← Files Slide ViewerARCHIVED FILE
FORMAT_SUPPORT.md
63 KB · Sep 30, 2026 · 23:02 UTC
# Format support and qualification boundaries
This is an inventory of the **0.1.59 release-candidate source**, not a claim that every file with a recognized extension works. Layout, transfer syntax, sample type, source authority and operation limits all matter. Limits below are implementation ceilings, not limits of the underlying file standards or measured performance guarantees.
Only inaccessible proprietary formats are outside the requested format scope. Unsupported **public** codecs, layouts and transports remain gaps; lack of a fixture does not turn them into access exclusions. See [implementation status](IMPLEMENTATION_STATUS.md), [source authority](SOURCE_AUTHORITY.md) and [requirements](CAPABILITY_REQUIREMENTS.md).
## What the evidence establishes
| Evidence | Meaning |
| ------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Source implementation | The named reader, writer or registered adapter exists. This alone does not establish successful execution. |
| Generated controls | Known pixels/geometry or independently generated codec vectors test implementation boundaries. Sparse multi-gigabyte controls are not acquired specimens. |
| Independently acquired objects | Unmodified, hash-pinned public bytes were exercised. Distinguish scanner/acquisition data from another project's original automated-test objects. One supported object does not qualify its entire family. |
| Packaged/controlled MCP | Actual runtime bytes and protocol execution in a controlled harness. Simulated test authority is not real user consent or desktop-host acceptance. |
| Installed host | Requires the exact installed package, authenticated source, actual rendered result and applicable action/export evidence. This document does **not** establish that gate. |
Source and test links below refer to the source checkout. Specimen binaries and qualification receipts live in ignored caches; an optional test's default skip is not a successful qualification. Historical receipts must be reconciled with the final source/runtime hashes before release acceptance.
## Entry points and transports
| Surface | Current path | Boundary |
| ------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Local image files | `.svs`, `.tif`, `.tiff`, `.h5ad`, `.dcm`, `.dicom` through `slide.open_from_chat`; an explicit DICOM instance list through `slide.open_dicom_series`. | Current workspace permission and issued source/revision are required. A filename, URI, logical native-session ID or matching dimensions is not a grant. Companion files are not discovered by scanning directories. |
| Browser-selected TIFF/overlays | Browser-owned `File` readers and the corresponding UI import. | This is a separate parser/access path, not proof that a native or remote adapter supports the same file. It does not authorize agent filesystem reads. |
| OME-Zarr stores | `slide.open_ome_zarr` over an authorized directory or explicitly authorized anonymous public HTTPS object prefix. | Not a ZIP/kerchunk/cloud-credential adapter. Public S3 HTTPS objects can use the public provider; private authenticated object stores are not implemented here. |
| DICOMweb | Bounded QIDO/metadata/derived-object reads and `slide.open_dicomweb_wsi` for explicitly selected WSI instances, with actual frame assembly into viewer tiles. | Anonymous public HTTPS only; strong per-resource validators or a complete caller-supplied metadata/frame SHA manifest. Portable projects require complete SHA pins; annotation/measurement exports use verified metadata without remote pixel reads. No arbitrary `BulkDataURI`, inferred URL authority, automatic full-resolution coverage or authenticated clinical endpoints. PNG/numeric exports require the strict [native WADO profile](#dicom-derived-objects-and-web-operations) below. |
| DICOM upload | Explicit `slide.prepare_dicom_upload` then `slide.submit_dicom_upload`. | A separate consequential operation; no automatic POST from viewing/import. No live endpoint upload was performed for qualification. |
| Processed tables/annotations | Explicit overlay, scientific-layer, analysis-source or pathology-reference import, depending on the schema. | CSV/GeoJSON are not universally interchangeable with primary slides. Column roles, joins, units, image association and coverage must be supplied or established by actual source metadata. |
The network provider checks current permitted destinations, HTTPS, DNS/TLS/proxy behavior and source validators. It does not claim an atomic snapshot of an entire mutable remote store. See [object-source authority](src/server-source-authority.ts), [DICOM tools](src/server-dicom-tools.ts), [OME-Zarr tools](src/server-ome-zarr-tools.ts) and [workflow imports](src/server-analysis-workflow-imports.ts).
