Retrospective LLM-Based Complexity Evaluations

EIP complexity assessment

EIP-8298: SETCODEFROM Code Reuse Instruction

Assessed in Hegotá. The score describes the EIP text available at the snapshot, not the EIP as it stands today.

ProspectiveHegotáSnapshot 2026-10-07EIP-8081: CFILayers: execution
LLM Completescore 34
Human Pending· No STEEL checklist existed on the ethspecs/pm default branch or in any open pull request at the snapshot.

LLM assessment

Evaluated on: · Spec revision: 2026-10-07 · 6dac5e7491 · EIP-8081 list: CFI

Scope at the cutoff. EIP-8298 adds one EVM instruction, SETCODEFROM(source). It sets the current execution-environment account's codeHash to the codeHash of a live source account. The source must exist, have non-empty code, not start with 0xEF, and not have been created in the current transaction. The instruction is allowed in deployed code (including EIP-7702 delegated execution) and in initcode. When initcode adopts code this way, contract-creation completion skips return-data validation, installation and all code-deposit gas, both execution and state. The opcode charges tiered execution gas from EIP-8038 parameters and no state gas. It extends the EIP-7928 BAL CodeChange with an optional trailing new_code_hash element for adopted code. It also states non-consensus public-mempool rules for EIP-8141 frame transactions, and relies on EIP-3607 and EIP-7702 to permanently disable ECDSA origination for migrated EOAs.

34HighHigh
Evaluator
LLMChecklist v3
Confidence
Medium
Under-specified at assessment cutoff
Yes — 6 criteria affected
Plausible range
30–36 (High)
Snapshot
2026-10-07 · EIP revision 6dac5e7491 (2026-10-07)
Score bands · Checklist revision 3
  • Low <12
  • Medium 12–22
  • High ≥23

28 criteria scored 0–3 (4 in exceptional cases; cross-EIP interactions is uncapped); nominal maximum 84.

Complexity profile

Each segment is one criterion's contribution to the LLM total. Hover or focus a segment for its score and rationale.

Top complexity drivers

  1. Cross-EIP interactions4
  2. Modified opcodes3
  3. Encoding changes (RLP/SSZ)3
  4. Security risks3

Under-specified at assessment cutoff: Yes

The EIP text available at the assessment cutoff left material behavior unresolved. The affected criteria and the plausible total range record that uncertainty.

Why: Several localized details are open. Source validity is open-ended ('valid regular deployed code under the active fork, e.g.'). BAL recording is undefined when an adopted code hash nets back to its pre-transaction value. SETCODEFROM is not mapped onto EIP-7928's pre-state/post-state BAL inclusion rules. The EIP-8279 metering size for adoption entries is not given. How BAL decoding and validation map onto block-import structural checks is only implied.

Unresolved questions at the cutoff (5)
  • Beyond the 0xEF prefix, what makes source code 'valid regular deployed code under the active fork' (e.g., legacy code exceeding a current size limit)?
  • If an account adopts a hash and then later adopts back its pre-transaction hash, is a CodeChange recorded?
  • If gas covers the cold source access but not the extra WARM_ACCESS for code validation, is the source included in the BAL?
  • Is the static-context halt checked before or after gas and state access, which affects BAL inclusion of the source?
  • How many BAL bytes should EIP-8279 meter for an adoption entry?
Notable ambiguities noted by the assessor (5)
  • SETCODEFROM_OPCODE byte is TBD.
  • 'e.g.' in the source-validity rule leaves additional code-validity conditions undefined.
  • BAL net no-op code-hash changes are not addressed.
  • The Test Cases section is a TODO.
  • The Public Mempool rules use 'should', and their non-consensus status relative to EIP-8141 is stated but not tested as consensus.

