A read longer than isize::MAX (2 GiB on wasm32) aborted the module in LazyStorage::assemble (capacity_overflow), taking every open file on the page with it, and a hostile server only had to claim a large length and serve a heap collection of 2 GiB + 4 KiB to get there (after fetching 2 GiB). Reading a large u8 dataset whole aborted the same way when its values were widened to 64 bits. - LazyConfig::max_fetch (openUrl option maxFetch, default 512 MiB, at most 1 GiB): a read longer than it fails at once, before anything is fetched, and an operation whose passes would fetch more than it fails before fetching (Operation::charge). assemble reserves fallibly. - Reader::read refuses a read that would use more than 1 GiB while decoding (core::MAX_READ_BYTES: stored bytes + 64-bit values + result) with an error naming readHyperslab, before reading. - openUrl refuses a file of 4 GiB or more at open on wasm32: the format code turns offsets into usize, so nothing past 4 GiB can be read there (shown by a new test: data at 3 GiB reads, a 4 GiB file is refused). maxDownload is bounded to 1 GiB. Tests: make_fixture.py writes limits.h5 (a sparse 2^28 + 1024 byte u8 dataset), hostile_vl.h5 (the reviewer's collection) and far.h5 (data at 3 GiB); test.mjs (wasm32) and tests/lazy.rs (native) check each is an error or reads, and that the module survives. Before: RuntimeError: unreachable in Node; the native test read the huge dataset and fetched 2 GiB. Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
HDF5 viewer in the browser
A single page that opens an HDF5 or NetCDF-4 file entirely in the browser
with clawhdf5-wasm (clawhdf5's reader compiled to WebAssembly): drop a
file or give a URL, browse its groups, and look at a dataset's type, shape,
attributes and values (a 50 x 12 window at a time, read as a hyperslab,
with the leading dimensions of a 3-D+ dataset held at chosen indices). A
local file never leaves the page. A file given by URL is not downloaded:
only the byte ranges each view needs are fetched (HTTP range requests),
and the header shows the requests and bytes that has cost so far.
Build and open
rustup target add wasm32-unknown-unknown
cargo install wasm-bindgen-cli --version 0.2.129 # must equal the crate version; build.sh checks
bash examples/wasm-viewer/build.sh # writes examples/wasm-viewer/pkg/ (not committed)
python3 -m http.server -d examples/wasm-viewer 8000 # wasm cannot load from file://
Then open http://localhost:8000/. The URL box, or
?file=<url>&path=<object>, opens a file by URL (same origin, or a server
sending CORS headers, see Limits) and selects an object in it, e.g.
?file=data/run1.h5&path=/results/energy. Python's http.server does not
answer range requests, so a file served by it is downloaded whole (the
header says so); test/serve.py does:
python3 examples/wasm-viewer/test/serve.py --root data=/path/to/files --root =examples/wasm-viewer
# prints its port; open http://127.0.0.1:<port>/?file=data/run1.h5
JavaScript API
import init, { open, openUrl } from "./pkg/clawhdf5_wasm.js";
await init();
const f = open(new Uint8Array(await blob.arrayBuffer()));
f.list("/"); // [{ name, kind: "group" | "dataset" }], groups first
f.info("/grid"); // { shape, maxshape, dtype, elementShape }
f.attrs("/grid"); // [{ name, value, dtype }]
f.read("/grid"); // { shape, dtype, data }
f.readHyperslab("/grid", [0, 0], [10, 5], [2, 1]); // start, count, stride?, block?
f.free();
// A file on a web server, read by HTTP range requests as needed. The same
// methods, each returning a promise.
const r = await openUrl("https://example.org/run1.h5", { blockSize: 1 << 20 });
await r.list("/");
await r.readHyperslab("/grid", [0, 0], [10, 5]); // fetches only the chunks it touches
r.stats(); // { lazy, size, requests, bytesFetched, cachedBytes, passes }
r.free();
openUrl(url, opts) options, all optional: blockSize (bytes per block
fetched, 512 B to 64 MiB, default 1 MiB), cacheSize (bytes of blocks kept
between calls, default 64 MiB), fallback ("download", the default,
reads the whole file when the server ignores Range, up to maxDownload
bytes, default 512 MiB; "error" refuses such a server), headers and
credentials (passed to every request), parallel (requests in flight,
default 6), fetch (a fetch-compatible function to use).
