LibraryConsensus2017Design paperCorpus record
Tail Call Execution Semantics
BIP 117. Mark Friedenbach.
BIP 117, Tail Call Execution Semantics. BIP16 (Pay to Script Hash)[1] and BIP141 (Segregated Witness)[2] provide mechanisms by which script policy can be revealed at spend time as part of the execution witness.
Status in the source: Draft. A reading of the public specification, not a copy of it and not a certification.
Tail Call Execution Semantics is worth reading for the rule it actually adds: BIP16 (Pay to Script Hash)[1] and BIP141 (Segregated Witness)[2] provide mechanisms by which script policy can be revealed at spend time as part of the execution witness.
The five-minute read
The rule
BIP16 (Pay to Script Hash)[1] and BIP141 (Segregated Witness)[2] provide mechanisms by which script policy can be revealed at spend time as part of the execution witness.
What was already failing
Bitcoin script and block validity only change when a soft fork says an old pattern is now invalid. Without that rule, every node is free to accept what this document wants to reject.
What the number does not mean
The source marks this draft. It is not a live consensus rule just because it has a number.
What a builder should be able to point at
An implementation either constrains BIP16, BIP141, BIP116 or it is a different design.
One action, walked through
- Open BIP 117 and read the status line before the examples.
- Write down the rule in one sentence. A fair version of that sentence is: BIP16 (Pay to Script Hash)[1] and BIP141 (Segregated Witness)[2] provide mechanisms by which script policy can be revealed at spend time as part of the execution witness.
- Name the object that changes: BIP16, BIP141, BIP116.
- Ask what an old client, an old contract, or an offline counterparty does. If the document is silent, the silence is part of the design.
The argument, unpacked
What the text is allowed to settle
Bitcoin Improvement Proposal 117 can settle the shape of Tail Call Execution Semantics. It cannot settle whether a later client, a later fork, or a later wallet still does this.
What this page will not pretend
There is no benchmark, no adoption number, and no claim that the mechanism is safe outside the assumptions written in the source.
What has to be true
- You are implementing BIP 117 at the status the text itself states: Draft.
- The object that has to change is BIP16, BIP141, BIP116. A neighbouring document with a similar name is not this one.
- Activation is a separate mechanism from the opcode or the sighash. This page does not pick a height.
What happened after the paper
The source marks this draft. It is not a live consensus rule just because it has a number. Later documents can narrow, replace, or ignore this one. Cite the number you mean.
What to check before you use the idea
- Which bytes become invalid under Tail Call Execution Semantics, and which old transactions stay valid?
- Is enforcement in consensus, or only in the mempool policy of one client?
- Which of these objects does the text actually define: BIP16, BIP141, BIP116?
Terms
- BIP 117
- The public text titled Tail Call Execution Semantics.
- Draft
- The document's own label for how finished the text is. It is not a market fact.
The problem the paper names
Bitcoin script and block validity only change when a soft fork says an old pattern is now invalid. Without that rule, every node is free to accept what this document wants to reject.
What the design proposes
- BIP16 (Pay to Script Hash)[1] and BIP141 (Segregated Witness)[2] provide mechanisms by which script policy can be revealed at spend time as part of the execution witness.
- In both cases only a single script can be committed to by the construct.
- While useful for achieving the goals of these proposals, they still require that all policies be specified within the confine of a single script, regardless of whether the policies are needed at the time of spend.
How the mechanism is specified
- Taken from the specification, the next constraint is: In both cases only a single script can be committed to by the construct.
- Locate BIP16, BIP141, BIP116 in BIP 117 and apply it to one transaction or call.
- Then check the failure the class of rule always has: a node that did not upgrade, a reverted call, a replayed signature, or a peer that does not speak the message.
What this page does not treat as proven
- A soft fork does not bind a node that never upgrades. It binds the nodes that enforce the new rejection.
- Activation is a separate mechanism from the opcode or the sighash. This page does not pick a height.
- The source marks this draft. It is not a live consensus rule just because it has a number.
Why a venture studio still reads it
Use BIP 117 when a pitch says 'Tail Call Execution Semantics' without saying whether the rule is consensus, policy, or an interface. The number is the citation. The pitch is not.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