Criterion breakdown

EIP-8298 Hegotá: LLM criterion scores and rationale
CriterionScoreWhy this scoreEvidence / uncertainty
Cross-EIP interactionsExceptional4The target couples behavior from EIP-7702, 3607, 6780, 7928, 8037 and 3541. Coordinated scenarios are needed across them, e.g. delegate execution → SETCODEFROM → later tx rejected and authorization rejected, with the BAL hash-form recorded and state-gas accounting checked for adopted creations.
  • eip.md · SETCODEFROM Under EIP-7702 delegated execution, the authority account is updated. Sources with an EIP-3541/7702 0xEF prefix are invalid. The created-in-tx test is defined via EIP-6780.
  • eip.md · Block-Level Access Lists Extends the EIP-7928 CodeChange.
  • eip.md · Contract Creation EIP-8037 account-creation state gas still applies, while code-deposit state and execution gas are skipped.
  • eip.md · ECDSA Transaction Origination EIP-3607 rejection and EIP-7702 redelegation failure after adoption.
Confidence: Medium
Interacting EIPs: EIP-7702, EIP-3607, EIP-6780, EIP-7928, EIP-8037, EIP-8038, EIP-3541, EIP-8141, EIP-8151, EIP-8279
Modified opcodes3The completion semantics of CREATE/CREATE2 change: a new code-installation rule, and return data that would fail validation (oversize or 0xEF prefix) no longer causes failure after adoption.
  • eip.md · Contract Creation For CREATE/CREATE2 and creation transactions, when codeHash was adopted the initcode's return data 'is not validated, hashed, installed, or charged code-deposit gas'. This changes the creation-completion semantics of existing instructions.
  • eip.md · Contract Creation EXTCODESIZE/EXTCODEHASH/EXTCODECOPY and calls targeting the account under construction now see the adopted code.
Confidence: Medium
Uncertainty: These changes are only reachable after SETCODEFROM executes. One could argue they belong to the new opcode, but CREATE's specified completion rule is altered.
Encoding changes (RLP/SSZ)3The RLP schema of an EL block-level object, the BAL's CodeChange, changes.
  • eip.md · Block-Level Access Lists CodeChange gains an optional trailing Hash32 element: [block_access_index, b"", new_code_hash].
  • supporting/eip-7928.md · RLP Data Structures The baseline CodeChange is [BlockAccessIndex, Bytecode].
Confidence: High
Security risks3The shared invariant that deployed code is immutable (apart from creation, delegation, and same-tx SELFDESTRUCT) changes. This affects the EVM, BAL completeness and executionless consumers, code-database availability, transaction-origination authority (EIP-3607/7702), and mempool validation (EIP-8141). Coordinated adversarial scenarios are needed, for example transitive adoption chains and re-entrancy into accounts under construction.
  • eip.md · Security Considerations Changes account-code identity semantics: any account's code, including under delegated execution, may be replaced. The EIP notes the codehash-presentation risk and the conflict with mempool immutability assumptions.
  • eip.md · Rationale Rejecting sources created in the same tx is needed so that every adopted hash resolves to bytecode in the pre-state or the BAL. The gap would otherwise be transitive.
  • eip.md · ECDSA Transaction Origination Permanently disables ECDSA origination and EIP-7702 redelegation for migrated EOAs.
  • supporting/eip-7702.md · Delegation of code execution only Notes that contracts rely on codehash as a definition of account behavior, and code changes were previously limited.
Confidence: Medium
Edge/boundary conditions3Several boundary-sensitive mechanisms are introduced: source validity, tiered gas, the creation-completion branch, and BAL form selection. The gas outcome is an elevated matrix of interacting dimensions (cold/warm × validity × hash equality, plus out-of-gas at each tier). The creation path interacts adoption × return-data validity (oversize or 0xEF) × new/existing destination × revert/halt.
  • eip.md · SETCODEFROM Source validity has four conditions: exists, non-empty code, no 0xEF prefix, not created in the current tx. Static context halts.
  • eip.md · Gas Costs Cost outcomes depend on cold/warm source × invalid/same-hash/different-hash.
  • eip.md · Contract Creation Creation completion branches on whether codeHash was adopted. Return data is ignored (no size or 0xEF checks) when code is adopted, and account-creation charges depend on whether the destination exists.
  • eip.md · Block-Level Access Lists The choice between three-element and two-element form depends on whether the end-of-tx value was set by SETCODEFROM.
Confidence: Medium
Added opcodes2Exactly one instruction is added. It is complex because its gas is not constant.
  • eip.md · SETCODEFROM One instruction: takes one stack item, pushes success, has no immediates.
  • eip.md · Gas Costs Gas is dynamic (cold/warm and conditional tiers).
Confidence: High
EVM Gas rule changes2The new instruction brings its own conditional, multi-stage charging rule, and adopted creations get a new code-deposit exemption. Without SETCODEFROM, baseline operations keep their expected gas results. This matches level 2: a new mechanism without changing baseline expectations.
  • eip.md · Gas Costs Adds a tiered charging scheme: SETCODEFROM_SOURCE_GAS on every attempt, then WARM_ACCESS only if the source is valid, then ACCOUNT_WRITE only if the hashes differ. This gives six cost outcomes (3100/200/3200/300/12200/9300).
  • eip.md · Contract Creation When code is adopted, contract creation charges no code-deposit execution gas (hash cost). Baseline creations, where codeHash is empty, are unchanged.
  • supporting/eip-8038.md · Parameters Defines the COLD_ACCOUNT_ACCESS, WARM_ACCESS and ACCOUNT_WRITE values that the new schedule reuses.
