← Files Slide ViewerARCHIVED FILE

IMPLEMENTATION_STATUS.md

60.9 KB · Oct 3, 2026 · 06:21 UTC

↓ Download file

# Slide Viewer 0.1.59 implementation and acceptance

This follow-up addresses the gaps audited after PR #1337471. All implementation belongs to **Slide Viewer or the shared scientific-viewer plugin**; it does not modify the Codex host. Multiplayer services and inaccessible proprietary formats are excluded. Accessible formats, single-user persistence, scientific validity, UI/agent equivalence, and real-data qualification remain in scope.

**This is a permissive-only release candidate, not a verified superset of the specialist products in [the requirements](CAPABILITY_REQUIREMENTS.md).** Source implementation, unit tests, controlled MCP execution, browser rendering, installed-host acceptance, scientific accuracy, and permission to publish are different gates. This work has not published version 0.1.59. The current package excludes scran.js and its native dependencies; it cannot start or resume `hvg-cluster` or `reference-labels` jobs. Source embeddings, independent small-panel clustering, ligand/receptor analysis, region QC and authenticated historical artifact inspection/application remain supported.

The independent small-panel PCA and object/pixel classifier solver no longer use `ml-pca` or `ml-matrix`. Their bounded first-party replacements preserve the existing feature, work and iteration ceilings. PCA now keeps numerically null components at zero, so a new spatial-domain run on rank-deficient data can differ from older runs that amplified roundoff during component normalization. Existing saved assignments are not recomputed. Extreme mixed scales that cannot preserve working precision fail explicitly; this is not a general-purpose numerical library or a new full-assay workflow.

The [feature-level specialist comparison](PEER_FEATURE_COMPARISON.md) lists remaining public-format and analysis gaps. Implementing one workflow in a category does not close every method in that category.

The [acceptance manifest](scripts/slide-acceptance-manifest.json) supplies pinned specimen data and the declared clustering genes. Retained tests verify source identity and UI/agent behavior directly. The two unavailable native workflows remain excluded capabilities; their absence is not a successful analysis result.

## Acceptance execution

Playwright discovers the acceptance spec files through `playwright.acceptance.config.ts`. Ordinary CI jobs use native Playwright sharding with one browser worker and no retries; each shard builds and verifies its own installed package. Opening checks run separately. Runner exit statuses determine the job results, and reports and failure diagnostics remain ordinary CI artifacts. The source checkout's [browser test guide](e2e/README.md) documents commands and discovery.

Independent specimen operations run as separate tests. Retained tests verify actual source values, scientific results, permissions, or persistence; repeated cosmetic tours and synthetic receipt-validator matrices have been removed. The repeated cold/warm specimen benchmarks and their sampled-memory gates have also been removed. Installed opening still verifies the genuine pathology slide, and ordinary acceptance exercises the pinned Visium source. Current CI verifies functional behavior without qualifying p95 performance or memory limits. Historical test counts and failed runs below remain evidence for their recorded revisions.

