Retrospective LLM-Based Complexity Evaluations

EIP complexity assessment

EIP-8282: Builder Execution Requests

Assessed in Amsterdam / Glamsterdam. The score describes the EIP text available at the assessment cutoff, not the EIP as it stands today.

RetrospectiveAmsterdam / GlamsterdamAssessment cutoff 2026-07-13Added after cutoffLayers: execution, consensus
LLM Completescore 22
Human Not available· The STEEL team did not publish a human checklist for this EIP in the Amsterdam assessment round.

LLM assessment

Evaluated on: · Spec revision: 2026-07-08 · 554d3325e3

Scope at the cutoff. EIP-8282 adds two new predeploys for EIP-7732 builders. One is a builder deposit contract that takes 184-byte calldata, checks that the amount is at least 1 ETH and that msg.value covers the fee plus the stake, queues the record and emits a LOG0. The other is a builder exit contract that takes a 48-byte pubkey, charges a fee and records msg.sender as source_address. Each contract reuses the EIP-7002/EIP-7251 request-bus storage layout, EIP-1559-style excess fee and EXCESS_INHIBITOR. An end-of-block SYSTEM_ADDRESS call drains each queue (up to 64 deposit and 16 exit records per block) into new EIP-7685 request types 0x03 and 0x04, which are committed in requests_hash. The remaining changes rewire consensus-layer handling of EIP-7732 builder onboarding and exits, and there is no reference bytecode yet.

22MediumMedium
Evaluator
LLMChecklist v3
Confidence
Medium
Under-specified at assessment cutoff
Yes — 7 criteria affected
Plausible range
18–30 (Medium–High)
Assessment cutoff
2026-07-13 · EIP revision 554d3325e3 (2026-07-08)
Score bands · Checklist revision 3
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the LLM total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. Added system contracts3
  2. Encoding changes (RLP/SSZ)3
  3. Edge/boundary conditions3
  4. Cross-EIP interactions3

Under-specified at assessment cutoff: Yes

The EIP text available at the assessment cutoff left material behavior unresolved. The affected criteria and the plausible total range record that uncertainty.

Why: Several consensus-visible details are left open. There is no reference bytecode, so gas use, storage packing of the 184-byte deposit record, log data and the derived addresses are not fixed. The 0x03 type byte conflicts with EIP-7804 and its allocation is deferred. The order of the new system calls relative to the existing ones is not stated.

Unresolved questions at the cutoff (5)
  • How are 184-byte deposit records laid out across storage slots from slot 4?
  • What are the final bytecode, deployment transactions and addresses?
  • Is 0x03/0x04 the final allocation, given the EIP-7804 conflict?
  • In what order are the builder system calls made relative to the EIP-7002/7251 calls?
  • Does the exit contract use its own excess state with TARGET=2, or the deposit contract's fee? The phrase 'same request fee as the deposit contract' is ambiguous.
Notable ambiguities noted by the assessor (4)
  • The exit contract is said to charge 'the same request fee as the deposit contract', but it has its own TARGET_EXIT_REQUESTS_PER_BLOCK and its own excess slot.
  • The system-call rule refers to a generic MAX_REQUESTS_PER_BLOCK and TARGET_REQUESTS_PER_BLOCK without naming per-contract values explicitly.
  • Deployment addresses depend on bytecode that has not been audited or frozen, and the Reference Implementation section is a TODO.
  • Overpayment beyond amount*1 gwei + fee is retained and not credited, so value boundaries need explicit vectors.