Confidence: Medium
Uncertainty: It is arguable whether a new opcode's schedule built from existing parameters counts as a 'new accounting mechanism'. The conditional tiers and the creation exemption support level 2.
State-access ordering within opcode executionUnder-specified2This is a new state-accessing operation (it reads the source account and its code, and writes the current account's codeHash). It needs its own ordering rule for gas charges against accesses and for BAL inclusion, covering cold/warm source, valid/invalid source, same/different hash, and static/non-static context. It does not change ordering for an existing opcode class, so level 2.
  • eip.md · Gas Costs Sets an order: source account load, then source code-store inspection, then (if valid) the current-account access charged 'before comparing', then ACCOUNT_WRITE charged 'before updating'.
  • supporting/eip-7928.md · Gas Validation Before State Access Pre-state and post-state validation rules decide BAL inclusion for state-accessing opcodes. SETCODEFROM is not in that table.
Confidence: Medium
Uncertainty: The EIP does not map SETCODEFROM onto EIP-7928's pre-state/post-state table. It is unclear whether a cold source enters the BAL when gas covers the account access but not the extra WARM_ACCESS for code validation.
State gas accounting changesUnder-specified2The EIP adds a conditional exemption to the EIP-8037 code-deposit state-gas charge at the creation site, keyed on whether the created account adopted code. It interacts with the account-creation charge and with refill on revert. It is not just a parameter change, and it adds no new state-gas mechanism or spill change. Level 2 is the closest fit (a changed charging condition at a site, using the existing mechanism).
  • eip.md · Contract Creation With adopted code, 'no code-deposit state gas or code-deposit execution gas is charged'. The account-creation state gas still applies for a new leaf.
  • eip.md · Gas Costs SETCODEFROM_STATE_GAS is 0, and nothing depends on source code size.
  • supporting/eip-8037.md · Gas accounting for new accounts In the baseline, CREATE/CREATE2 is charged L × CPSB code-deposit state gas, plus the new-account charge when the destination is non-existent.
Confidence: Medium
Uncertainty: This could be read as level 1, because no new charging site is added; the existing one is conditionally zeroed.
Block syncing changesUnder-specified2Block import must decode and validate the changed CodeChange structure: optional trailing hash, empty bytecode in the hash form, 32-byte hash. These are multiple simple structural rules. Choosing the correct form is decided by comparison with the executed BAL.
  • eip.md · Block-Level Access Lists 'A BAL that records a code change in any other way is invalid.' The CodeChange decoder must accept an optional third element, with empty bytecode, for adoption entries.
  • eip.md · Backwards Compatibility A client implementing only EIP-7928 rejects blocks that use the new form, and vice versa.
  • supporting/eip-7928.md · State Transition Function The BAL is validated against execution during block processing, and a mismatch invalidates the block.
Confidence: Low
Uncertainty: The BAL is carried in the payload rather than the block body, and form selection depends on execution. Whether these count as structural block validation (and whether any are 'complex') is debatable.
Performance risks2Targeted benchmarks are needed for a bounded interaction. The cases are: repeated cold or warm SETCODEFROM with code-store inspection priced at 100 gas regardless of code size; cheap mass adoption of maximum-size code; and code-database retention or reference handling for hashes referenced only through adoption.
  • eip.md · Gas Costs Validating source code is a fixed WARM_ACCESS charge for a code-store access, and 'the gas cost is not affected by source code size'.
  • eip.md · Rationale Bytecode deposited by a source must stay persisted for adopters, even if the source later replaces its own code in the same block.
  • eip.md · Contract Creation Creation with adopted code avoids code-deposit cost entirely, so many accounts can share large code cheaply.
Confidence: Medium
Uncertainty: The code-store read cost depends on whether clients load full code or only the prefix. No benchmark evidence was supplied.
Unspecified behavior requiring cross-client consensus2Several localized outcomes have competing readings. These are: what makes source code 'valid regular deployed code' beyond the 0xEF prefix; whether a codeHash that returns to its pre-tx value creates a CodeChange entry; and BAL inclusion of the source when out of gas between access and code validation. Agreement is needed before fixed expected results can be written.
  • eip.md · SETCODEFROM Requires that 'source.code is valid regular deployed code under the active fork, e.g. it does not start with 0xEF'. The 'e.g.' leaves any other validity conditions open.
  • eip.md · Block-Level Access Lists 'If an account's code hash changes in a transaction and its value at the end of the transaction was set by SETCODEFROM...' It does not say how a net no-op is recorded, e.g. adopting and then re-adopting the original hash.
  • eip.md · Gas Costs SETCODEFROM_SOURCE_GAS is charged per attempt with no pre-state/post-state split for BAL inclusion, unlike the EIP-7928 table.
Confidence: Medium
Uncertainty: The surrounding EIP-7928 rules on no-op writes and pre-state checks may imply defaults, but the target does not state them.
Engine API changesUnder-specified1The contents of the existing blockAccessList field change meaning or format. That is one field change, with no new method or exchange behavior.