## Implementation and remaining qualification

| Area                              | Plugin implementation                                                                                                                                                                                                                                                                                                                                                                                                                                           | Evidence boundary / remaining qualification                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| --------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Whole-slide navigation            | Bounded TIFF/SVS ranges and pyramids; source/plane-aware tiles, readiness, failures and viewport commands.                                                                                                                                                                                                                                                                                                                                                      | Real 132.6 MB CMU-1 and 722.9 MB Leica files exercise actual pixels. At `7b79873836a0`, the complete 7.26 GB HTA-MELATLAS1 original matched nine of 72 fresh planned pixel comparisons before failing the unchanged 256 MiB packaged-process RSS guard. The no-readable-roots rejection passed; the remaining pixel and fabricated/closed-resource checks did not complete. Multi-gigabyte performance, installed-host cold/warm p95, GPU memory and long-session recovery remain unqualified.                                                                                                                                                                                                                                                                                                                                                                                                         |
| Multichannel microscopy           | OME scenes, C/Z/T, independent channel windows/colors/gamma/opacity; raw-value min/max/mean/sum projections before display conversion; anisotropic calibration and source-bound exports.                                                                                                                                                                                                                                                                        | Display opacity does not change quantitative samples or grant consent for an invisible source. Supported codecs/layouts below, not arbitrary microscopy formats. Inferred pyramid extent ratios are labeled inferred, not measured calibration. Installed plane/export acceptance remains separate.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Tissue registration               | H5AD embedded image/library catalogs and full-source windows; explicit affine registration for H5AD or indexed scientific coordinate sources, with source/target identities, applicable library membership and current index-read authorization; unregistered points withheld.                                                                                                                                                                                  | A declared association or plausible transform is not a scientifically validated registration. Independent landmarks and researcher acceptance remain necessary. A source filename does not select or bypass the indexed-source permission path.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Annotation and measurement        | Stable IDs, points/lines/rectangles/polygons/holes, labels, reversible edits, anisotropic measurements, spatial-index queries and entity inspection. Native ASAP XML imports retain supported geometry, ordinal identity, labels/groups and source colors through the same UI/agent layer settings. Source/scene/plane provenance fences rendering and export.                                                                                                  | Vector components, source cells and estimated objects remain distinct. Unknown legacy geometry is retained but withheld from aligned rendering, not silently rebound. ASAP spline/None and native XML output remain unsupported; project recipes reparse the original XML rather than claim native-application roundtrip equivalence. Real-specimen cross-tool round trips and every installed UI affordance are not yet accepted.                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Quantitative pathology            | Source-backed ROI/object features, labeled object/pixel classifiers, pinned StarDist H&E nuclei, dual-channel DNA-seeded cell-region watershed and annotation-based evaluation.                                                                                                                                                                                                                                                                                 | Real PUMA and BBBC007 executions are bounded research evidence, not whole-slide inference, clinical accuracy, QuPath/Cellpose equivalence or hidden-test benchmarks. See [PATHOLOGY.md](PATHOLOGY.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Spatial molecular data            | Streaming CSV/TSV/GeoJSON cell/bin/transcript layers, SQLite RTree indexes, stable IDs, QC/joins, exact filtered pages/ROI queries and explicit density overviews.                                                                                                                                                                                                                                                                                              | A generated million-point benchmark verifies index scale, not a million-molecule specimen. Processed outputs do not implement instrument decoding or prove transcript-to-cell assignments.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Linked exploration and references | Actual source embeddings/annotations and stable-ID selections. Authenticated historical PCA/cluster/reference artifacts can be applied through exact physical-row/ID joins, source/matrix fences and verified artifact hashes. New reference-labeling jobs and resumes are unavailable.                                                                                                                                                                         | Derived projections do not overwrite source metadata or recompute missing results. Excluded, unanalyzed and unassigned observations remain distinct. Prior reference-labeling performance belongs to the removed native implementation and does not qualify this release.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| AnnData matrix selection          | Dense/CSR/CSC `X`, same-axis layers and independent `raw/X`/`raw/var`; matrix-bound gene/window pages, lazy vectors, workflows, portable recipes and CSV receipts. Physical-column references disambiguate duplicate names; missing/ambiguous selections clear without a default. Alternate matrices never borrow another matrix's normalization denominator.                                                                                                   | Controlled source/component tests cover reordered, extended, disjoint and duplicate features. The existing 64-row PBMC derivative matches all 8,380,928 values across four representations in the provider checks. At `9dde573608a1`, separate actual-package runs verify the complete bounded count matrix and the independent raw-axis derivative against full-value hashes, below the unchanged 256 MiB child RSS limit. The raw derivative contains 64 × 32,738 raw features and 64 × 16 reordered X features; it is not a full PBMC specimen or spatial-image dataset. Matrix names do not establish count scale. A native transport lacking matrix proof retains the requested recipe but marks restoration unavailable rather than claiming X is the restored raw matrix.                                                                                                                       |