## TIFF, Aperio SVS and OME-TIFF
| Profile | Implemented layout/sample path | Explicit limits and remaining gaps |
| ----------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| TIFF/SVS pyramids | Classic TIFF and BigTIFF; bounded directory/tile ranges, main IFD/SubIFD traversal, source orientation and per-level geometry. Native SVS includes Aperio JPEG and JPEG-2000 compression tags `33003`/`33005`; the pinned OpenJPEG backend is packaged separately. | A valid TIFF container does not guarantee a qualified codec. Old-style JPEG and unsupported JPEG sample precision are rejected. Very large offsets are preserved/address-checked; generated 16-GiB address-space tests do not establish real 16-GiB specimen throughput. |
| Non-OME local/browser TIFF | Grayscale/RGB/RGBA display, signed/unsigned scientific samples and floating-point intensity handling; qualified YCbCr conversion, including bounded subsampled LZW/YCbCr. | Display conversion is not a raw quantitative export. The ordinary browser path accepts 1, 3 or 4 samples per pixel; JPEG requires 8-bit samples. Its decoder/limits must not be inferred from the richer OME reader. |
| Single-file OME-TIFF | Explicit OME-XML image/scene and C/Z/T plane mapping, main/SubIFD pyramids; scalar channel planes or one packed channel group with planar configuration 1/2. All eight TIFF orientations normalize to top-left and must agree within each scene. Physical XY units and source-bound windows; raw min/max/mean/sum C, Z or T projections remain separate from display composites. | Up to 32 scenes, 128 levels, 64 channels (16 active display channels), 4,096 Z/T indices and bounded plane/directory work. No automatic multi-file OME companion resolution. Missing/external planes, XML entities/DOCTYPE, incompatible sample metadata, ambiguous pyramids and unqualified transforms/predictors are rejected. |
| Explicit OME-TIFF collections | `slide.open_ome_tiff_series` resolves actual UUID/member/IFD/C/Z/T mappings across authorized TIFF originals and an optional supplied companion XML. Scene selection, quantitative exports and complete portable recipes preserve every original member and topology. | At most 16 total originals, 32 scenes, 4,096 directories, 65,536 sample planes and 1 MiB XML. No directory discovery, inferred companions or physical IFD aliasing across scenes. Every member needs current authorization; a fresh model read can renew the five-minute lease only within its immutable 30-minute lifetime. Restoring a recipe does not restore grants. |
| OME compression | Raw `1`, LZW `5`, PackBits `32773`, qualified 8-bit baseline JPEG `7`; Deflate `8`/`32946` only with the bounded inflater. Node single-file display, numeric and eligible source-PNG readers, plus explicit-collection adapters, inject a separate bounded Zstd `50000` decoder. Predictor/sample compatibility and endian handling are checked. | Browser and reader factories without the Zstd backend still reject `50000`. Old-style JPEG, non-baseline JPEG and JPEG-2000 remain OME gaps even when a different SVS decoder supports JPEG-2000. Each physical block is bounded to 32 MiB; allocation guards are not whole-process RSS guarantees. |
Non-OME TIFF display grids are independent of storage strips or rectangular tiles. Large coarsest images gain derived display levels using nearest source-pixel centers and exact per-axis image transforms; these levels are labeled as sampled display data and never become stored IFDs or eligible native export levels. Each request preflights all required physical blocks and planes, with 32 MiB ceilings for encoded input, declared decoded work, and raster/output allocations, and at most 4,096 blocks. Requests that cannot fit remain unavailable. Existing generic codec semantics are unchanged; these planned-work bounds are not process-memory guarantees or new protection against malformed compressed-stream expansion.
OME `Pixels Type` must agree with the TIFF samples: bit1, Int8/16/32, UInt8/16/32, Float32 or Float64. The broader TIFF admission predicate does not establish OME UInt2/4 or Float16 support. Photometric profiles are WhiteIsZero/BlackIsZero/RGB and qualified JPEG YCbCr; planar YCbCr is not enabled. Predictor 2 requires integer8/16/32; predictor 3 requires compatible floating samples; JPEG requires predictor1/UInt8. Public acquisition/control evidence includes UInt16, Int16, Float32 and qualified 8-bit JPEG. Generic non-OME GeoTIFF intermediate allocations do not inherit the OME bounded-decoder proof.
**Evidence:** the full 132,565,343-byte `CMU-1-JP2K-33005.svs` (46,000×32,893; three levels) exercises real tissue JPEG-2000 tiles. Its exact source/hash is in [opening fixture pins](scripts/prepare-opening-tests.mjs), with [packaged opening checks](integration/packaged-opening.test.ts). A real 722,911,158-byte Leica OME file exercises two scenes with three/five levels and actual selected windows. Its comparison uses a separate GeoTIFF reference path, not an independent codec implementation. Ten pinned upstream BinaryOnly/HCS files exercise collection routing and exports; these are original upstream software controls, not acquired biological specimens. Additional SHA-pinned public TIFF/OME cases cover endian/sample/color and negative cases in [scientific TIFF regressions](src/slide/tiff-scientific-regression.test.ts). Generated plane/orientation/large-offset controls remain separately labeled.