Criterion breakdown

EIP-8282 Amsterdam / Glamsterdam: LLM criterion scores and rationale
CriterionScoreWhy this scoreEvidence / uncertainty
Added system contracts3Multiple contracts are introduced, and both are stateful and trigger system actions (execution requests).
  • eip.md · Constants — BUILDER_DEPOSIT_CONTRACT_ADDRESS, BUILDER_EXIT_CONTRACT_ADDRESS Two new protocol-designated contracts are defined.
  • eip.md · Request queue and system call Both keep in-state queues and excess/count storage and emit EIP-7685 requests through system calls.
Confidence: High
Encoding changes (RLP/SSZ)3These are new request payload schemas within the existing request-type scheme.
  • eip.md · Consensus layer request objects New request payload schemas: 184-byte BuilderDepositRequest and 68-byte BuilderExitRequest, with amount little-endian.
  • eip.md · Deposit requests — "with the amount converted to its little-endian SSZ encoding" Defines the conversion from big-endian input to little-endian output.
Confidence: High
Edge/boundary conditions3Several independent boundary-sensitive mechanisms are introduced: calldata dispatch, the minimum deposit, the per-block caps, the excess/fee update and the inhibitor. The deposit funding check is an elevated matrix, because amount, fee/excess and msg.value interact and their combinations change acceptance.
  • eip.md · Deposit requests — "`amount * 1 gwei >= BUILDER_MIN_DEPOSIT`" and "`msg.value - fee >= amount * 1 gwei`" Deposit acceptance depends on amount, the current fee (from excess) and msg.value together.
  • eip.md · Request queue and system call Several boundaries apply: exact calldata sizes (184/48/0, all others revert), value-bearing fee-getter revert, MAX caps of 64/16, queue reset on full drain, and excess update with TARGET 8/2 and inhibitor handling.
Confidence: Medium
Cross-EIP interactionsUnder-specified3The target couples the EIP-7685 commitment ordering with the EIP-6110, 7002 and 7251 request sources. Coordinated scenarios are needed: blocks mixing all request types, one transaction calling several predeploys, failure of any system call, and type ordering and empty-type exclusion.
  • supporting/eip-7685.md · Block Header — "ordered by `request_type` ascending" The new types must be ordered and committed alongside 0x00–0x02, with empty types excluded.
  • eip.md · Request queue and system call — "if any of the predeploys' system calls fails" End-of-block processing now includes four request predeploy calls plus deposit log parsing.
  • eip.md · Changes to EIP-7732 Deposits to the validator deposit contract (EIP-6110), including 0xB0 credentials, stay type 0x00 and coexist with builder deposits.
Confidence: Medium
Uncertainty: Level 2 is also defensible if mixed-request tests are treated as simple extensions.
Interacting EIPs: EIP-7685, EIP-7002, EIP-7251, EIP-6110, EIP-1559, EIP-7732, EIP-7804
Block syncing changesUnder-specified2One complex validation, the requests_hash check that depends on execution state, changes content. The no-code and system-call-failure invalidity rules follow the existing pattern.
  • eip.md · Request queue and system call — "if any of the predeploys' system calls fails or returns an error, the block MUST be invalid" Adds block-invalidity conditions.
  • eip.md · Request queue and system call — "committed via the `requests_hash`" The content of the requests_hash header commitment now includes two new state-derived types.
Confidence: Medium
Uncertainty: It is debatable whether a change to requests_hash content counts as structural validation rather than an ordinary execution rule.
Security risks2The EL contract's value and minimum checks, and its msg.sender recording, are trusted by CL builder stake crediting and exit authorization. This bounded cross-layer interaction needs targeted adversarial cases: underfunded deposits, spoofed source_address, and non-system dequeue.
  • eip.md · Security Considerations — "`BUILDER_MIN_DEPOSIT` is enforced only at the execution layer ... with no consensus-layer re-assertion" The CL relies on the EL contract to check funding and the minimum before crediting builder stake.
  • eip.md · Security Considerations — Exit authorization / System-read access control msg.sender is the sole exit authorization, and only SYSTEM_ADDRESS can dequeue.
Confidence: Medium