| Scientific preprocessing          | Independent exploratory PCA/Louvain is retained for at most 8,000 loaded observations and 16 selected genes. Full-assay HVG/PCA/neighbor graph/Leiden and newly computed UMAP/t-SNE are unavailable because the native engine is excluded.                                                                                                                                                                                                                      | Small-panel results are not full-assay preprocessing. Imported/source embeddings and authenticated historical artifacts do not imply that this release can recompute them. Unknown matrix scale remains unknown, and embedding axes are dimensionless rather than tissue coordinates.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Spatial analysis                  | Explicit graphs, neighborhood enrichment, global Moran's I and Geary's C, disjoint-subset comparisons and source-backed ligand/receptor complexes with recorded null models.                                                                                                                                                                                                                                                                                    | Real-data arithmetic agreement does not establish biological communication, donor replication or validity for every assay. Geary uses binary unstandardized weights and a centered permutation tail, with measured isolated nodes retained; it is not PySAL's default p-value convention, local Geary or multi-gene correction. Descriptive scores without permutations do not acquire p-values.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Region profiling                  | Explicit counts/probes/negative controls, morphology joins, QC, LOQ and Q3 processing, units and separate region identities.                                                                                                                                                                                                                                                                                                                                    | All 231 GSE190088 Q3 factors, negative-control means and LOQs, plus 1,155 normalized values pass strict independent numerical checks. Reproducing the upstream reflected-p-value bug requires an explicit, warned legacy mode; the corrected method remains the default. Aggregate counts do not provide transcript coordinates or biological validation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Interoperability                  | Local DICOM multi-instance WSI, ANN/SR/SEG/parametric-map semantics and exports; public DICOMweb WSI tile assembly, SHA-backed projects, metadata-only annotation/measurement exports and strict native WADO PNG/TIFF/OME-TIFF; separately guarded STOW; NGFF/OME-Zarr v2/v3. Verified ANN/SR layers retain analytic geometry, coded measurements and source identities.                                                                                        | A real default-SDK read of 55 reduced IDC frames checks actual interior/edge pixels, not full-resolution coverage, publisher-authenticated pins or installed remote-viewer acceptance. That lossy RGB8 JPEG source does not qualify native MONOCHROME2 exports; those use generated controls only. Other public profiles remain gaps. Analytic ellipses use a disclosed display tessellation, not polygon measurements. No external STOW POST was performed for qualification.                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Single-user projects              | Signed records, compare-and-swap, atomic writes, portable file/DICOM-collection/OME-TIFF-collection, complete SHA-backed DICOMweb and inventory/SHA-backed OME-Zarr recipes, fresh layer imports and coordinate/history restoration. Own-format ZIPs reopen without extraction; derived-result recipes refer to existing signed artifacts, never saved grants or recomputation. Source-only model preparation precedes one-use consume-time index/state writes. | Restored state is neither authority nor image consent. Fresh-server SDK checks cover source identity, geometry, pixels and file/ZIP reopening. Separate source-runtime tests save and reopen a generated-TIFF JSON project in distinct Node children, checking observed close-before-restart and unchanged source/artifact identities. Production packaged Visium restart, mounted-browser behavior and installed-host acceptance remain separate gates. OME-TIFF recipes retain complete member identities/topology and require fresh per-member permission; rollback releases only newly prepared handles. Missing recovery storage is read without creating it; failed/canceled work retains capacity until cleanup drains and preserves the old scene. ETag-only/lazy stores are not durable recipes; missing/expired derived results remain explicitly unavailable. Multiplayer remains excluded. |
| Captured-view exports             | Six default-plugin formats: annotation GeoJSON, calibrated measurement CSV, loaded-view spatial CSV, portable project JSON, annotation ZIP and eligible source-native PNG. Exact typed CSV IDs, single-use commands and no-clobber byte/hash receipts.                                                                                                                                                                                                          | PNG requires actual current user capture and supported source samples, not a display substitute. Spatial tables cover the loaded original rows for one gene, not the full assay. DICOM collection exports retain every member and exact topology; fresh permissions and source identities are required on project/bundle reopening. See [format boundaries](FORMAT_SUPPORT.md#captured-view-exports).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Numeric source exports            | TIFF/OME-TIFF from actual selected microscopy planes, metadata-qualified native Gray/RGB 8/16-bit local files/collections, or level-zero native WADO unsigned MONOCHROME2 u8/u16; native-level geometry, inward capture mapping, exact physical-plane checks and IFD/SOP/frame provenance.                                                                                                                                                                      | Decoded source color values are distinct from original stored numeric samples; display gamma/opacity never become quantitative input. Reduced-level support does not imply every source level/profile is qualified. Capture coordinates alone are not consent. The native WADO adapter reads delivered samples before display scaling and retains unknown original stored syntax; acquired native-16-bit WADO and installed-host qualification remain open.                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| UI and agent control              | Shared typed operations for presentation, sources, channels, regions, layers, projects, exports and science forms; revisioned/idempotent commands and render acknowledgements. Source-bound queries page the complete selected observation IDs and microscopy scene/channel catalogues with exact UI defaults.                                                                                                                                                  | Source registration or a queued command is not a mounted frame. The 501-observation query is controller-level evidence; component and real SDK regressions cover continuations, current image/assay identities and withdrawn read authority. Privileged UI actions request authorization through chat; chat delivery is not admission. Executed UI/agent pairs and installed native-opening acceptance remain required.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Beyond-UI jobs                    | Structured imports/queries, asynchronous workflows/artifacts, progress/cancel/retry, signed durable records and guarded resume with worker/IO drain.                                                                                                                                                                                                                                                                                                            | Actual parent-death testing exercises the copied watchdog against a CPU-blocked child, with recovery blocked until the child exits. Resumption still requires current permissions, unchanged inputs and valid records; app caches cannot restore disk state or renew write authority. Large-batch and installed-host recovery remain separate qualifications.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Usable workspace                  | Keyboard-controlled Layers/Sources/Project/Inspect sections, viewer-scoped command search with shared UI/agent state, bounded panels, scientific forms, linked inspection, legends and explicit unsupported/recovery states.                                                                                                                                                                                                                                    | Component tests are not accessibility or researcher studies. Automated accessibility/task cases and researcher usability evidence must run; styling alone does not establish ease of use.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Runtime and packaging             | Node minimum guard, frozen dependencies, browser/Node boundary guard, single-chunk schema-initialization regression, supported scientific workers, self-contained view and source/runtime fingerprints. The emitted-input license gate rejects excluded or unresolved runtime code and binds retained notices to the copied package.                                                                                                                            | Compiler tests are not mounted-browser acceptance. Final head-bound CI and installed-host runtime selection remain gates. Hash-bound source reviews and permissive license declarations are technical evidence, not a legal opinion or publication approval.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |

## Images and files

- **Node:** the launcher requires Node 22.23.2 or newer. It reports the actual runtime and never downloads Node or changes the host's global selection.
- **TIFF/OME-TIFF:** bounded raw, Deflate, LZW, PackBits and qualified baseline JPEG reads; main/SubIFD DAG traversal, all TIFF orientations, explicit source, block and pixel budgets, multi-scene/plane layouts and per-level transforms. Explicit collection opening accepts up to 16 authorized TIFF/XML originals and 32 scenes, with exact UUID/member/plane routing and complete project recipes; it does not discover companions. Missing members, unqualified predictors/codecs and ambiguous pyramids fail explicitly. Non-OME and browser-local paths retain their own limits.
- **Node OME Zstd:** compression `50000` uses a separate bounded backend in single-file display, numeric and eligible source-PNG readers and explicit-collection paths. Browser and missing-backend paths still reject it. Two unchanged imagecodecs TIFF software controls match a separate codec oracle using the same TIFF parser; they are not biological OME acquisitions. Generated controls cover the integrated routes without establishing package or installed-host parity.
- A real 722,911,158-byte Leica OME file provides two scenes with three and five levels. Bounded raw windows match a separate GeoTIFF reference path; that shared reference decoder is not independent codec implementation evidence.
- Ten pinned upstream BinaryOnly/HCS files exercise collection routing, signed samples and exports; they are software controls, not biological examples. Native PNG requires actual unsigned 8/16-bit grayscale or same-IFD packed RGB, while numeric TIFF also preserves signed/float planes and losslessly promotes packed 1/2/4-bit samples. Source sample preservation is not color-calibration or clinical-accuracy evidence.
- **DICOM WSI:** an explicitly supplied, authorized instance list forms a pyramid only when study/series/frame-of-reference, optical path, plane geometry and calibration agree. Supported frames include raw, qualified baseline JPEG, RLE and JPEG 2000. Unsupported sparse/concatenated layouts, ambiguous frame maps and unqualified transfer syntaxes are rejected.
- **Native WADO exports:** only level-zero TILED_FULL, one optical path/Z, full-width unsigned MONOCHROME2 u8/u16 and native Explicit VR Little Endian delivery, with no declared transforms. `LossyImageCompression=00` is a required metadata declaration, not acquisition-history proof; original stored syntax stays unknown. The 16-frame ceiling and actual JSON/XML/padded-output planning can reject smaller regions before pixel reads, destination authorization or state creation. Existing current source, user-capture and destination checks remain required; RGB, compressed/transcoded, reduced-level and multiplane exports remain unsupported.
- Public OpenSlide `3DHISTECH-1` instances `000009` and `000010` exercise a real calibrated pyramid, including half-pixel origins and image pixels. Larger files in that archive declare baseline JPEG but contain progressive JPEG; the mismatch is rejected, not silently reinterpreted as conformance.
- **DICOM derived objects:** ANN/SR preserve supported coordinate systems, measurements and source references; SEG/parametric maps preserve typed semantic values/units. Standalone patient-coordinate objects can be inspected without claiming alignment to the slide. Model results do not expose raw WSI or parametric-map raster windows as a substitute for image context.
- **OME-Zarr/NGFF:** directory or explicitly authorized anonymous public HTTPS sources; NGFF 0.4/0.5 metadata on Zarr 2/3, axes/C/Z/T, calibration, bounded raw/gzip/zlib/Zstd and qualified Blosc LZ4/LZ4HC/zlib/Zstd with none/byte shuffle or format-2 bitshuffle, transpose, CRC32C and sharded ranges. Independent Numcodecs vectors and two losslessly re-encoded IDR planes verify the new bitshuffle path; those planes are derived format references, not original acquired bitshuffle specimens or whole-volume acceptance. Unsupported codecs/layouts and excessive decoded sizes fail before unbounded allocation. Public objects require strong validators or a complete integrity manifest.
- **H5AD:** indexed dense/CSR/CSC access to `X`, literal same-axis layers or independent `raw/X`, with actual matrix shapes/IDs, libraries, images, observation metadata and full-source windows. Layout-v3 compact payloads and layout-v4 single-chunk, unfiltered implicit and paged/unpaged fixed-array indexes use the bounded readers. Independent h5py controls supplement, not replace, acquired fixtures. Nonempty extensible-array/B-tree-v2 indexes and additional storage semantics remain unsupported; see [the exact profiles](FORMAT_SUPPORT.md#anndatah5ad-and-registered-tissue-images). The separate capped browser-local parser is not the large-file reader. Empty filtered pages are not automatically EOF; page bounds are not full-specimen bounds. Metadata-only matrices do not acquire invented tissue coordinates.

Raw TIFF/OME-TIFF outputs preserve selected numeric channels and recorded C/Z/T, ROI, projection and calibration semantics. They are derived artifacts; original specimens are never rewritten. Display composites and RGB8 pathology features are not raw quantitative channel samples.

## Authority, consent and durability

[SOURCE_AUTHORITY.md](SOURCE_AUTHORITY.md) records the audited host behavior, source policies, network constraints and limits. Widget `_meta`, `ui.visibility`, native resource IDs and restored projects are not independent authority. Privileged model routes use the existing Codex transport exclusion, a private in-flight context, current grants and bounded single-use prepared operations. Unknown hosts fail closed for those privileged routes; no host change is assumed.

Native mount correlation is distinct from actively authorized plugin sources. Project replacement must not reuse the old native file's permissions or allow native reconnect/checkpoint paths to overwrite the replacement. Source renewal, mutation, session close and cancellation fence subsequent reads. A lease cannot detect a permission change the host has not reported.