**Zstd evidence:** two unchanged, hash-pinned upstream imagecodecs TIFF software controls (grayscale strips and tiled RGB) match a separate `zstddec/stream` codec oracle using the same GeoTIFF parser. Generated OME controls cover numeric samples, predictors, byte order, local display/numeric reads and explicit-collection exports. Four additional generated [source-PNG readbacks](src/slide/local-source-png.test.ts) preserve selected C/Z/T scalar samples and native planar RGB order at 8/16 bits under controlled range-read authority, not actual SDK/host authorization. These are not biological OME-Zstd acquisitions or browser/package/installed-host qualification. See the [bounded Node decoder](src/interop/bounded-node-zstd.ts), [original-control tests](src/slide/ome-tiff-microscopy.test.ts) and [default collection tests](src/server-ome-tiff-tools.test.ts).
The complete 7,259,131,673-byte HTA-MELATLAS1 H&E original was acquired and independently referenced. At `7b79873836a0`, a fresh clean package discovered all 67 tools, rejected an opening request without readable roots, and matched nine L0 center/edge samples across all three channels. It then exceeded the unchanged 256 MiB child RSS ceiling, with an observed maximum of 269,271,040 bytes. The remaining 63 of 72 planned pixel comparisons and fabricated/closed-resource checks did not complete. This is a failed qualification, not multi-gigabyte performance support; no retry or memory-limit increase converted it into a pass. The independent 72-case reference is not a substitute for a successful packaged run.
Sources: [local TIFF/SVS/DICOM provider](src/slide/local-svs.ts), [browser TIFF](src/slide/browser-tiff-slide.ts), [OME metadata/planes](src/slide/ome-tiff-microscopy.ts), [bounded OME codecs](src/slide/ome-tiff-bounded-decoder.ts), [OME tests](src/slide/ome-tiff-microscopy.test.ts), [shared TIFF engine](../scientific-viewer-platform/src/slide/scientific-slide-tiff.ts).
## AnnData/H5AD and registered tissue images
| Profile | Implemented | Rejections or qualification boundary |
| ------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Indexed HDF5 storage | HDF5 signature at file offset zero; superblock versions 0, 2 or 3 with eight-byte addresses/lengths; contiguous storage, layout-v3 compact numeric/fixed-string payloads and v1 chunk B-trees. Layout-v4 single-chunk, unfiltered implicit and fixed-array indexes, including paged fixed arrays, use exact maximum-dimension strides and checked metadata. Deflate, shuffle and Fletcher32 filters. | Nonempty extensible-array and B-tree-v2 chunk indexes, partial-edge filter flags, fill-value synthesis, other filters, user-block placement and external/virtual layouts remain unsupported. Empty datasets do not imply nonempty index support. Compact payloads must match their exact shape, dtype, message and source bounds. Integer addressing, metadata checksums and existing range/decode budgets remain enforced. |
| Numeric/string datasets | Signed/unsigned 8/16/32/64-bit numeric storage and Float32/64; fixed strings and supported variable-length strings. | Int64/UInt64 values outside JavaScript's exact integer range reject; numeric Float16, complex/compound/object types are not silently converted. Dataset shape/heap/string metadata is bounded. |
| AnnData expression/spatial data | Dense, CSR or CSC `X`, literal same-axis `layers/<name>`, and `raw/X` with independent `raw/var` features and the actual common observation index. Gene/observation IDs, supported observation fields, real source embeddings and spatial coordinates; matrix-bound catalogue, expression and spatial-window pages. Multi-library selection requires explicit membership/association. | No feature intersection, `/var` fallback for raw, or count-scale inference. A missing/ambiguous selected symbol clears on a matrix switch; explicit source-bound physical columns disambiguate duplicates. Unsupported storage/encodings, legacy flat `raw.X` and ambiguous multi-library membership remain unsupported. Absent spatial coordinates are not invented; matrix-only analysis does not become a tissue image. |
| `uns/spatial` images | Explicit library plus `hires`/`lowres`; H×W×3/4 UInt8 or normalized Float32/64 RGB(A), positive source scale factor, optional actual spot diameter. The indexed reader reads bounded image rows/tiles. | Embedded previews are not missing raw channels or external full-resolution scans. The legacy whole-file image path is limited to 64 MiB input and 4,194,304 pixels; do not apply that limit to the indexed source path or claim unlimited indexed images. External-image associations require a separately authorized image and explicit registration. |
Indexed operation defaults: 8 MiB maximum range/chunk, 32 MiB source bytes, 64 MiB decoded work and 15 seconds. Pages are at most 4,096 observations, 512 gene names, 16 expression genes/65,536 values or 16,384 matrix entries. These are per-operation bounds, not an assertion that the UI renders every observation at once or that source-byte size bounds expanded memory.