Unspecified behavior requiring cross-client consensus2Several consensus-visible outcomes have competing possibilities: the storage packing of the 184-byte deposit record, the exact gas use and log layout, the final type byte, and the addresses. All of these need agreement or a reference implementation before expected results can be fixed.
  • eip.md · Reference Implementation — "TODO: Add test cases and reference implementation" Bytecode is missing. Addresses depend on bytecode that is not yet fixed.
  • eip.md · Request queue and system call — "reusing those contracts' storage layout" How a 184-byte record is packed into slots is not specified. State roots and gas depend on it.
  • eip.md · Constants — "EIP-7804, a Draft, also claims `0x03`); final allocation is coordinated in consensus-specs" The request type byte is not settled.
Confidence: Medium
Uncertainty: The EIP states that the bytecode will be supplied later, so the gap is localized rather than spread across families.
Patterns affecting pre-existing testsUnder-specified1Blocks with no builder requests keep the same requests_hash. Rework is limited to fork pre-allocation and to request-bus tests that enumerate request types and their ordering, which are localized cases.
  • eip.md · Deployment — "If there is no code at either predeploy address once the EIP is active, every block from activation onward MUST be invalid" Fork pre-states must contain both predeploys, so baseline fixtures need the new accounts.
  • eip.md · Backwards Compatibility — "blocks that contain no builder requests produce empty `request_data`" Blocks without builder requests leave requests_hash unchanged.
Confidence: Medium
Uncertainty: Whether adding the predeploys to pre-state is handled centrally by the framework, and whether the inhibitor-clearing writes change fork-transition expectations, cannot be established from the supplied evidence.
New invariant on pre-existing testsUnder-specified1Only fork-transition and request-bus cases need extra assertions: the predeploys' storage after the inhibitor is cleared, and the presence or absence of 0x03/0x04 requests. Ordinary tests gain no new output.
  • eip.md · Request fee — "that call clears the inhibitor" The first post-fork system call writes predeploy storage, which is a new state output in fork-transition blocks.
  • eip.md · Backwards Compatibility Empty builder request_data is excluded from requests_hash, so ordinary blocks show no new commitment output.
Confidence: Medium
Uncertainty: Post-state checks of the predeploy storage could apply more widely, depending on the fixture convention.
New test-framework primitives1These are local extensions of existing request-type helper primitives, as used for EIP-6110, 7002 and 7251.
  • eip.md · Consensus layer request objects BuilderDepositRequest (184 bytes) and BuilderExitRequest (68 bytes) need encoders and expected-request helpers.
Confidence: Medium
Performance risks1Component benchmarks of the new system-call drain cost and the enqueue path cover the workload. The system calls use the existing dedicated-gas pattern.
  • eip.md · Request queue and system call Two extra end-of-block system calls, draining up to 64×184-byte and 16×68-byte records, within a 30M dedicated gas limit.
  • eip.md · Security Considerations — Spam and state growth Enqueue is limited only by gas, and queue growth is gated by 1 ETH locked per deposit.
Confidence: Medium
Show 17 zero-score criteria
Zero-score criteria (Checklist revision 3)
CriterionScoreWhy this scoreEvidence / uncertainty
Added opcodes0No new opcodes.
  • eip.md · Specification No new instruction is defined.
Modified opcodes0No opcode modifications.
  • eip.md · Specification No instruction semantics change.
Added precompiles0No precompiles.
  • eip.md · Constants Only EVM predeploys are added, not precompiles.
Modified precompiles0None.
  • eip.md · Specification No precompile changes.
Modified system contracts0Existing contracts keep their rules, code and layout. The changed CL interpretation of 0xB0 deposits is CL-only.
  • eip.md · Backwards Compatibility — "It does not modify the validator deposit contract ... the validator withdrawal/consolidation predeploys" Existing system contracts are left unchanged.
Uncertainty: The order of the new system calls relative to the EIP-7002/7251 calls is not stated.