Model-created or restored regions are **coordinates only**. They cannot manufacture a current user-drawn image capture, silently inspect tissue pixels or reuse an earlier screenshot for another plane/region. Projects strip screenshots and consent and require fresh source authorization. Destination write permission and tissue-image consent are separate conditions.

Private project/job storage is bounded, signed and revisioned. Compare-and-swap, private path checks, hashes and atomic non-overwrite publication prevent accidental replacement and stale claims; they are not a multi-user database. Cancellation must drain children and IO before job slots or recovery claims are reused.

## Scientific interpretation

An H5AD matrix is not automatically raw counts. Unknown scale remains unknown until an explicit, recorded declaration. Count normalization uses whole-assay sizes, never totals over the displayed panel. Source annotations, reference predictions, estimated regions and verified cell identities are distinct. Retain feature IDs, missingness, normalization, graph/null model, seed, correction, reference versions and uncertainty in results.

PUMA/BBBC007 are public specimens with declared selection and annotation coverage, not hidden challenge data. Annotated-only references cannot establish false positives, precision, F1 or panoptic quality for unannotated objects. Spatial pseudoreplication, donor/batch effects and reference mismatch remain limitations even when a numeric implementation matches its reference.

## Evidence and release rules

### Historical 0.1.53 follow-up validation

The results below predate the permissive-only profile. In particular, native HVG/reference/UMAP/t-SNE executions describe the removed engine, not available 0.1.59 capabilities or current acceptance. Later qualification must use the current profile and exact build.

The optional UMAP/t-SNE implementation passed 337 focused tests with three existing real-assay opt-in skips, covering actual native execution, isolated workers and cancellation, guarded SDK calls, source-row artifact application, UI drafts and portable project recipes. These checks do not establish final-package/browser acceptance or independent embedding quality. The pinned scran.js 4.0.9 wrapper uses one native thread; t-SNE initialization is fixed at 42 and UMAP exposes no initialization-seed control. Neighbor counts must stay within the existing deployment cap (at most 50) and below the retained observation count; the actual helper resolves perplexity 30 to 90 neighbors, so that request is rejected without clamping. Optimizer progress is not a durable checkpoint: resumed work restarts the optimizer after authenticated preprocessing recovery.

The global Geary addition passed 94 tests across three existing suites, with no skips, plus a full nonincremental typecheck. Hand-computed references cover irregular graphs with C greater than two, the complete binary-path permutation space, missingness and retained isolated nodes. The actual guarded SDK route verifies generated H5AD values, source/matrix/row provenance, idempotency and denial after read authority is withdrawn. Rendering distinguishes zero, values above two and an unavailable statistic. These are controlled numerical and authorization checks, not biological, packaged-browser or installed-host qualification.

Native ASAP import passed 199 tests across seven parser, UI, default-SDK and project suites, with two existing missing-real-fixture skips. These controls cover original geometry and group colors, strict XML/resource rejection, cancellation without a partial index, source-bound queries, and fresh project reparse. Indexed registration now uses semantic source identity, even for XML supplied under a misleading `.h5ad` filename, and retains the read-revocation latch until guarded renewal. Current image checks cannot silently renew an indexed source. The tests use explicitly controlled XML, not native-ASAP GUI, real-specimen interoperability or installed-host acceptance.

The HDF5 format-control object was provisioned create-only and independently read back at exactly 137,248 bytes with SHA-256 `099d18fc0ccfa4a3812b2a4cfcde64c6d0a4d6c248750cbb6f3068c719c598c1`. All 137 targeted HDF5 checks and 30 managed-fixture contract tests passed; ten unrelated fixture cases were excluded from the targeted HDF5 run. The combined HDF5/embedding source passed the full nonincremental plugin typecheck after three test-only buffer annotations were corrected. The Linux opening producer requires that pinned native-verified control through the existing Applied download API; no h5py installation, test-data generation or public fallback occurs in CI. At `a6623f3ed014`, its actual source/integration report confirms the control's numeric, string, matrix and registered-pixel test passed after checking the exact size and hash. All 35 bounded layout-v4 index cases also passed. These are consumed, pre-generated software controls, not biological specimens or publication qualification.

The six unchanged public 10x original JPEG2000 ranges were provisioned create-only after explicit approval: all 2,647,713 bytes matched their canonical hashes on independent, ETag-bound readback. The CI consumer uses the existing authenticated managed-download path with fixed object keys, no public fallback and the unchanged 30-second transfer supervision. Its 91 offline tests passed with no skips. The subsequent Linux run at `a6623f3ed014` consumed all six managed ranges and passed all 88 numeric/codec tests, including 15 reference decodes and four supervision controls. This qualifies that source-level decoder path, not fresh upstream range responses, an intact reconstructed slide or integration into the packaged viewer. See the [exact fixture scope](scripts/NUMERIC_CI_FIXTURE.md).

