diff --git a/complexity_assessments/EIPs/EIP-7645.md b/complexity_assessments/EIPs/EIP-7645.md new file mode 100644 index 0000000..3e6403a --- /dev/null +++ b/complexity_assessments/EIPs/EIP-7645.md @@ -0,0 +1,424 @@ +# EIP-7645: Alias ORIGIN to SENDER + +Checklist revision: **2** (28 anchors) — see [Revision Notes](#revision-notes) + +Link: https://github.com/ethereum/EIPs/blob/fe5cd0aef497f6a5cfe704d2788dd94b6e488936/EIPS/eip-7645.md + +## Execution Specs + +### Specs + +TBD + +### Testing + +#### Anchors + +All anchors are scored on a 0–3 scale. A score of 4 may be used in exceptional circumstances where the complexity or impact exceeds the defined anchors. + +##### EVM Gas rule changes + +New EVM gas accounting rules +- 0. No gas accounting changes. +- 1. Existing gas accounting mechanism is updated. +- 2. A new gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests. +- 3. A new gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests. + +##### State-access ordering within opcode execution + +Changes *where inside an opcode's execution* state is accessed, or where gas is charged relative to that access. Because a state access is recorded in the block-level access list only if execution had enough gas to reach it, this ordering is consensus-critical: moving it changes the BAL at every gas boundary of every affected opcode. + +- 0. No change to where state is accessed, or to where gas is charged relative to a state access, within any opcode. +- 1. A single opcode's state-access or gas-charge ordering changes. +- 2. Multiple opcodes' ordering changes, or a new state-accessing operation is introduced whose position in the order must be settled. +- 3. The ordering rule changes for a whole class of state-accessing opcodes at once, or what counts as a recordable state access is redefined — requiring existing BAL vectors to be re-derived across opcodes and forks. + +*Distinct from "Modified opcodes", which asks whether an opcode's **result** changed. This row asks about the **path to the result**, which is observable even when the result is identical. An EIP can be 0 on that row and 3 on this one. + +*Score changes **to** the ordering. Do not score the fact that state accesses are observable — they always are. + +*Each boundary must be re-tested against every other dimension that can change the answer (cold/warm, static/non-static, delegated/direct, revert/success), so the case count grows multiplicatively rather than additively. Note this explicitly under Special Considerations. + +##### Blob gas accounting changes + +New Blob gas accounting rules which potentially affect pre-existing tests + +- 0. No blob gas accounting changes. +- 1. Existing blob gas accounting mechanism is updated. +- 2. A new blob gas accounting mechanism is introduced but it does not affect existing mechanisms nor does it affect existing tests. +- 3. A new blob gas accounting mechanism is introduced and affects existing mechanisms which in turn affect existing tests. + +##### State gas accounting changes + +New state gas accounting rules. State gas is the cost of *writing* state, as opposed to accessing or executing it: `StateGasCosts`, `COST_PER_STATE_BYTE`, the block-level state gas budget, and the spill path into execution gas. + +- 0. No state gas accounting changes. +- 1. An existing state gas cost or `STATE_BYTES_PER_*` rate is adjusted. +- 2. A new state-gas-charging site is introduced, or the block-level state gas budget or reservoir allocation is modified. +- 3. A new state gas charging mechanism is introduced, or the spill interaction between state gas and execution gas is modified, affecting existing gas tests. + +*Harder to test than blob gas: the spill path means state gas cannot be metered independently of execution gas, and some costs (e.g. `NEW_ACCOUNT`) are state-dependent. + +##### New EVM gas refund + +New gas-refund mechanism + +- 0. No new gas-refund mechanisms are introduced. +- 1. A new simple gas-refund mechanism is introduced that does not affect either existing tests or existing gas-refund mechanisms. +- 2. A new complex gas-refund mechanism is introduced or a simple mechanism that affects existing tests or existing gas-refund mechanisms. +- 3. A new complex gas-refund mechanism is introduced that affects existing tests or existing gas-refund mechanisms. + +##### Patterns affecting pre-existing tests + +Implements a new validation mechanism or rule that translates in reworking pre-existing tests + +- 0. No pre-existing tests are affected by this change. +- 1. Minor subset of existing tests are affected by this change. +- 2. Considerable subset of existing tests are affected by this change but involves only a contrived