EVM Gas rule changes0The system-call gas exemption is inherited from EIP-7002/7251, and the fee is an ordinary contract fee. No execution-gas accounting rule changes.
  • eip.md · Request queue and system call — "dedicated gas limit of `30_000_000`" The system-call gas handling is restated from EIP-7002/7251. No new execution-gas accounting rule is introduced.
  • eip.md · Request fee The request fee is a contract-level value fee, not an execution-gas rule.
State-access ordering within opcode execution0No opcode's state-access or gas-charge ordering changes.
  • eip.md · Request queue and system call Only contract internals and system calls are defined. No instruction's access ordering changes.
Blob gas accounting changes0No blob-gas accounting change.
  • eip.md · Specification Blob gas is not mentioned anywhere.
State gas accounting changes0No state-gas mechanism or rate change.
  • eip.md · Request queue and system call Queue writes use ordinary storage under unchanged pricing.
New EVM gas refund0No new gas refund.
  • eip.md · Request fee — "left locked in the contract" No refund mechanism is introduced. Overpayment is retained by the contract.
New transaction types0No new transaction type.
  • eip.md · Specification Requests are submitted as ordinary contract calls. No transaction envelope is added.
New or modified transaction validity mechanisms0No consensus transaction-validity rule changes.
  • eip.md · Deposit requests — "The contract MUST reject" Rejection happens through a contract revert, which is application-level and not transaction validity.
New block / header fields0Adding a request type under an existing commitment is not a new header field.
  • eip.md · Backwards Compatibility New request types sit under the existing requests_hash.
New fork activation mechanismUnder-specified0Installation uses ordinary deployment transactions. Clearing the inhibitor is contract-internal recurring logic inherited from the EIP-7002 pattern, not a protocol-mandated state conversion.
  • eip.md · Deployment — "by a one-time presigned transaction" Contracts are installed by ordinary deployment transactions before the fork, not by protocol-mandated installation.
  • eip.md · Request fee — "the first system call clears the inhibitor" The inhibitor is cleared by contract logic inside the recurring system call, as in EIP-7002.
Uncertainty: The inhibitor clearing could be read as a one-time conversion embedded in a recurring system call.
Engine API changesUnder-specified0No Engine API field or endpoint is defined or changed.
  • eip.md · Request queue and system call Requests are carried through the existing EIP-7685 requests list.
  • supporting/eip-7732.md · Engine API — "No changes needed." The prerequisite states that no Engine API changes are needed.
Uncertainty: The EIP does not say whether Engine API request-type validation lists need updating.
Transition-tool interface changesUnder-specified0New request types travel through the existing requests output, so no new field or mechanism is needed.
  • supporting/eip-7685.md · Requests The requests are opaque type-prefixed bytes under the existing request scheme.
  • eip.md · Request queue and system call — "includes `request_type ++ request_data` in the block requests list" The new types use the existing requests list.
Uncertainty: No transition-tool evidence is supplied.
Cryptography0No EL cryptographic mechanism changes.
  • eip.md · Security Considerations — "the execution layer does not verify BLS" BLS verification is CL-only. The EL only carries the signature bytes.
  • supporting/eip-7685.md · Block Header The sha256 requests commitment is unchanged.
Assessment provenance
Assessed EIP revision
ethereum/EIPs@554d3325e3 EIPS/eip-8282.md committed 2026-07-08 · information cutoff 2026-07-13T07:12:57Z
Current master · File history · blob 35ab20cb31 · sha256 ff36162c244b
Rubric
Checklist revision 3 · ethspecs/pm@fe2f793b03
Evaluator
Opus 5.5 (claude-opus-5-5) at high effort, one tool-less call per EIP · isolation bubblewrap_claude_p_no_tools_v1
Source record
Frozen research record research/tasks/10-opus-v3-reassessment/retrospective/outputs/assessments/amsterdam/eip-8282.yaml · sha256 96ad961a02b3
Supporting documents supplied with the EIP
supporting/eip-1559.md, supporting/eip-6110.md, supporting/eip-7002.md, supporting/eip-7251.md, supporting/eip-7685.md, supporting/eip-7732.md, supporting/eip-7804.md
Criterion legend and glossary

