to their intrinsic gas cost calculation.
    1
    Minor adjustments are introduced to validity rules or intrinsic gas cost calculation, but they do not significantly affect existing tests.
    2
    Changes to validity rules or intrinsic gas cost calculation affect existing tests, but require only limited updates to test cases and no redesign of the testing infrastructure.
    3
    Changes to validity rules or intrinsic gas cost calculation require extensive rework or redesign of the tests or testing infrastructure.
  • New block / header fields
    Introduces new block or block header fields
    Score anchors
    0
    No new block or header fields are introduced.
    3
    A new block or header field is introduced.
  • Encoding changes (RLP/SSZ)
    Introduces encoding changes at the transaction/block/interfaces level
    Score anchors
    0
    No encoding changes are introduced at the transaction, block, or interfaces levels.
    3
    An encoding change is introduced at transaction, block or interfaces level (e.g. RLP -> SSZ).
    • "Interfaces level" includes the Engine API. Score an Engine API encoding change (e.g. JSON -> SSZ) here.
  • Block syncing changes
    Modifies block RLP validation mechanisms that require test client syncing.
    Score anchors
    0
    No new RLP validation mechanism is introduced.
    1
    A single simple RLP validation mechanism is introduced.
    2
    Multiple simple RLP validation mechanisms are introduced or a single complex one.
    3
    Multiple RLP validation mechanisms are introduced and at least one of them is deemed complex.
  • New fork activation mechanism
    Modifies state, internal variables, or similar, at the fork activation block
    Score anchors
    0
    No state modifications, internal variables or similar are modified at the fork activation block.
    3
    Either a state modification or internal variables are modified at the fork activation block.
    • Initialization of new internal variable is not considered a modification.

Client interfaces

Engine API and transition-tool interface changes.

  • Engine API changes
    Introduces new fields to the Engine API directives
    Score anchors
    0
    No new fields or communication mechanisms are introduced to the Engine API.
    1
    A single new field is introduced in one of the Engine API endpoints.
    2
    Multiple fields are introduced to one or multiple Engine API end points, or a new Engine API end-point is introduced.
    3
    Multiple fields are introduced to one or multiple Engine API end points and a new Engine API end-point is introduced.
  • Engine API encoding changes · Checklist revision 1 only
    Engine API encoding changes (the revision-1 template defines no anchor text for this row).
  • Transition-tool interface changes
    Modifies or adds new fields to the transition tool interface.
    Score anchors
    0
    No modifications to the transition tool interface are required.
    1
    A single new field needs to be introduced to the transition tool interface.
    2
    Multiple new fields or a new mechanism has to be introduced to the transition tool interface.
    3
    Multiple new fields and a new mechanism has to be introduced to the transition tool interface.
    • Special consideration must be paid to this section if the EIP introduces a mechanism that requires the state transition tool to be aware whether the block it is processing is the fork-activation block.

Testing impact

Rework, new invariants, and new primitives required in the test framework.

  • Patterns affecting pre-existing tests
    Implements a new validation mechanism or rule that translates in reworking pre-existing tests
    Score anchors
    0
    No pre-existing tests are affected by this change.
    1
    Minor subset of existing tests are affected by this change.
    2
    Considerable subset of existing tests are affected by this change but involves only a contrived category of tests.
    3
    Major subset of existing tests are affected, including diverse category of tests (benchmarks, static, multiple forks, etc.).
  • New invariant on pre-existing tests · not in checklist revision 1
    Tests that are **not about this EIP** must nonetheless assert something this EIP produces. Their logic does not change; they gain a new thing to check.
    Score anchors
    0
    Pre-existing tests assert nothing new.
    1
    A narrow, contrived category of pre-existing tests gains a new assertion.
    2
    A broad category gains a new assertion, applied mechanically.
    3
    Every test in the fork gains the assertion regardless of what it tests, and pre-fork vectors must be re-derived to satisfy it.
    • Paired with the row above, and easy to confuse with it. "Patterns affecting pre-existing tests" asks whether existing tests must be **reworked**; this row asks whether they must **additionally assert something new**. Score both — an EIP can be low on one and high on the other.
  • New test-framework primitives · not in checklist revision 1
    Requires new abstractions in the test framework itself — expectation types, modifiers, helpers — beyond writing test functions with what already exists.
    Score anchors
    0
    Existing test primitives suffice.
    1
    Existing primitives need minor extension.
    2
    New expectation or modifier primitives are required, reusable within this EIP's own test suite.
    3
    New framework-level primitives are required that become a permanent part of the framework and are used by other EIPs' tests.