category of tests. +- 3. Major subset of existing tests are affected, including diverse category of tests (benchmarks, static, multiple forks, etc.). + +##### New invariant on pre-existing tests + +Tests that are **not about this EIP** must nonetheless assert something this EIP produces. Their logic does not change; they gain a new thing to check. + +- 0. Pre-existing tests assert nothing new. +- 1. A narrow, contrived category of pre-existing tests gains a new assertion. +- 2. A broad category gains a new assertion, applied mechanically. +- 3. Every test in the fork gains the assertion regardless of what it tests, and pre-fork vectors must be re-derived to satisfy it. + +*Paired with the row above, and easy to confuse with it. "Patterns affecting pre-existing tests" asks whether existing tests must be **reworked**; this row asks whether they must **additionally assert something new**. Score both — an EIP can be low on one and high on the other. + +##### Transition-tool interface changes + +Modifies or adds new fields to the transition tool interface. + +- 0. No modifications to the transition tool interface are required. +- 1. A single new field needs to be introduced to the transition tool interface. +- 2. Multiple new fields or a new mechanism has to be introduced to the transition tool interface. +- 3. Multiple new fields and a new mechanism has to be introduced to the transition tool interface. + +*Special consideration must be paid to this section if the EIP introduces a mechanism that requires the state transition tool to be aware whether the block it is processing is the fork-activation block. + +##### New test-framework primitives + +Requires new abstractions in the test framework itself — expectation types, modifiers, helpers — beyond writing test functions with what already exists. + +- 0. Existing test primitives suffice. +- 1. Existing primitives need minor extension. +- 2. New expectation or modifier primitives are required, reusable within this EIP's own test suite. +- 3. New framework-level primitives are required that become a permanent part of the framework and are used by other EIPs' tests. + +##### Cryptography + +Introduces new cryptography mechanisms or modifies existing functionality that involves cryptography + +- 0. No cryptography mechanisms are introduced. +- 1. A new cryptography mechanism is introduced but it is a well known mechanism that is known to have vast resources to aid on its testing. +- 2. Multiple new cryptography mechanisms are introduced that are well-known or a single but novel mechanism is introduced that is either untested or has limited resources. +- 3. Multiple new cryptography mechanisms are introduced and at least one of them is a novel mechanism. + +##### Edge/boundary conditions + +Feature contains edge/boundary conditions. + +- 0. No discernible edge cases or boundary conditions are introduced. +- 1. A single edge-case or boundary-condition prone mechanism is introduced. +- 2. Multiple edge-case or boundary-condition prone mechanisms are introduced, but none of them requires an elevated number of cases to test. +- 3. Multiple edge-case or boundary-condition prone mechanisms are introduced and at least one of them requires an elevated number of cases to test. + +##### Block syncing changes + +Modifies block RLP validation mechanisms that require test client syncing. + +- 0. No new RLP validation mechanism is introduced. +- 1. A single simple RLP validation mechanism is introduced. +- 2. Multiple simple RLP validation mechanisms are introduced or a single complex one. +- 3. Multiple RLP validation mechanisms are introduced and at least one of them is deemed complex. + +##### Engine API changes + +Introduces new fields to the Engine API directives + +- 0. No new fields or communication mechanisms are introduced to the Engine API. +- 1. A single new field is introduced in one of the Engine API endpoints. +- 2. Multiple fields are introduced to one or multiple Engine API end points, or a new Engine API end-point is introduced. +- 3. Multiple fields are introduced to one or multiple Engine API end points and a new Engine API end-point is introduced. + +##### Added system contracts + +Introduces new system contract, stateful or not + +- 0. No new system contracts are introduced. +- 1. A new system contract is introduced that is not stateful nor does it trigger a new system action (e.g. requests to the consensus layer). +- 2. Multiple new system contracts are introduced or a single new system contract that is either stateful or triggers a new system action (e.g. requests to the consensus layer). +- 3. Multiple new system contracts are introduced and at least one of them