Every stacked bar, comparison matrix, and criterion table on this site uses the same criterion colours, abbreviations, and order. Colour marks the criterion group; the abbreviation and name identify the criterion. Scores are 0–3 per criterion (4 is exceptional; cross-EIP interactions is uncapped).

EVM surface

Opcodes, precompiles, and system contracts that are added or modified.

  • Added opcodes
    Introduces new opcodes
    Score anchors
    0
    No new opcodes are introduced.
    1
    A new simple opcode is introduced (no data portion, no complex stack mechanics, and a constant gas cost).
    2
    Multiple new simple opcodes are introduced, or a single new complex opcode is introduced (has data portion, or complex stack mechanics, or a dynamic gas cost).
    3
    Multiple new opcodes are introduced, and at least one of them is complex (has data portion, or complex stack mechanics, or a dynamic gas cost).
    • Cryptography opcodes are not considered complex by default. Refer to the "Cryptography" section for a separate assessment.
  • Modified opcodes
    Modifies pre-existing opcodes
    Score anchors
    0
    No pre-existing opcode modifications are introduced.
    3
    At least one pre-existing opcode's behavior is modified (not including gas changes) or a pre-existing opcode is deprecated.
  • Added precompiles
    Introduces new precompiles
    Score anchors
    0
    No new precompiles are introduced.
    1
    A new simple precompile is introduced (constant input length, constant gas cost).
    2
    Multiple new simple precompiles are introduced, or a single new complex precompile is introduced (dynamic input length or dynamic gas cost).
    3
    Multiple new precompiles are introduced, and at least one of them is complex (dynamic input length or dynamic gas cost).
    • Cryptography precompiles are not considered complex by default. Refer to the "Cryptography" for a separate assessment.
  • Modified precompiles
    Modifies pre-existing precompiles logic or gas-accounting
    Score anchors
    0
    No pre-existing precompiles are modified.
    1
    At least one pre-existing precompile has its gas schedule modified.
    2
    Multiple pre-existing precompiles have their gas schedule modified, or a single pre-existing precompile has its behavior modified.
    3
    The behavior of multiple pre-existing precompiles, or a single complex pre-existing precompile modified.
  • Added system contracts
    Introduces new system contract, stateful or not
    Score anchors
    0
    No new system contracts are introduced.
    1
    A new system contract is introduced that is not stateful nor does it trigger a new system action (e.g. requests to the consensus layer).
    2
    Multiple new system contracts are introduced or a single new system contract that is either stateful or triggers a new system action (e.g. requests to the consensus layer).
    3
    Multiple new system contracts are introduced and at least one of them is either stateful or triggers a new system action (e.g. requests to the consensus layer).
  • Modified system contracts
    Modifies pre-existing system contracts
    Score anchors
    0
    No modifications to pre-existing system contracts are introduced, directly or indirectly.
    1
    Does not directly modify any system contract, but its behavior has minor indirect effects on one or more system contracts.
    2
    Does not directly modify any system contract, but its behavior has major indirect effects on one or more system contracts.
    3
    At least one pre-existing system contract code or state is modified, which would involve irregular state transition or a similarly complex transition methodology.

Gas and accounting

Execution, blob, and state gas rules, refunds, and where charges happen inside opcodes.