  • supporting/eip-7928.md · Engine API ExecutionPayloadV4.blockAccessList carries the RLP-encoded BAL.
  • eip.md · Block-Level Access Lists Changes the CodeChange schema inside that BAL.
Confidence: Low
Uncertainty: The field is opaque RLP bytes, so this could also be seen as no Engine API change.
Transition-tool interface changesUnder-specified1If the transition tool emits or consumes BALs, the code_changes entry gains one optional field (new_code_hash). That is one field changed, with no new mechanism.
  • eip.md · Block-Level Access Lists CodeChange = [BlockAccessIndex, Bytecode, Optional[Hash32]]: one semantic change to the BAL code-change record.
  • supporting/eip-7928.md · RLP Data Structures Defines the baseline BAL schema that a transition tool producing BALs would emit.
Confidence: Low
Uncertainty: No transition-tool documentation was supplied. Whether the tool carries the BAL is assumed from the Amsterdam baseline.
Patterns affecting pre-existing tests1The only baseline rework is in undefined/invalid-opcode tests that use the newly allocated byte, a localized case within one family. Creation and BAL baselines are preserved by design.
  • eip.md · Parameters SETCODEFROM_OPCODE is TBD. A previously undefined byte becomes a defined instruction.
  • eip.md · Contract Creation The creation-completion rule branches on the created account's codeHash. Without SETCODEFROM the codeHash stays EMPTYCODEHASH, so baseline creation tests are unaffected.
  • eip.md · Block-Level Access Lists Code changes other than adoptions keep the two-element form, so baseline BAL expectations stay valid.
Confidence: Medium
Uncertainty: The opcode byte is TBD, so which invalid-opcode tests are affected is unknown.
New test-framework primitives1The existing BAL expectation primitive needs a local extension for the hash-form CodeChange, and account expectations need adopted-code checks. No new shared abstraction is required.
  • eip.md · Block-Level Access Lists BAL expectations must express [index, b"", code_hash] entries in addition to bytecode entries.
  • eip.md · Deployed Code Execution Tests must check code identity by hash, shared across accounts.
Confidence: Medium
Show 12 zero-score criteria
Zero-score criteria (Checklist revision 3)
CriterionScoreWhy this scoreEvidence / uncertainty
Added precompiles0None.
  • eip.md · Specification No precompile is introduced.
Modified precompiles0No precompile change is required by the target.
  • eip.md · Security Considerations Mentions EIP-8151 as an optional companion ecRecover change. The target does not modify any precompile.
Added system contracts0None introduced.
  • eip.md · Specification No protocol-designated contract is introduced. Templates are ordinary contracts.
Modified system contracts0No system contract rules change.
  • eip.md · Specification No system contract is referenced or modified.
Blob gas accounting changes0No blob-gas rule is touched.
  • eip.md · Gas Costs Only execution gas and (zero) state gas are discussed. Blobs are not mentioned.
New EVM gas refund0No refund mechanism is introduced.
  • eip.md · Gas Costs No refund is defined. Invalid or same-hash cases simply skip later charges.
New transaction types0None.
  • eip.md · Specification No transaction envelope is introduced.
New or modified transaction validity mechanismsUnder-specified0No consensus validity or intrinsic-gas rule is changed. Existing EIP-3607 and EIP-7702 rules apply to newly reachable states, and that is tested as a cross-EIP interaction.
  • eip.md · ECDSA Transaction Origination ECDSA transactions from accounts that adopted code become invalid under the existing EIP-3607 rule. EIP-7702 redelegation fails under the existing authority check.
  • supporting/eip-3607.md · Specification Existing rule rejecting senders whose codeHash is not EMPTYCODEHASH.
Uncertainty: Testing that a sender is rejected after an in-block code adoption could be seen as validity-test work (level 1).
New block / header fields0No new header field.
  • eip.md · Block-Level Access Lists Only the BAL contents change. No header member is added.
New fork activation mechanism0No activation-specific state transition.
  • eip.md · Backwards Compatibility Only rule activation is required. There is no state migration or installation.
New invariant on pre-existing tests0Baseline tests need no new assertion.
  • eip.md · Block-Level Access Lists The new three-element CodeChange form appears only for SETCODEFROM-adopted code. Baseline tests produce no new output.
Cryptography0Code hashes are copied and compared, not computed under new rules.
  • eip.md · SETCODEFROM The instruction copies an existing codeHash. No hashing, signing or verification rule is added or changed.
Assessment provenance
Assessed EIP revision
ethereum/EIPs@6dac5e7491 EIPS/eip-8298.md committed 2026-10-07 · information cutoff 2026-10-07T22:23:55Z
Current master · File history · blob 7608d692a0 · sha256 5d9f63b6ebdc
Rubric
Checklist revision 3 · ethspecs/pm@fe2f793b03
Evaluator
Opus 5.5 (claude-opus-5-5) at high effort, one tool-less call per EIP · isolation bubblewrap_claude_p_no_tools_v1
Source record
Frozen research record research/tasks/10-opus-v3-reassessment/prospective/outputs/assessments/hegota-2026-10-08/eip-8298.yaml · sha256 1cec80efaf14
Supporting documents supplied with the EIP
supporting/eip-20.md, supporting/eip-3541.md, supporting/eip-3607.md, supporting/eip-6780.md, supporting/eip-6913.md, supporting/eip-7702.md, supporting/eip-7928.md, supporting/eip-8037.md, supporting/eip-8038.md, supporting/eip-8141.md, supporting/eip-8151.md, supporting/eip-8279.md
Criterion legend and glossary