is either stateful or triggers a new system action (e.g. requests to the consensus layer). + +##### Modified system contracts + +Modifies pre-existing system contracts + +- 0. No modifications to pre-existing system contracts are introduced, directly or indirectly. +- 1. Does not directly modify any system contract, but its behavior has minor indirect effects on one or more system contracts. +- 2. Does not directly modify any system contract, but its behavior has major indirect effects on one or more system contracts. +- 3. At least one pre-existing system contract code or state is modified, which would involve irregular state transition or a similarly complex transition methodology. + +##### Added opcodes + +Introduces new opcodes + +- 0. No new opcodes are introduced. +- 1. A new simple opcode is introduced (no data portion, no complex stack mechanics, and a constant gas cost). +- 2. Multiple new simple opcodes are introduced, or a single new complex opcode is introduced (has data portion, or complex stack mechanics, or a dynamic gas cost). +- 3. Multiple new opcodes are introduced, and at least one of them is complex (has data portion, or complex stack mechanics, or a dynamic gas cost). + +*Cryptography opcodes are not considered complex by default. Refer to the "Cryptography" section for a separate assessment. + +##### Modified opcodes + +Modifies pre-existing opcodes + +- 0. No pre-existing opcode modifications are introduced. +- 3. At least one pre-existing opcode's behavior is modified (not including gas changes) or a pre-existing opcode is deprecated. + +##### Added precompiles + +Introduces new precompiles + +- 0. No new precompiles are introduced. +- 1. A new simple precompile is introduced (constant input length, constant gas cost). +- 2. Multiple new simple precompiles are introduced, or a single new complex precompile is introduced (dynamic input length or dynamic gas cost). +- 3. Multiple new precompiles are introduced, and at least one of them is complex (dynamic input length or dynamic gas cost). + +*Cryptography precompiles are not considered complex by default. Refer to the "Cryptography" for a separate assessment. + +##### Modified precompiles + +Modifies pre-existing precompiles logic or gas-accounting + +- 0. No pre-existing precompiles are modified. +- 1. At least one pre-existing precompile has its gas schedule modified. +- 2. Multiple pre-existing precompiles have their gas schedule modified, or a single pre-existing precompile has its behavior modified. +- 3. The behavior of multiple pre-existing precompiles, or a single complex pre-existing precompile modified. + +##### Encoding changes (RLP/SSZ) + +Introduces encoding changes at the transaction/block/interfaces level + +- 0. No encoding changes are introduced at the transaction, block, or interfaces levels. +- 3. An encoding change is introduced at transaction, block or interfaces level (e.g. RLP -> SSZ). + +*"Interfaces level" includes the Engine API. Score an Engine API encoding change (e.g. JSON -> SSZ) here. + +##### New transaction types + +Introduces a new transaction type + +- 0. No new transaction types are introduced. +- 3. A new transaction type is introduced. + +##### New or modified transaction validity mechanisms + +Creates new or modifies pre-existing transaction types' validation mechanisms + +- 0. No changes are introduced to the validity rules of existing transaction types or to their intrinsic gas cost calculation. +- 1. Minor adjustments are introduced to validity rules or intrinsic gas cost calculation, but they do not significantly affect existing tests. +- 2. Changes to validity rules or intrinsic gas cost calculation affect existing tests, but require only limited updates to test cases and no redesign of the testing infrastructure. +- 3. Changes to validity rules or intrinsic gas cost calculation require extensive rework or redesign of the tests or testing infrastructure. + +##### New block / header fields + +Introduces new block or block header fields + +- 0. No new block or header fields are introduced. +- 3. A new block or header field is introduced. + +##### New fork activation mechanism + +Modifies state, internal variables, or similar, at the fork activation block + +- 0. No state modifications, internal variables or similar are modified at the fork activation block. +- 3. Either a state modification or internal variables are modified at the fork activation block. + +*Initialization of new internal variable is not considered a modification. + +##### Performance risks + +Introduces or modifies mechanisms and requires performance validation. + +- 0. No new mechanisms are introduced that require performance validation. +- 