The corrected paired-control fixture now includes the RGB classification required by the real GeoJSON parser. All 19 packaged-host fixture regressions passed, and the next full browser run advanced beyond that failure before encountering a separate spatial-import acknowledgement failure. Local Windows-state regressions passed 21 cases with five Windows-only skips. The subsequent native Windows security job passed 249 tests with 11 skips. The archive-only Windows build also completed with verified source provenance, although later contract tests failed; neither result makes the whole Windows plugin job pass.

The combined source passed the full nonincremental plugin typecheck after correcting one density-test literal type. Reusing identical private numeric validators also preserves the complete 67-tool discovery response: two normal-settings cache compilations, with only that source substitution, produced identical 495,750-byte pre-ToolSchema SDK envelopes. No fields were ignored, no scientific operations or forced GC ran, and both discovery children drained below 256 MiB. This is discovery-contract equivalence, not raw-stdout, whole-slide memory, clean-package or installed-host qualification.

At clean commit `7b79873836a0`, the documented frozen Slide install and normal bundle command passed on Node 22.23.2 without tracked dependency changes or archive/dirty-build overrides. Git provenance records all 39 runtime files; the complete package and its provenance were independently rehashed. The full Slide source suite passed 3,444 tests with 119 existing conditional skips. Shared-platform typechecking passed; the core/shared and slide suites passed 251 and 298 tests respectively, with nine and 31 existing skips. All observed owned processes drained, and source, package and Sequence non-mutation guards stayed unchanged. These are local source/build results, not current-head browser, Windows-native or optional numeric-codec qualification. No Sequence source, release hash, build or publication was changed by this validation.

### Last completed CI result

At `a6623f3ed014`, [Buildkite 6634002](https://buildkite.com/openai-mono/monorepo/builds/6634002) is **failed**, with 50 passed jobs, four effective failures and eight unexecuted jobs. A superseded automatic mandatory-check attempt accounts for one additional raw failure. The opening parent passed 3,434 source/integration tests with 134 conditional skips, including all five packaged integrations, and all nine browser-opening cases without retries, failures or skips. Its source-bound handoff through the unchanged canonical normalizer also passed. These are controlled packaged-host tests, not installed-host acceptance.

The full child actually selected **34 cases**, despite its stale 32-case display label. It passed the real pathology and Visium workloads, then failed the ordinary UI/agent paired-control scenario: the independent model route for `import.spatial` returned `applied:false` because its requested state was superseded before the frame was presented. The run ended after 652.505 seconds with **two passed, one failed and 31 not run**, without retries or flakes. All 30 controlled cases, including UMAP, t-SNE and command-palette parity, were unexecuted. The retained failure has an error/source excerpt but no raw command receipt or frame timeline; the exact triggering state update is not observed evidence. A subsequent delayed-frame component regression reproduced the same supersession error. Its source fix still requires an exact-head browser result; the controlled reproduction does not reconstruct the missing CI frame timeline.

The other failures were three files over the 150,000-byte repository limit, 16 Windows contract failures, and the Sequence Viewer generated-bundle check. The Windows build phase succeeded with authenticated archived source and `releaseEligible:false`, then its contracts passed 244 and failed 16: eight Git null-device configuration failures, six file-symlink setup failures and two POSIX-permission assumptions. Its later typecheck and source suite did not run. Linux numeric source qualification passed all 88 tests using the six original managed ranges; the decoder remains unintegrated. Windows shared-platform security passed separately.

The follow-up CI-test repairs split the oversized files without dropping assertions or cases, retain POSIX file-symlink coverage, and use genuine Windows directory junctions plus explicitly controlled metadata/error checks. The spatial-import fix follows only the command's parsed spatial payload through its own source initialization and presented frame. It covers repeated same-object/same-window imports and rechecks source ownership and the original deadline at the final acknowledgement boundary; ordinary lazy refreshes and image/no-target rejection remain unchanged. Local validation of the combined repairs passed the full nonincremental typecheck, all 260 contract tests and 3,490 source tests with 119 existing conditional skips. Restoring the original assertion on the acknowledgement's embedded layer snapshot was followed by another typecheck and all 192 tests in the two affected existing suites, without skips. Every observed owned process drained; the existing package and guarded Sequence files stayed unchanged. No new local bundle was built. Native Windows and repository/browser CI still need to verify these repairs.

The newer base contains the separately merged [Sequence 0.1.41 release](https://github.com/openai/openai/pull/1342622), but its generated server still fails the frozen-rebuild check. Sequence directly consumes the shared file/state implementations changed here; an isolated before/after rebuild has not attributed the entire bundle difference. The current-base mismatch is observed, not merely predicted from the earlier 0.1.40 checkout. Sequence source, version, managed hashes and publication remain unchanged; any sibling artifact refresh is held as a separate scope decision.

The earlier `31106d34900c` [build 6632131](https://buildkite.com/openai-mono/monorepo/builds/6632131) remains a failed historical result. It passed the nine opening cases but stopped full acceptance at the malformed segmentation fixture, failed Windows checkpoint/provenance checks, and could not acquire numeric ranges after an immediate `ECONNRESET`. Later source fixes and successful intermediate checks do not retroactively qualify that run.