How it works: the reader is synchronous and a page cannot block on the
network, so each call runs as a pass over the blocks fetched so far. A
pass that needs a block not yet fetched is abandoned, the missing blocks
are fetched (in parallel, adjacent blocks in one request), and the pass is
run again, until one completes (docs/design/range-reads.md, M4). Opening
costs one request (the first block, which also gives the file's size);
listing a group whose metadata is in blocks already fetched costs none;
reading a chunked dataset costs a round trip for its chunk index (a few
for a deep one) and one batch of requests for its chunks. Every answer is
checked — a 206 with exactly the bytes asked for, from the same file
(ETag or Last-Modified, and length) — or the call fails.
data is the typed array of the stored width (Float64Array,
Float32Array also for f16, Int8Array ... BigInt64Array,
BigUint64Array), or an array of strings for fixed- and variable-length
strings and enumerations (h5py booleans read as "TRUE"/"FALSE"). Array
datatypes are flattened, their dimensions appended to shape. Anything
else throws an Error naming the type.
Limits
- Read-only.
open(bytes)holds the whole file in memory. openUrl: a cross-origin server must allow CORS and exposeContent-Range(Access-Control-Expose-Headers: Content-Range) or answerHEADwithContent-Length; if the page cannot seeETagorLast-Modifiedeither, a file replaced on the server is detected only by a change of length. A call keeps what it reads until it finishes, so a whole read of a large dataset needs its stored bytes in memory; read windows of large datasets. More indocs/known-issues.md.- Compound, reference, opaque and variable-length-sequence datasets are
refused with an error. Attributes of those types are listed with
value: nulland theirdtype. - No Zstd or SZIP filters (they link C): such a dataset fails with
unsupported filter. Deflate, shuffle, Fletcher-32, LZ4, N-Bit and scale-offset are read (within the limits indocs/known-issues.md). - Virtual datasets whose sources are in other files, and external links, cannot be followed: there is no file system.
Tests
test/run.sh builds the package, writes fixture.h5 (h5py) and
fixture.nc (netCDF4) with test/make_fixture.py, and big.h5, a 200 MB
h5py file (WASM_BIG_MB sets its size, 0 leaves it out; it goes under
TMPDIR), serves them with test/serve.py (range requests, a request
counter, and /norange/... for a server without range support), then:
- runs
test/test.mjsunder Node: every dataset (whole and a strided hyperslab), listing and attribute is compared with what libhdf5 reads back, error paths are checked, and so are the page's DOM-free helpers (viewer-lib.js). Then the same checks on the files opened by URL (1 MiB and 512 B blocks), calls in flight at once, the request budget ofbig.h5(listing it and reading small things of it must take at most 8 requests and under 5% of the file), the download fallback and its limit, and the errors: HTTP status, a file that changes, a server that sends the wrong bytes or stops honouringRange.CLAWHDF5_WASM_CORPUS=DIRalso compares every HDF5 file underDIR(up to 16 MiB) read by URL with the same file read from bytes; - runs
test/browser.sh: loads the page in headless Chromium with?file=fix/fixture.h5&path=...for eight objects and checks the rendered tree, types, shapes, attribute and value cells, the request counter, and the error shown for an unsupported type; then a server without range support, andbig.h5(a small dataset and a window of the large one, with a single-digit percentage of the file fetched). Skipped when no Chromium is found (CHROMEnames one; a Playwright download under~/.cache/ms-playwrightis picked up). Drag-and-drop, the file picker and the URL box are not driven by it; they sharesetFile()with the?file=path.
The same expectations are checked natively, without Node, by
crates/clawhdf5-wasm/tests/h5py_interop.rs, and the lazy reader against
the in-memory one by tests/lazy.rs (with CLAWHDF5_WASM_CORPUS, over the
corpus too), which is what CI runs (the CI container has no Node or
browser).
Size
Measured 2026-09-26 on tank (rustc 1.98.1, wasm-bindgen 0.2.129, gzip 1.14,
gzip -9 -n), after bash examples/wasm-viewer/build.sh. The package is
larger now and the table has not been re-measured: the reader has grown
since, and openUrl (2026-09-27) made the facade's range-read path
reachable from JavaScript and added promise glue and remote.js.
| raw | gzip -9 | |
|---|---|---|
pkg/clawhdf5_wasm_bg.wasm (profile wasm-release, opt-level s) |
627,501 B | 191,639 B |
pkg/clawhdf5_wasm.js (wasm-bindgen glue) |
21,826 B | 4,487 B |
same wasm at opt-level z |
693,068 B | 192,550 B |
same wasm at opt-level 3 |
544,035 B | 198,803 B |
h5wasm 0.10.3: wasm embedded in dist/esm/hdf5_util.js |
3,544,184 B | 907,096 B |
h5wasm 0.10.3: dist/esm/hdf5_util.js as shipped |
4,150,134 B | 986,699 B |
h5wasm figures: npm pack [email protected] (npm reports
dist.unpackedSize 14,731,385 B for the whole package), wasm extracted from
the binaryDecode literal in hdf5_util.js. h5wasm is the whole of libhdf5
(writing, every datatype, plugins), so this compares download size, not
equal functionality. No wasm-opt pass was applied (binaryen is not
installed on tank). opt-level s is used because it is the smallest
compressed.