docs: openUrl hardening after review (limits, listing passes, CORS tests)
CHANGELOG (M4 section), known-issues (wasm limits: maxFetch, the 1 GiB decode limit, the 4 GiB file limit on wasm32, bodies cut off at their length, listing passes, the cross-origin tests, and a pre-existing nondeterministic error choice on cve-2025-2310.h5 that can fail the native corpus comparison), the viewer README (options, how listing costs, tests) and the M4 status in docs/design/range-reads.md. Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
This commit is contained in:
@@ -50,6 +50,38 @@
|
||||
reachable from JavaScript (it was compiled out before), and the promise
|
||||
glue and `remote.js` add JavaScript. Not measured for the docs yet (the
|
||||
build machine was shared); the viewer README's size table predates M4.
|
||||
- **Hardened after review (2026-09-27):**
|
||||
- Sizes a server or a dataset names are errors, never an abort of the
|
||||
wasm module (which took every open file on the page with it): a read
|
||||
past 2 GiB aborted in the lazy cache, reachable by a hostile server
|
||||
claiming a large file and a 2 GiB heap collection, and `read()` of a
|
||||
256 MiB `u8` dataset aborted widening it to 64 bits. New option
|
||||
`maxFetch` (512 MiB, at most 1 GiB): what one call may fetch, and the
|
||||
longest single read, refused before fetching. `read()` refuses a
|
||||
dataset that would take more than 1 GiB to decode, naming
|
||||
`readHyperslab`. A file of 4 GiB or more is refused at open (wasm32
|
||||
reads offsets as 32-bit); `maxDownload` is at most 1 GiB.
|
||||
- Response bodies are read as they arrive and cut off at the length
|
||||
asked for (`maxDownload` for a `200`): a `206` with a gigabyte body
|
||||
was buffered whole before its length was checked.
|
||||
- Listing a group reads every child's header, and every node of each
|
||||
level of the group's index, in one pass: 3000 datasets (h5py, 198 MB)
|
||||
listed in 6 passes and 73 requests at 1 MiB blocks instead of 185
|
||||
passes and 184 serial requests (`libver="latest"`: 9 passes instead of
|
||||
189). In `clawhdf5-format`, the B-tree v1/v2 collectors, the symbol
|
||||
table node loop and the dense-link loop read (without using) the
|
||||
siblings after the first that fails, then return that error: same
|
||||
results and errors, more reads only on failure (free in memory). The
|
||||
lazy cache no longer re-fetches a cached block to merge two requests.
|
||||
- `headers` may be a `Headers` instance or `[name, value]` pairs (a
|
||||
`Headers` was silently dropped); when one range request fails the
|
||||
others in flight are aborted; `parallel` must be an integer from 1 to
|
||||
1024.
|
||||
- Tests: `test/serve.py` serves ranges without exposed `Content-Range`/
|
||||
`ETag` (`/noexpose/`, and `/unexposed/` for a real cross-origin page
|
||||
in Chromium), so the HEAD-length path runs end to end; hostile and
|
||||
oversized files (`make_fixture.py`'s `write_limits`), flooding
|
||||
bodies, aborted siblings.
|
||||
|
||||
### Range reads, milestone M3: remote files (2026-09-26)
|
||||
- **New crate `clawhdf5-remote`.** `open_url("http://host/file.h5")` gives
|
||||
|
||||
Reference in New Issue
Block a user