Every stacked bar, comparison matrix, and criterion table on this site uses the same criterion colours, abbreviations, and order. Colour marks the criterion group; the abbreviation and name identify the criterion. Scores are 0–3 per criterion (4 is exceptional; cross-EIP interactions is uncapped).

EVM surface

Opcodes, precompiles, and system contracts that are added or modified.

  • Added opcodes
    Introduces new opcodes
    Score anchors
    0
    No new opcodes are introduced.
    1
    A new simple opcode is introduced (no data portion, no complex stack mechanics, and a constant gas cost).
    2
    Multiple new simple opcodes are introduced, or a single new complex opcode is introduced (has data portion, or complex stack mechanics, or a dynamic gas cost).
    3
    Multiple new opcodes are introduced, and at least one of them is complex (has data portion, or complex stack mechanics, or a dynamic gas cost).
    • Cryptography opcodes are not considered complex by default. Refer to the "Cryptography" section for a separate assessment.
  • Modified opcodes
    Modifies pre-existing opcodes
    Score anchors
    0
    No pre-existing opcode modifications are introduced.
    3
    At least one pre-existing opcode's behavior is modified (not including gas changes) or a pre-existing opcode is deprecated.
  • Added precompiles
    Introduces new precompiles
    Score anchors
    0
    No new precompiles are introduced.
    1
    A new simple precompile is introduced (constant input length, constant gas cost).
    2
    Multiple new simple precompiles are introduced, or a single new complex precompile is introduced (dynamic input length or dynamic gas cost).
    3
    Multiple new precompiles are introduced, and at least one of them is complex (dynamic input length or dynamic gas cost).
    • Cryptography precompiles are not considered complex by default. Refer to the "Cryptography" for a separate assessment.
  • Modified precompiles
    Modifies pre-existing precompiles logic or gas-accounting
    Score anchors
    0
    No pre-existing precompiles are modified.
    1
    At least one pre-existing precompile has its gas schedule modified.
    2
    Multiple pre-existing precompiles have their gas schedule modified, or a single pre-existing precompile has its behavior modified.
    3
    The behavior of multiple pre-existing precompiles, or a single complex pre-existing precompile modified.
  • Added system contracts
    Introduces new system contract, stateful or not
    Score anchors
    0
    No new system contracts are introduced.
    1
    A new system contract is introduced that is not stateful nor does it trigger a new system action (e.g. requests to the consensus layer).
    2
    Multiple new system contracts are introduced or a single new system contract that is either stateful or triggers a new system action (e.g. requests to the consensus layer).
    3
    Multiple new system contracts are introduced and at least one of them is either stateful or triggers a new system action (e.g. requests to the consensus layer).
  • Modified system contracts
    Modifies pre-existing system contracts
    Score anchors
    0
    No modifications to pre-existing system contracts are introduced, directly or indirectly.
    1
    Does not directly modify any system contract, but its behavior has minor indirect effects on one or more system contracts.
    2
    Does not directly modify any system contract, but its behavior has major indirect effects on one or more system contracts.
    3
    At least one pre-existing system contract code or state is modified, which would involve irregular state transition or a similarly complex transition methodology.