1. The introduced mechanisms can be benchmarked in isolation and do not affect existing performance behavior. +- 2. The introduced mechanisms cannot be fully benchmarked in isolation, but they only have a limited impact on the existing performance benchmarks. +- 3. The introduced mechanisms cannot be benchmarked in isolation and have a substantial impact on existing performance benchmarks or have complex interactions with existing mechanisms. + +##### Security risks + +Introduces or modifies mechanisms that could compromise the security of the chain, users, validators, or other stakeholders, if not implemented properly. + +- 0. No new mechanisms are introduced that could pose a security risk. +- 1. The introduced mechanisms are self-contained, can be validated in isolation, and do not alter existing invariants that could pose a security risk for any stakeholders. +- 2. The introduced mechanisms interact with a limited number of existing components, slightly altering their security assumptions and requiring a targeted security review or fuzzing. +- 3. The introduced mechanisms interact with multiple existing components, including critical ones, substantially altering their security assumptions and requiring an extensive security review and fuzzing. + +##### Unspecified behavior requiring cross-client consensus + +The EIP text does not determine the answer for cases a test can construct. Clients must agree on a previously unspecified detail before tests can be baselined. The cost here is coordination and re-baselining, not test writing. + +- 0. The EIP text determines the answer for every case a test could construct. +- 1. A few details are unspecified but have an obvious intended reading. +- 2. Details require client agreement before tests can be written, but they are localized. +- 3. A previously unspecified *and previously unobservable* behavior becomes consensus-critical; expect tests to be re-baselined on each round of EIP amendment. + +*Score this from the EIP's state at assessment time: whether it has client implementations, whether it has been through a devnet, and how many open questions remain on its discussion thread. + +##### Cross-EIP interactions + +Introduces or modifies mechanisms that affect other EIPs in either the same or past forks. + +- 0. Fully self-contained EIP that does not depend on, modify, or conflict with any other EIP. +- 1. The EIP interacts with one or more other EIPs in a non-critical and limited way but can be tested independently for the most part. +- 2. The EIP depends on or modifies one or more other EIPs such that coordinated testing and consideration is required, but interactions are limited in scope and not complex. +- 3. The EIP has strong interdependencies with multiple EIPs, requiring extensive coordinated cross-EIP testing as well as potential re-design of existing test vectors. +- **+1 for every 3 additional interacting EIPs beyond the first 3**, each of which requires its own coordinated test cases. List the EIPs in the rationale. + +*This row is intentionally uncapped, unlike every other anchor: each interacting EIP is another axis of the test matrix, so a ceiling would make a 12-EIP product indistinguishable from a 3-EIP one. + +### Checklist + +| Anchor | Score (0–3) | Rationale | +|---|---:|---| +| **EVM Gas rule changes** | | | +| **State-access ordering within opcode execution** | | | +| **Blob gas accounting changes** | | | +| **State gas accounting changes** | | | +| **New EVM gas refund** | | | +| **Patterns affecting pre-existing tests** | 2 | Considerable, but one contrived category — tests that read ORIGIN. `Op.ORIGIN` appears in **9 hand-written test files**, and ORIGIN in **121 files under `tests/ported_static/`**. Unlike CALLCODE or SELFDESTRUCT, ORIGIN is not woven through call-graph or state-lifecycle tests; the affected set is precisely the tests that assert on the transaction initiator. This row also absorbs the cost of re-baselining tests that exercise ORIGIN alongside other features. | +| **New invariant on pre-existing tests** | | | +| **Transition-tool interface changes** | | | +| **New test-framework primitives** | | | +| **Cryptography-related testing** | | | +| **Edge/boundary conditions** | 1 | A single boundary-prone mechanism. The cases are the top-level frame (where ORIGIN and SENDER already agree, so the change is invisible), then one frame-entry variant each for CALL, CALLCODE, DELEGATECALL and STATICCALL, plus an EIP-7702 delegated frame. Small and fixed — the EIP's own Test Cases section says exactly this. | +| **Block syncing changes** | | | +| **Engine API changes** | | | +| **Added system contracts** | | | +| **Modified system