  • EVM Gas rule changes
    New EVM gas accounting rules
    Score anchors
    0
    No gas accounting changes.
    1
    Existing gas accounting mechanism is updated.
    2
    A new gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State-access ordering within opcode execution · not in checklist revision 1
    Changes *where inside an opcode's execution* state is accessed, or where gas is charged relative to that access. Because a state access is recorded in the block-level access list only if execution had enough gas to reach it, this ordering is consensus-critical: moving it changes the BAL at every gas boundary of every affected opcode.
    Score anchors
    0
    No change to where state is accessed, or to where gas is charged relative to a state access, within any opcode.
    1
    A single opcode's state-access or gas-charge ordering changes.
    2
    Multiple opcodes' ordering changes, or a new state-accessing operation is introduced whose position in the order must be settled.
    3
    The ordering rule changes for a whole class of state-accessing opcodes at once, or what counts as a recordable state access is redefined — requiring existing BAL vectors to be re-derived across opcodes and forks.
    • Distinct from "Modified opcodes", which asks whether an opcode's **result** changed. This row asks about the **path to the result**, which is observable even when the result is identical. An EIP can be 0 on that row and 3 on this one.
    • Score changes **to** the ordering. Do not score the fact that state accesses are observable — they always are.
    • Each boundary must be re-tested against every other dimension that can change the answer (cold/warm, static/non-static, delegated/direct, revert/success), so the case count grows multiplicatively rather than additively. Note this explicitly under Special Considerations.
  • Blob gas accounting changes
    New Blob gas accounting rules which potentially affect pre-existing tests
    Score anchors
    0
    No blob gas accounting changes.
    1
    Existing blob gas accounting mechanism is updated.
    2
    A new blob gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new blob gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State gas accounting changes · not in checklist revision 1
    New state gas accounting rules. State gas is the cost of *writing* state, as opposed to accessing or executing it: `StateGasCosts`, `COST_PER_STATE_BYTE`, the block-level state gas budget, and the spill path into execution gas.
    Score anchors
    0
    No state gas accounting changes.
    1
    An existing state gas cost or `STATE_BYTES_PER_*` rate is adjusted.
    2
    A new state-gas-charging site is introduced, or the block-level state gas budget or reservoir allocation is modified.
    3
    A new state gas charging mechanism is introduced, or the spill interaction between state gas and execution gas is modified, affecting existing gas tests.
    • Harder to test than blob gas: the spill path means state gas cannot be metered independently of execution gas, and some costs (e.g. `NEW_ACCOUNT`) are state-dependent.
  • New EVM gas refund
    New gas-refund mechanism
    Score anchors
    0
    No new gas-refund mechanisms are introduced.
    1
    A new simple gas-refund mechanism is introduced that does not affect either existing tests or existing gas-refund mechanisms.
    2
    A new complex gas-refund mechanism is introduced or a simple mechanism that affects existing tests or existing gas-refund mechanisms.
    3
    A new complex gas-refund mechanism is introduced that affects existing tests or existing gas-refund mechanisms.

Blocks, transactions, and encoding

Transaction types and validity, block and header fields, encodings, syncing, and activation-time changes.

  • New transaction types
    Introduces a new transaction type
    Score anchors
    0
    No new transaction types are introduced.
    3
    A new transaction type is introduced.
  • New or modified transaction validity mechanisms
    Creates new or modifies pre-existing transaction types' validation mechanisms
    Score anchors
    0
    No changes are introduced to the validity rules of existing transaction types or to their intrinsic gas cost calculation.
    1
    Minor adjustments are introduced to validity rules or intrinsic gas cost calculation, but they do not significantly affect existing tests.
    2
    Changes to validity rules or intrinsic gas cost calculation affect existing tests, but require only limited updates to test cases and no redesign of the testing infrastructure.
    3
    Changes to validity rules or intrinsic gas cost calculation require extensive rework or redesign of the tests or testing infrastructure.
  • New block / header fields
    Introduces new block or block header fields
    Score anchors
    0
    No new block or header fields are introduced.
    3
    A new block or header field is introduced.
  • Encoding changes (RLP/SSZ)
    Introduces encoding changes at the transaction/block/interfaces level
    Score anchors
    0
    No encoding changes are introduced at the transaction, block, or interfaces levels.
    3
    An encoding change is introduced at transaction, block or interfaces level (e.g. RLP -> SSZ).
    • "Interfaces level" includes the Engine API. Score an Engine API encoding change (e.g. JSON -> SSZ) here.
  • Block syncing changes
    Modifies block RLP validation mechanisms that require test client syncing.
    Score anchors
    0
    No new RLP validation mechanism is introduced.
    1
    A single simple RLP validation mechanism is introduced.
    2
    Multiple simple RLP validation mechanisms are introduced or a single complex one.
    3
    Multiple RLP validation mechanisms are introduced and at least one of them is deemed complex.
  • New fork activation mechanism
    Modifies state, internal variables, or similar, at the fork activation block
    Score anchors
    0
    No state modifications, internal variables or similar are modified at the fork activation block.
    3
    Either a state modification or internal variables are modified at the fork activation block.
    • Initialization of new internal variable is not considered a modification.