### Large-file qualification

The `4bf96839a357` large-slide run used one actual SDK initialize and one tools/list (67 tools), then the original 7,259,131,673-byte HTA acquisition. A separate reference read validated all 37 expected pixel samples. The actual packaged server completed 26 samples before its max-RSS guard observed 268,550,144 bytes; exit peak was 268,566,528 bytes. The 256 MiB limit is 268,435,456 bytes. The failed prefix does not establish the full-workload peak or imply that a small fixed saving would suffice. The last completed sample was `L0-C1-top-left-origin`; `L0-C2-top-left-origin` failed and neither authority-denial case ran. Both child processes drained. This remains a failed qualification, separate from the smaller browser specimens.

Some local temporary diagnostic directories were subsequently removed. Historical outcomes above were inspected during execution, but missing temporary files are not current reproducible artifacts. Fresh qualification must retain a new exact-package receipt; a byte-identical package reconstructed from the retained runtime inventory does not reconstruct a lost run receipt.

A fresh independent tifffile reference rehashed the complete original and produced 72 cases across eight levels and three channels: 69 distinct regions, including explicitly labeled center and clipped-edge cases. Oracle-only reads totaled 55,334,093 bytes and native peak RSS was 61,669,376 bytes. The full-file hash is counted separately. This is a new reference workload, not a reconstruction of the missing 37-case receipt, a cold-cache measurement, or a passing packaged-server run.

The subsequent once-only SDK run used the clean `7b79873836a0` package, ordinary negotiated roots and unchanged resource limits. It discovered all 67 tools, rejected a new open with no readable roots without source reads, and matched all nine planned L0 center/right-edge/bottom-right channel tiles. The next level did not qualify: observed native max RSS reached **269,271,040 bytes**, above the **268,435,456-byte** cap. The result is **9/72 matched and qualification failed**; the remaining 63 comparisons and fabricated/closed-resource denials did not complete. Original-file identity, pinned runtime bytes and external dependency-resolution snapshots remained unchanged, and all three owned processes were confirmed absent after cleanup. The retained failure records an observed memory maximum, not a full-workload or final-exit peak. No retry, forced GC, profiling or limit change was used. The smaller passing specimens and independent oracle do not supersede this failure.

### Earlier evidence and limitations

Build provenance records source revision, dirty state, tree digest, semantic registry and the packaged runtime inventory. The opening harness rechecks actual bytes before launching real stdio MCP. Its host is `packaged-test-host`, not an installed Codex task. `dist/build-provenance.json` is the attestation, excluded from its own digest and not required for execution.

Specimens remain in ignored, integrity-verified caches. Generated TIFF, matrix, geometry and million-point fixtures test software boundaries, not biological realism or specimen throughput. Fresh-process timing does not imply cold OS cache; sampled heap/RSS does not imply GPU memory or guaranteed instantaneous peaks.

The matrix-provider numerical result is separate from default-server memory qualification. Three recorded actual-package runs exceeded the unchanged **256 MiB** guard: **269,336,576 bytes (256.9 MiB)** after an earlier operation-local allocation change, **269,893,632 bytes (257.4 MiB)** at `fd6fb6d1d75f`, and **268,697,600 bytes (256.25 MiB)** at `ca8f1dc1e24e`. Those failed runs did not reach complete expression hashes and the remaining rejection checks; subsequent source changes do not convert them to passes.

At `9dde573608a1`, the same count-matrix qualification passes at **263,454,720 bytes (251.25 MiB)** peak child RSS with 81 tool calls, including all 2,095,232 count values, row totals, physical feature order, and stale/cross-cursor/revoked-source rejection. A separate raw-axis run passes at **263,880,704 bytes (251.66 MiB)** with 87 calls, checking all 2,095,232 raw values plus 1,024 reordered X values and 91 duplicate raw symbols. Both retain the 256 MiB RSS limit, 45-second deadline and existing call/read/decode budgets, verify all 39 actual runtime files, and drain the child before completion. SDK/reference memory is in a separate parent process. Service-private fingerprint scratch reuse preserves every physical verification read; sparse paging reuses only operation-owned arrays. These bounded derivative runs do not establish whole-specimen, browser, p95 or installed-host performance.

At the same head, local checks passed **2,919 Slide tests** with 104 optional skips, **1,498 shared-platform tests** with six optional skips, all **137 release contracts**, typechecking and clean-bundle inventory validation. These counts describe that historical build, not later changes. The current OME-TIFF source follow-up passed **772 tests**, with no failures and six existing optional-fixture skips; its typecheck, formatting and seven independent review slices passed. A separate root-run PNG regression passed 67 tests with six optional-fixture skips. Those suites overlap and are not additive; neither establishes a new clean-package memory result.

