EIP-7709 - Read BLOCKHASH from Storage and Update Cost

Created 2024-05-18
Status Draft
Category Core
Type Standards Track
Authors
Requires

Abstract

Update the BLOCKHASH (0x40) opcode to read and serve from the system contract storage and charge the additional (cold or warm) storage costs.

Motivation

The BLOCKHASH (0x40) opcode currently assumes that the client has access to recent block history. This makes it a protocol special case: it depends on historical chain data, but it is not modeled like other state-backed reads.

With EIP-2935, recent block hashes are stored in the system contract storage. This allows in-window BLOCKHASH lookups to be modeled as storage-backed accesses while preserving the existing BLOCKHASH return-value semantics.

Specification

The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in RFC 2119 and RFC 8174.

Parameter Value
FORK_TIMESTAMP TBD
HISTORY_STORAGE_ADDRESS 0x0000F90827F1C53a10cb7A02335B175320002935
BLOCKHASH_SERVE_WINDOW 256
HISTORY_SERVE_WINDOW 8191

The BLOCKHASH opcode semantics remains the same as before. From the fork_block (defined as fork_block.timestamp >= FORK_TIMESTAMP and fork_block.parent.timestamp < FORK_TIMESTAMP), the BLOCKHASH instruction should be updated to resolve block hash in the following manner:

def resolve_blockhash(block: Block, state: State, arg: uint64):
  # note that outside the BLOCKHASH_SERVE_WINDOW we continue to return 0
  # despite the 2935 history contract being able to serve more hashes
  if arg >= block.number or (arg + BLOCKHASH_SERVE_WINDOW) < block.number:
    return 0

  # performs an sload on arg % HISTORY_SERVE_WINDOW including gas charges,
  # warming effects as well as state-access recording
  #
  # note that the `BLOCKHASH_SERVE_WINDOW` and the 2935 ring buffer window
  # `HISTORY_SERVE_WINDOW` for slot calculation are different
  return state.load_slot(HISTORY_STORAGE_ADDRESS, arg % HISTORY_SERVE_WINDOW)

If the arg is within the correct BLOCKHASH window, clients MAY choose to either

Regardless of the chosen resolution method, clients MUST apply the entire semantics and effects of the SLOAD operation as defined by the active fork if the arg is within the correct BLOCKHASH window:

Activation

This EIP specifies the transition to the new logic assuming that EIP-2935 has been activated:

Gas costs

As described above, if the arg to be resolved is within the correct window, the corresponding SLOAD charges and accesses are to be applied for the slot arg % HISTORY_SERVE_WINDOW. Note that the HISTORY_SERVE_WINDOW and BLOCKHASH_SERVE_WINDOW are different.

Reading from the System contract

Even if the clients choose to resolve BLOCKHASH through system call to EIP-2935 contract, the gas cost for the system code execution is not applied. Only the effect of SLOAD is applied as described above.

Rationale

Note that BLOCKHASH opcode only serves a limited BLOCKHASH_SERVE_WINDOW to be backward compatible (and to not extend the above exemptions). For deeper accesses one will need to directly call EIP-2935 system contract which will lead to a normal contract execution (as well as charges and accesses).

Backwards Compatibility

This EIP does not change the return-value semantics of BLOCKHASH.

This EIP introduces a significant increase in the cost of in-window BLOCKHASH queries, which could break use-cases that rely on the previous gas cost. Also, this EIP introduces a breaking change in the case where less than BLOCKHASH_SERVE_WINDOW elapse between the EIP-2935 fork and this EIP's fork (unless EIP-2935 is activated in genesis for e.g. in testnets/devnets) as the EIP-2935 system contract would not have saved the required history.

Test Cases

Security Considerations

No security considerations other than the ones contained in EIP-2935 are determined as of now.

Copyright

Copyright and related rights waived via CC0.