Client interfaces

Engine API and transition-tool interface changes.

  • Engine API changes
    Introduces new fields to the Engine API directives
    Score anchors
    0
    No new fields or communication mechanisms are introduced to the Engine API.
    1
    A single new field is introduced in one of the Engine API endpoints.
    2
    Multiple fields are introduced to one or multiple Engine API end points, or a new Engine API end-point is introduced.
    3
    Multiple fields are introduced to one or multiple Engine API end points and a new Engine API end-point is introduced.
  • Engine API encoding changes · Checklist revision 1 only
    Engine API encoding changes (the revision-1 template defines no anchor text for this row).
  • Transition-tool interface changes
    Modifies or adds new fields to the transition tool interface.
    Score anchors
    0
    No modifications to the transition tool interface are required.
    1
    A single new field needs to be introduced to the transition tool interface.
    2
    Multiple new fields or a new mechanism has to be introduced to the transition tool interface.
    3
    Multiple new fields and a new mechanism has to be introduced to the transition tool interface.
    • Special consideration must be paid to this section if the EIP introduces a mechanism that requires the state transition tool to be aware whether the block it is processing is the fork-activation block.

Testing impact

Rework, new invariants, and new primitives required in the test framework.

  • Patterns affecting pre-existing tests
    Implements a new validation mechanism or rule that translates in reworking pre-existing tests
    Score anchors
    0
    No pre-existing tests are affected by this change.
    1
    Minor subset of existing tests are affected by this change.
    2
    Considerable subset of existing tests are affected by this change but involves only a contrived category of tests.
    3
    Major subset of existing tests are affected, including diverse category of tests (benchmarks, static, multiple forks, etc.).
  • New invariant on pre-existing tests · not in checklist revision 1
    Tests that are **not about this EIP** must nonetheless assert something this EIP produces. Their logic does not change; they gain a new thing to check.
    Score anchors
    0
    Pre-existing tests assert nothing new.
    1
    A narrow, contrived category of pre-existing tests gains a new assertion.
    2
    A broad category gains a new assertion, applied mechanically.
    3
    Every test in the fork gains the assertion regardless of what it tests, and pre-fork vectors must be re-derived to satisfy it.
    • Paired with the row above, and easy to confuse with it. "Patterns affecting pre-existing tests" asks whether existing tests must be **reworked**; this row asks whether they must **additionally assert something new**. Score both — an EIP can be low on one and high on the other.
  • New test-framework primitives · not in checklist revision 1
    Requires new abstractions in the test framework itself — expectation types, modifiers, helpers — beyond writing test functions with what already exists.
    Score anchors
    0
    Existing test primitives suffice.
    1
    Existing primitives need minor extension.
    2
    New expectation or modifier primitives are required, reusable within this EIP's own test suite.
    3
    New framework-level primitives are required that become a permanent part of the framework and are used by other EIPs' tests.

Risk and validation

Security, performance, boundary conditions, and cryptography that need validation.