The bounded Node OME-Zstd source at `d009db11478d` passed **224 tests** in four focused suites, with five existing conditional skips; both pinned imagecodecs software controls executed. A subsequent source-PNG binding fix passed four generated 8/16-bit scalar/native-RGB readbacks with controlled range-read authority, not actual MCP/host authorization. The native WADO export source at `d7c7650429de` passed **134 tests** with no skips, including 44 default-server SDK cases. The latter include exact generated u8/u16 export pixels and a 16-frame maximum-escaping OME request rejected before any frame read, destination authorization or private-state operation. The two committed source freezes passed typechecking, formatting and independent review. These scoped source-level results are not a combined package/browser result, acquired native-16-bit WADO qualification or permission to publish.

At `304f86843b50`, [CI build 6627048](https://buildkite.com/openai-mono/monorepo/builds/6627048) passed all **2,916 source/integration checks** with 127 conditional skips and **all nine opening browser cases**, including actual mouse tissue rendering. The build nevertheless failed: all three automatic attempts timed out in the paired suite. A stale matrix-fixture filename and an acceptance helper requiring absent optional render counters caused ten completed failures in each of the first two attempts and eight in the third; each attempt also interrupted one case and left others unstarted. The subsequent source fixes correct both assumptions and revalidate readiness after the final animation frames within the original deadline. They do not retroactively change that failed receipt. Earlier [build 6626252](https://buildkite.com/openai-mono/monorepo/builds/6626252) passed seven and failed two opening cases; those failed receipts remain retained. Each subsequent fix needs its own exact-head result. The canonical host normalizer is unchanged and all nine required opening cases are retained; local canonical-host preparation remains unavailable.

The acquired HTA-MELATLAS1 original is 7,259,131,673 bytes. At `9dde573608a1`, its 12 completed L0–L3 tile comparisons passed before the actual plugin child reached **268,484,608 bytes** RSS, 49,152 bytes over the unchanged 256 MiB guard. Remaining levels, edge tiles and authority checks did not complete. The display encoder now avoids an unnecessary full RGBA copy and waits for compression to drain on failure/cancellation, but that source fix is not proof that the original specimen now meets the memory limit.

The shared plugin contains an [unintegrated numeric JPEG2000 source prototype](../scientific-viewer-platform/native/jpeg2000/README.md) and pinned build/source notices. Its macOS source qualification passed 53 numeric and 35 existing codec tests with no skips, including six original UInt16 blocks. Linux CI at `a6623f3ed014` subsequently passed all 88 tests with six authenticated original-range downloads and no direct upstream fallback. It is still not registered, packaged or enabled in the viewer. With artifact inputs absent, 26 numeric runtime/watchdog tests skip; default-suite success cannot satisfy that gate. Product packaging, OME/DICOM adapters and original 16-bit DICOM interoperability remain unqualified. The existing format inventory is unchanged.

The historical 0.1.53 development runtime copied scran.js 4.0.9's compiled WASM. Its MIT JavaScript wrapper did **not** cover all statically linked components: igraph is GPL-2.0-or-later, and complete immutable native source provenance was unavailable. Version 0.1.54 removes that runtime and its two dependent workflows. The new emitted-input license gate does not convert historical native execution into release acceptance or publication approval.

The bounded paired-control suite defines **30 browser groups and 132 required UI/model pair obligations covering 53 of 100 registered UI action IDs**, including matrix selection, computed-result application, project recovery, cross-library switching, cancellation and same-job resume. All earlier groups and obligations remain. New cases pair real-Visium palette zoom and actual UI/agent HVG submission for None, UMAP and t-SNE; each embedding is checked against its own committed source-bound artifact, not another run's layout. Five stale/mismatched application cases require actual rejection and unchanged current results. The focused parity contracts passed 114 tests with no skips; the combined plugin typecheck passed. These are source-defined obligations and contract checks, not executed browser pairs or complete 100-ID acceptance. Other IDs have scenarios in the broader manifest, whose execution remains required. The strict bounded assessment under `test-results/opening/paired-controls/` is an output location, not a current passing result, and does not replace full-request or installed-host acceptance.

The two-library acceptance control combines the unchanged original 684-row H&E and 704-row coronal inputs, their original images/coordinates and two exact gene vectors. It is explicitly a derived software control, not a joint assay or a newly acquired biological example. A source-level SDK check verifies all rows, selected values and decoded image pixels; it does not establish packaged browser behavior. Lifecycle checks retain actual native workflow rows and artifact hashes, distinguish canceled work from interrupted work resumed as attempt two, and wait for actual child-close observations. A held callback or received process-close event is not proof that every underlying native I/O operation physically drained.

Source now defines all six required scripted user tasks, including scientific-result inspection and fresh-process project save/reopen, plus observation of the actual project-loading announcement. The keyboard/task scenario uses a new controlled real-Visium session with simulated fixture authority and unmeasured action-only memory. These producers are not executed browser, installed-host or human-usability evidence.

Before removing draft status, reconcile the revised-scope manifest with final head-bound integration, scientific and acceptance reports, retaining unresolved items explicitly. Publication additionally requires the plugin publishing flow, dependency/source review, current installed-host verification and a separate human publishing decision. No unit-test count substitutes for those gates.

SHA-256: f64efa7a4415c57648ee0f21cfbc2bea7c859c55ed9e496615c8f68fe6c51ec3