Gas and accounting

Execution, blob, and state gas rules, refunds, and where charges happen inside opcodes.

  • EVM Gas rule changes
    New EVM gas accounting rules
    Score anchors
    0
    No gas accounting changes.
    1
    Existing gas accounting mechanism is updated.
    2
    A new gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State-access ordering within opcode execution · not in checklist revision 1
    Changes *where inside an opcode's execution* state is accessed, or where gas is charged relative to that access. Because a state access is recorded in the block-level access list only if execution had enough gas to reach it, this ordering is consensus-critical: moving it changes the BAL at every gas boundary of every affected opcode.
    Score anchors
    0
    No change to where state is accessed, or to where gas is charged relative to a state access, within any opcode.
    1
    A single opcode's state-access or gas-charge ordering changes.
    2
    Multiple opcodes' ordering changes, or a new state-accessing operation is introduced whose position in the order must be settled.
    3
    The ordering rule changes for a whole class of state-accessing opcodes at once, or what counts as a recordable state access is redefined — requiring existing BAL vectors to be re-derived across opcodes and forks.
    • Distinct from "Modified opcodes", which asks whether an opcode's **result** changed. This row asks about the **path to the result**, which is observable even when the result is identical. An EIP can be 0 on that row and 3 on this one.
    • Score changes **to** the ordering. Do not score the fact that state accesses are observable — they always are.
    • Each boundary must be re-tested against every other dimension that can change the answer (cold/warm, static/non-static, delegated/direct, revert/success), so the case count grows multiplicatively rather than additively. Note this explicitly under Special Considerations.
  • Blob gas accounting changes
    New Blob gas accounting rules which potentially affect pre-existing tests
    Score anchors
    0
    No blob gas accounting changes.
    1
    Existing blob gas accounting mechanism is updated.
    2
    A new blob gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests.
    3
    A new blob gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests.
  • State gas accounting changes · not in checklist revision 1
    New state gas accounting rules. State gas is the cost of *writing* state, as opposed to accessing or executing it: `StateGasCosts`, `COST_PER_STATE_BYTE`, the block-level state gas budget, and the spill path into execution gas.
    Score anchors
    0
    No state gas accounting changes.
    1
    An existing state gas cost or `STATE_BYTES_PER_*` rate is adjusted.
    2
    A new state-gas-charging site is introduced, or the block-level state gas budget or reservoir allocation is modified.
    3
    A new state gas charging mechanism is introduced, or the spill interaction between state gas and execution gas is modified, affecting existing gas tests.
    • Harder to test than blob gas: the spill path means state gas cannot be metered independently of execution gas, and some costs (e.g. `NEW_ACCOUNT`) are state-dependent.
  • New EVM gas refund
    New gas-refund mechanism
    Score anchors
    0
    No new gas-refund mechanisms are introduced.
    1
    A new simple gas-refund mechanism is introduced that does not affect either existing tests or existing gas-refund mechanisms.
    2
    A new complex gas-refund mechanism is introduced or a simple mechanism that affects existing tests or existing gas-refund mechanisms.
    3
    A new complex gas-refund mechanism is introduced that affects existing tests or existing gas-refund mechanisms.

Blocks, transactions, and encoding

Transaction types and validity, block and header fields, encodings, syncing, and activation-time changes.