  • Security risks
    Introduces or modifies mechanisms that could compromise the security of the chain, users, validators, or other stakeholders, if not implemented properly.
    Score anchors
    0
    No new mechanisms are introduced that could pose a security risk.
    1
    The introduced mechanisms are self-contained, can be validated in isolation, and do not alter existing invariants that could pose a security risk for any stakeholders.
    2
    The introduced mechanisms interact with a limited number of existing components, slightly altering their security assumptions and requiring a targeted security review or fuzzing.
    3
    The introduced mechanisms interact with multiple existing components, including critical ones, substantially altering their security assumptions and requiring an extensive security review and fuzzing.
  • Performance risks
    Introduces or modifies mechanisms and requires performance validation.
    Score anchors
    0
    No new mechanisms are introduced that require performance validation.
    1
    The introduced mechanisms can be benchmarked in isolation and do not affect existing performance behavior.
    2
    The introduced mechanisms cannot be fully benchmarked in isolation, but they only have a limited impact on the existing performance benchmarks.
    3
    The introduced mechanisms cannot be benchmarked in isolation and have a substantial impact on existing performance benchmarks or have complex interactions with existing mechanisms.
  • Edge/boundary conditions
    Feature contains edge/boundary conditions.
    Score anchors
    0
    No discernible edge cases or boundary conditions are introduced.
    1
    A single edge-case or boundary-condition prone mechanism is introduced.
    2
    Multiple edge-case or boundary-condition prone mechanisms are introduced, but none of them requires an elevated number of cases to test.
    3
    Multiple edge-case or boundary-condition prone mechanisms are introduced and at least one of them requires an elevated number of cases to test.
  • Cryptography
    Introduces new cryptography mechanisms or modifies existing functionality that involves cryptography
    Score anchors
    0
    No cryptography mechanisms are introduced.
    1
    A new cryptography mechanism is introduced but it is a well known mechanism that is known to have vast resources to aid on its testing.
    2
    Multiple new cryptography mechanisms are introduced that are well-known or a single but novel mechanism is introduced that is either untested or has limited resources.
    3
    Multiple new cryptography mechanisms are introduced and at least one of them is a novel mechanism.

Coordination

Cross-EIP interactions and behavior that clients must agree on before tests exist.

  • Cross-EIP interactions
    Introduces or modifies mechanisms that affect other EIPs in either the same or past forks.
    Score anchors
    0
    Fully self-contained EIP that does not depend on, modify, or conflict with any other EIP.
    1
    The EIP interacts with one or more other EIPs in a non-critical and limited way but can be tested independently for the most part.
    2
    The EIP depends on or modifies one or more other EIPs such that coordinated testing and consideration is required, but interactions are limited in scope and not complex.
    3
    The EIP has strong interdependencies with multiple EIPs, requiring extensive coordinated cross-EIP testing as well as potential re-design of existing test vectors.
    • +1 for every 3 additional interacting EIPs beyond the first 3, each of which requires its own coordinated test cases. List the EIPs in the rationale.
    • This row is intentionally uncapped, unlike every other anchor: each interacting EIP is another axis of the test matrix, so a ceiling would make a 12-EIP product indistinguishable from a 3-EIP one.
  • Unspecified behavior requiring cross-client consensus · not in checklist revision 1
    The EIP text does not determine the answer for cases a test can construct. Clients must agree on a previously unspecified detail before tests can be baselined. The cost here is coordination and re-baselining, not test writing.
    Score anchors
    0
    The EIP text determines the answer for every case a test could construct.
    1
    A few details are unspecified but have an obvious intended reading.
    2
    Details require client agreement before tests can be written, but they are localized.
    3
    A previously unspecified *and previously unobservable* behavior becomes consensus-critical; expect tests to be re-baselined on each round of EIP amendment.
    • Score this from the EIP's state at assessment time: whether it has client implementations, whether it has been through a devnet, and how many open questions remain on its discussion thread.