contracts** | | | +| **Added opcodes** | | | +| **Modified opcodes** | 1 | ORIGIN (0x32) keeps its opcode and cost but returns the current frame's caller instead of the transaction initiator. Scored 1 rather than the anchor's binary 3 because the change is a one-line substitution with no new mechanism: the value pushed comes from a field the frame already carries. See Special Considerations — this row is defined as 0/3 with no intermediate level, which over-scores trivial opcode changes. | +| **Added precompiles** | | | +| **Modified precompiles** | | | +| **Encoding changes (RLP/SSZ)** | | | +| **New transaction types** | | | +| **New or modified transaction validity mechanisms** | | | +| **New block / header fields** | | | +| **New fork activation mechanism** | | | +| **Performance risks** | | | +| **Security risks** | 3 | The blast radius is unknown and has to be determined before this can ship. The EIP asserts that for existing misuse affected negatively "a clear example has yet to be identified" — but `require(tx.origin == msg.sender)` is the standard idiom for "the caller is an EOA, not a contract", and aliasing makes it unconditionally true. Every contract using that guard silently loses it, and it fails **open**: the contract-caller patterns it was written to block (flash-loan and reentrancy shapes) become reachable again. Nobody has measured how many deployed contracts depend on it, in what value, or what each one gates. That is a substantial change to the security assumptions of an unquantified set of live contracts, and it needs on-chain analysis plus extensive review before the change can be judged safe — not a test-suite exercise. | +| **Unspecified behavior requiring cross-client consensus** | 1 | A few details unspecified but with an obvious intended reading. "Return the same value as CALLER" fully determines the pushed value in every frame type, including DELEGATECALL. The one genuine omission is that **the EIP does not state a gas cost at all** — not that it is unchanged, not what it becomes. Left at 1 rather than 2 because either answer is trivial on both the specs and the testing side: ORIGIN and CALLER are both fixed-cost, and settling it needs no back-and-forth with clients. | +| **Cross-EIP interactions** (uncapped) | 0 | Not scored. ORIGIN is read by EIP-7702 delegated frames and is load-bearing in the ERC-4337 bundler-authority example the EIP cites, but in every case the consequence is only that existing tests need updating — which is already counted under "Patterns affecting pre-existing tests". There is no coordinated cross-EIP design question and no other EIP's vectors need re-deriving, so scoring here would double-count. | + +**Total: 8** + +#### Special Considerations + +> Evaluator must write here special considerations that make the EIP particularly complex to test due to reasons not directly included in this checklist. + +- **The security risk is a research task, not a testing task.** Almost all of this EIP's score sits in one row, and the work it implies is on-chain measurement of how widely `require(tx.origin == msg.sender)` is deployed and what it protects. Test-writing is cheap here; establishing that the change is safe is not. +- **The EIP under-states its own compatibility break.** Security Considerations claims no clear example of negatively affected misuse has been identified. The EOA-guard idiom is a counterexample in wide use, and it fails open rather than closed. +- **Checklist feedback: "Modified opcodes" is binary 0/3 with no middle.** Aliasing ORIGIN to an already-available field and, say, redefining a call opcode's frame semantics both land on 3. Scored 1 here as a deliberate departure. A 0-3 ladder for that row — one for a value substitution, two for changed stack or memory behaviour, three for changed control flow or state effects — would score this EIP without needing the exception. + +#### Notes + +- ORIGIN is a fixed-cost opcode (2 gas) and touches no state, so the gas rows and the state-access ordering row do not apply; only the pushed value changes. +- The EIP's Test Cases section already defines the full matrix: for each of CALL / STATICCALL / DELEGATECALL / CALLCODE, assert ORIGIN equals SENDER directly and at each hop of a multi-hop chain. +- If EIP-2488 (Deprecate CALLCODE) also lands, the CALLCODE arm of that matrix becomes vacuous; sequence the two together. +- Status is Stagnant (created 2024-03-03) and two of the three AA proposals cited as motivation (EIP-3074, EIP-7377) have since been superseded by EIP-7702, which already shipped. The motivation section is worth revalidating before test work starts. + +#### Final Assessment + +| Category | Description | Value | +|-----------|--------------|:----:| +| **Total Score** | Sum of all anchor scores (0–84 nominal; **Cross-EIP interactions** is uncapped, so there is no hard maximum) | **`8`** | +| **Complexity Tier** | Computed from total score | 🟢 | + +##### Tier Interpretation + +| Tier | Range | Meaning | +|------|--------|----------| +| 🟢 **Low Complexity** | **<12** | Minor feature or localized change. Existing tests are largely unaffected. Does not require intensive cross-EIP testing. | +| 🟡 **Medium Complexity** | **>=12<23** | Moderate change affecting multiple components. Requires moderate cross-EIP testing. | +| 🔴 **High Complexity** | **>=23** | Broad or deep impact on protocol behavior; high regression risk; and/or requiring intensive cross-EIP testing. | + +##### Revision Notes + +> Background only. Nothing here is needed to fill in the checklist — the anchor +> definitions above are self-contained. Record the revision a completed +> assessment was scored against at the top of the document; **scores are not +> comparable across revisions**, so re-score rather than compare. + +###### Revision 2 — 28 anchors, nominal 0–84 + +Five anchors were added, one was removed, and **Cross-EIP interactions** was +uncapped: 24 anchors become 28. + +Tier thresholds were 10/20 against revision 1's 24-anchor, 72-point scale. They +are scaled by 84/72 to 12/23 so that tier membership stays stable as the anchor +set grows, rather than every EIP drifting upward a tier. + +The revision comes from +[the Amsterdam calibration](../complexity_assessments/calibration/README.md), +which measured each Amsterdam EIP's score against the work it actually produced in +`ethereum/execution-specs`. Every mature Amsterdam EIP landed within ±3 of the +score its measured work implies, except EIP-7928, which was short by 11 points +with no rows left to score on — it had 29 of a possible 33 across the ten rows +that applied to it. The five new rows are where that work should have been +recorded. See +[proposed-anchors.md](../complexity_assessments/calibration/proposed-anchors.md) +for the evidence behind each one. + +Per-row notes: + +- **State-access ordering within opcode execution.** EIP-7928 made every state + access consensus-observable via the BAL. That was a one-time transition, so the + row is worded for the world after it: it scores EIPs that *move* the ordering, + not the introduction of observability. EIP-7928 itself scored 0 on **Modified + opcodes** — correctly, since final EVM semantics were unchanged — which is how + the most expensive part of its work scored zero under the previous revision. + Scored retroactively against this row it is a 3: it reordered gas-charge sites + across an entire class of opcodes. Any pre-Amsterdam EIP is a 0 regardless of + what it did internally, since intra-opcode ordering was not consensus then. +- **New invariant on pre-existing tests.** Split out from **Patterns affecting + pre-existing tests**, which only captures *rework*. EIP-7928 scored 2 there and + would score 3 here: every Amsterdam test now validates a BAL whether or not it + has anything to do with access lists. +- **State gas accounting changes.** State gas was introduced by EIP-8037. The + checklist had a row for blob gas and none for this. +- **Cross-EIP interactions.** The `+1 per 3 additional EIPs` increment is a + judgement call, not a calibrated figure. It exists because EIP-7928 interacted + with 12 EIPs and scored the same 3 as an EIP interacting with three. +- **Engine API encoding changes** was removed. It described a wire-format change + at the Engine API layer (JSON -> RLP/SSZ), but such migrations are coordinated + outside the EIP process, so an EIP-scoped assessment has no use for the row. It + was scored 0 or left blank in all 28 assessments written against revision 1, so + removing it changes no historical total, and it never had anchor level + definitions. **Encoding changes (RLP/SSZ)** covers the case if it ever arises — + that row already reads "transaction, block or interfaces level". + +One finding is deliberately **not** reflected in the scoring: some of this cost +grows multiplicatively rather than additively, and no additive row at any weight +reproduces EIP-7928's measured cost. A multiplier row was considered and deferred +— with only one high-cost EIP observed, the data cannot identify which row should +multiply. Until a second fork supplies a second observation, evaluators record +multiplicative test-matrix growth under **Special Considerations**, as the +State-access ordering anchor instructs. + +###### Revision 1 — 24 anchors, 0–72 + +Original version. + + +## Consensus Specs + +### Specs + +### Testing + +### Notes