  • New transaction types
    Introduces a new transaction type
    Score anchors
    0
    No new transaction types are introduced.
    3
    A new transaction type is introduced.
  • New or modified transaction validity mechanisms
    Creates new or modifies pre-existing transaction types' validation mechanisms
    Score anchors
    0
    No changes are introduced to the validity rules of existing transaction types or to their intrinsic gas cost calculation.
    1
    Minor adjustments are introduced to validity rules or intrinsic gas cost calculation, but they do not significantly affect existing tests.
    2
    Changes to validity rules or intrinsic gas cost calculation affect existing tests, but require only limited updates to test cases and no redesign of the testing infrastructure.
    3
    Changes to validity rules or intrinsic gas cost calculation require extensive rework or redesign of the tests or testing infrastructure.
  • New block / header fields
    Introduces new block or block header fields
    Score anchors
    0
    No new block or header fields are introduced.
    3
    A new block or header field is introduced.
  • Encoding changes (RLP/SSZ)
    Introduces encoding changes at the transaction/block/interfaces level
    Score anchors
    0
    No encoding changes are introduced at the transaction, block, or interfaces levels.
    3
    An encoding change is introduced at transaction, block or interfaces level (e.g. RLP -> SSZ).
    • "Interfaces level" includes the Engine API. Score an Engine API encoding change (e.g. JSON -> SSZ) here.
  • Block syncing changes
    Modifies block RLP validation mechanisms that require test client syncing.
    Score anchors
    0
    No new RLP validation mechanism is introduced.
    1
    A single simple RLP validation mechanism is introduced.
    2
    Multiple simple RLP validation mechanisms are introduced or a single complex one.
    3
    Multiple RLP validation mechanisms are introduced and at least one of them is deemed complex.
  • New fork activation mechanism
    Modifies state, internal variables, or similar, at the fork activation block
    Score anchors
    0
    No state modifications, internal variables or similar are modified at the fork activation block.
    3
    Either a state modification or internal variables are modified at the fork activation block.
    • Initialization of new internal variable is not considered a modification.

Client interfaces

Engine API and transition-tool interface changes.

  • Engine API changes
    Introduces new fields to the Engine API directives
    Score anchors
    0
    No new fields or communication mechanisms are introduced to the Engine API.
    1
    A single new field is introduced in one of the Engine API endpoints.
    2
    Multiple fields are introduced to one or multiple Engine API end points, or a new Engine API end-point is introduced.
    3
    Multiple fields are introduced to one or multiple Engine API end points and a new Engine API end-point is introduced.
  • Engine API encoding changes · Checklist revision 1 only
    Engine API encoding changes (the revision-1 template defines no anchor text for this row).
  • Transition-tool interface changes
    Modifies or adds new fields to the transition tool interface.
    Score anchors
    0
    No modifications to the transition tool interface are required.
    1
    A single new field needs to be introduced to the transition tool interface.
    2
    Multiple new fields or a new mechanism has to be introduced to the transition tool interface.
    3
    Multiple new fields and a new mechanism has to be introduced to the transition tool interface.
    • Special consideration must be paid to this section if the EIP introduces a mechanism that requires the state transition tool to be aware whether the block it is processing is the fork-activation block.

Testing impact

Rework, new invariants, and new primitives required in the test framework.

  • Patterns affecting pre-existing tests
    Implements a new validation mechanism or rule that translates in reworking pre-existing tests
    Score anchors
    0
    No pre-existing tests are affected by this change.
    1
    Minor subset of existing tests are affected by this change.
    2
    Considerable subset of existing tests are affected by this change but involves only a contrived category of tests.
    3
    Major subset of existing tests are affected, including diverse category of tests (benchmarks, static, multiple forks, etc.).
  • New invariant on pre-existing tests · not in checklist revision 1
    Tests that are **not about this EIP** must nonetheless assert something this EIP produces. Their logic does not change; they gain a new thing to check.
    Score anchors
    0
    Pre-existing tests assert nothing new.
    1
    A narrow, contrived category of pre-existing tests gains a new assertion.
    2
    A broad category gains a new assertion, applied mechanically.
    3
    Every test in the fork gains the assertion regardless of what it tests, and pre-fork vectors must be re-derived to satisfy it.
    • Paired with the row above, and easy to confuse with it. "Patterns affecting pre-existing tests" asks whether existing tests must be **reworked**; this row asks whether they must **additionally assert something new**. Score both — an EIP can be low on one and high on the other.
  • New test-framework primitives · not in checklist revision 1
    Requires new abstractions in the test framework itself — expectation types, modifiers, helpers — beyond writing test functions with what already exists.
    Score anchors
    0
    Existing test primitives suffice.
    1
    Existing primitives need minor extension.
    2
    New expectation or modifier primitives are required, reusable within this EIP's own test suite.
    3
    New framework-level primitives are required that become a permanent part of the framework and are used by other EIPs' tests.