Risk and validation

Security, performance, boundary conditions, and cryptography that need validation.

  • Security risks
    Introduces or modifies mechanisms that could compromise the security of the chain, users, validators, or other stakeholders, if not implemented properly.
    Score anchors
    0
    No new mechanisms are introduced that could pose a security risk.
    1
    The introduced mechanisms are self-contained, can be validated in isolation, and do not alter existing invariants that could pose a security risk for any stakeholders.
    2
    The introduced mechanisms interact with a limited number of existing components, slightly altering their security assumptions and requiring a targeted security review or fuzzing.
    3
    The introduced mechanisms interact with multiple existing components, including critical ones, substantially altering their security assumptions and requiring an extensive security review and fuzzing.
  • Performance risks
    Introduces or modifies mechanisms and requires performance validation.
    Score anchors
    0
    No new mechanisms are introduced that require performance validation.
    1
    The introduced mechanisms can be benchmarked in isolation and do not affect existing performance behavior.
    2
    The introduced mechanisms cannot be fully benchmarked in isolation, but they only have a limited impact on the existing performance benchmarks.
    3
    The introduced mechanisms cannot be benchmarked in isolation and have a substantial impact on existing performance benchmarks or have complex interactions with existing mechanisms.
  • Edge/boundary conditions
    Feature contains edge/boundary conditions.
    Score anchors
    0
    No discernible edge cases or boundary conditions are introduced.
    1
    A single edge-case or boundary-condition prone mechanism is introduced.
    2
    Multiple edge-case or boundary-condition prone mechanisms are introduced, but none of them requires an elevated number of cases to test.
    3
    Multiple edge-case or boundary-condition prone mechanisms are introduced and at least one of them requires an elevated number of cases to test.
  • Cryptography
    Introduces new cryptography mechanisms or modifies existing functionality that involves cryptography
    Score anchors
    0
    No cryptography mechanisms are introduced.
    1
    A new cryptography mechanism is introduced but it is a well known mechanism that is known to have vast resources to aid on its testing.
    2
    Multiple new cryptography mechanisms are introduced that are well-known or a single but novel mechanism is introduced that is either untested or has limited resources.
    3
    Multiple new cryptography mechanisms are introduced and at least one of them is a novel mechanism.

Coordination

Cross-EIP interactions and behavior that clients must agree on before tests exist.

  • Cross-EIP interactions
    Introduces or modifies mechanisms that affect other EIPs in either the same or past forks.
    Score anchors
    0
    Fully self-contained EIP that does not depend on, modify, or conflict with any other EIP.
    1
    The EIP interacts with one or more other EIPs in a non-critical and limited way but can be tested independently for the most part.
    2
    The EIP depends on or modifies one or more other EIPs such that coordinated testing and consideration is required, but interactions are limited in scope and not complex.
    3
    The EIP has strong interdependencies with multiple EIPs, requiring extensive coordinated cross-EIP testing as well as potential re-design of existing test vectors.
    • +1 for every 3 additional interacting EIPs beyond the first 3, each of which requires its own coordinated test cases. List the EIPs in the rationale.
    • This row is intentionally uncapped, unlike every other anchor: each interacting EIP is another axis of the test matrix, so a ceiling would make a 12-EIP product indistinguishable from a 3-EIP one.
  • Unspecified behavior requiring cross-client consensus · not in checklist revision 1
    The EIP text does not determine the answer for cases a test can construct. Clients must agree on a previously unspecified detail before tests can be baselined. The cost here is coordination and re-baselining, not test writing.
    Score anchors
    0
    The EIP text determines the answer for every case a test could construct.
    1
    A few details are unspecified but have an obvious intended reading.
    2
    Details require client agreement before tests can be written, but they are localized.
    3
    A previously unspecified *and previously unobservable* behavior becomes consensus-critical; expect tests to be re-baselined on each round of EIP amendment.
    • Score this from the EIP's state at assessment time: whether it has client implementations, whether it has been through a devnet, and how many open questions remain on its discussion thread.