Risk and validation

Security, performance, boundary conditions, and cryptography that need validation.

  • Security risks
    Introduces or modifies mechanisms that could compromise the security of the chain, users, validators, or other stakeholders, if not implemented properly.
    Score anchors
    0
    No new mechanisms are introduced that could pose a security risk.
    1
    The introduced mechanisms are self-contained, can be validated in isolation, and do not alter existing invariants that could pose a security risk for any stakeholders.
    2
    The introduced mechanisms interact with a limited number of existing components, slightly altering their security assumptions and requiring a targeted security review or fuzzing.
    3
    The introduced mechanisms interact with multiple existing components, including critical ones, substantially altering their security assumptions and requiring an extensive security review and fuzzing.
  • Performance risks
    Introduces or modifies mechanisms and requires performance validation.
    Score anchors
    0
    No new mechanisms are introduced that require performance validation.
    1
    The introduced mechanisms can be benchmarked in isolation and do not affect existing performance behavior.
    2
    The introduced mechanisms cannot be fully benchmarked in isolation, but they only have a limited impact on the existing performance benchmarks.
    3
    The introduced mechanisms cannot be benchmarked in isolation and have a substantial impact on existing performance benchmarks or have complex interactions with existing mechanisms.
  • Edge/boundary conditions
    Feature contains edge/boundary conditions.
    Score anchors
    0
    No discernible edge cases or boundary conditions are introduced.
    1
    A single edge-case or boundary-condition prone mechanism is introduced.
    2
    Multiple edge-case or boundary-condition prone mechanisms are introduced, but none of them requires an elevated number of cases to test.
    3
    Multiple edge-case or boundary-condition prone mechanisms are introduced and at least one of them requires an elevated number of cases to test.
  • Cryptography
    Introduces new cryptography mechanisms or modifies existing functionality that involves cryptography
    Score anchors
    0
    No cryptography mechanisms are introduced.
    1
    A new cryptography mechanism is introduced but it is a well known mechanism that is known to have vast resources to aid on its testing.
    2
    Multiple new cryptography mechanisms are introduced that are well-known or a single but novel mechanism is introduced that is either untested or has limited resources.
    3
    Multiple new cryptography mechanisms are introduced and at least one of them is a novel mechanism.

Coordination

Cross-EIP interactions and behavior that clients must agree on before tests exist.

  • Cross-EIP interactions
    Introduces or modifies mechanisms that affect other EIPs in either the same or past forks.
    Score anchors
    0
    Fully self-contained EIP that does not depend on, modify, or conflict with any other EIP.
    1
    The EIP interacts with one or more other EIPs in a non-critical and limited way but can be tested independently for the most part.
    2
    The EIP depends on or modifies one or more other EIPs such that coordinated testing and consideration is required, but interactions are limited in scope and not complex.
    3
    The EIP has strong interdependencies with multiple EIPs, requiring extensive coordinated cross-EIP testing as well as potential re-design of existing test vectors.
    • +1 for every 3 additional interacting EIPs beyond the first 3, each of which requires its own coordinated test cases. List the EIPs in the rationale.
    • This row is intentionally uncapped, unlike every other anchor: each interacting EIP is another axis of the test matrix, so a ceiling would make a 12-EIP product indistinguishable from a 3-EIP one.
  • Unspecified behavior requiring cross-client consensus · not in checklist revision 1
    The EIP text does not determine the answer for cases a test can construct. Clients must agree on a previously unspecified detail before tests can be baselined. The cost here is coordination and re-baselining, not test writing.
    Score anchors
    0
    The EIP text determines the answer for every case a test could construct.
    1
    A few details are unspecified but have an obvious intended reading.
    2
    Details require client agreement before tests can be written, but they are localized.
    3
    A previously unspecified *and previously unobservable* behavior becomes consensus-critical; expect tests to be re-baselined on each round of EIP amendment.
    • Score this from the EIP's state at assessment time: whether it has client implementations, whether it has been through a devnet, and how many open questions remain on its discussion thread.