The matrix catalogue inspects at most 64 literal layer names plus `X` and `raw/X`, in pages of at most 16 entries; unsupported entries carry explicit reasons. Matrix revisions bind the actual file revision, axes, layout and selection, but are not whole-file hashes or grants. Layer providers and lazy caches are separate, cross-matrix continuations reject, and a layer cannot inherit another matrix's `obs/total_counts` denominator. Complete-assay normalization reads the selected matrix under the existing budgets. A 64-observation derivative of real PBMC3k data exercises all 32,738 genes in CSR/CSC counts and explicitly derived log matrices against independent full-value hashes and row totals; that bounded derivative is not whole-PBMC, spatial-image or installed-viewer qualification.
Indexed opening loads tissue, coordinates and the gene catalogue without choosing or reading a gene automatically. Explicit or restored gene selections use sequential expression pages of at most 256 observations, never silently truncate a vector, and retain each page's source identity and read statistics. A complete assembly allows at most 16 pages, 4,096 observations and 65,536 values, within one 15-second caller deadline and a three-operation aggregate allowance (at most 96 MiB read, 192 MiB cumulative decoded work and 1,536 chunks; lower advertised source limits apply). Readers advertising `expressionReadLimits: "v1"` enforce the remaining allowance inside each operation before I/O; older readers still require a full native allowance to be reserved before dispatch. No operation or aggregate ceiling is increased. Aggregate receipts are explicitly client assemblies, not native pages with inflated statistics. Cancellation or any invalid page prevents a partial vector from being committed and leaves a previous complete selection intact; a transport that ignores cancellation may still finish its bounded in-flight read. The real 684-observation H&E sample and independently hashed Slc17a7/Gad1 vectors exercise this path. These limits do not establish process/GPU memory or whole-assay throughput.
**Evidence:** pinned real Squidpy mouse data include the 27,856,369-byte 704-spot coronal sample with its 600-pixel fluorescence preview and the 94,259,482-byte 684-spot H&E sample with 18,078 genes. The separate 49-observation upstream software-test fixture is regression coverage, not a biological demo. [Opening tests](integration/packaged-opening.test.ts) distinguish these from generated TIFF controls. Indexed dense/CSR/CSC/storage negatives are in [indexed-source tests](src/slide/h5ad-indexed-spatial-source.test.ts); image/library tests include generated contracts and must not be described as independently acquired cross-library qualification.
The layout-v4 [generated control](scripts/chunked-hdf5-managed-fixture.json) was independently written and reopened with h5py 3.15.1/HDF5 1.14.6. Its numeric/string spans, matrix pages and registered pixels exercise the actual indexed-reader dependency. The 137,248-byte control was uploaded create-only and independently downloaded with its full SHA-256 verified. CI hydrates this immutable internal object and makes the reader test mandatory; it does not install h5py, regenerate the file, substitute a biological example or fall back to a public download. The exact `a6623f3ed014` [opening job](https://buildkite.com/openai-mono/monorepo/builds/6634002#01a02cc3-bdd6-44c0-a6e2-c02bee0e5ee0) passed that control test, including its size/hash checks and actual reader calls, plus all 35 bounded index cases. This does not establish browser-local support or acquired layout-v4 specimen qualification.
Sources: [HDF5 range reader](src/slide/h5ad-indexed-reader.ts), [matrix pages](src/slide/h5ad-indexed-matrix.ts), [spatial/annotation pages](src/slide/h5ad-indexed-spatial-source.ts), [indexed tissue](src/slide/h5ad-indexed-tissue-source.ts), [legacy tissue parser](src/slide/h5ad-tissue-image.ts), [operation limits](src/slide/h5ad-indexed-limits.ts).
## Processed spatial tables and GeoJSON
| Input | Implemented semantics | Boundary |
| ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| CSV/TSV processed cell/transcript tables | Explicit cell IDs, XY, optional area/labels/QC; actual transcript IDs, gene, XY, cell assignment and optional quality. Explicit units and missing/unassigned tokens; proper quoted-record parsing. | No invented transcript positions, cells or segmentation. Required coordinates, duplicate/missing joins, unsafe/nonfinite numbers and undeclared missing tokens reject. Zero is a measured value, not missing. This is not a raw Xenium/CosMx instrument decoder. |
| Region counts + morphology | Explicit region-ID join, declared gene/count columns, actual morphology/QC and optional library sizes; retained normalization declarations. Workflow source import also recognizes `.csv`, `.tsv`, `.txt` and their `.gz` forms for the corresponding bounded downstream reader. | Not every vendor export is automatically recognized. Default processed-analysis import accepts at most 16 MiB/table; its standalone core parser allows 32 MiB. Both retain the 256-column, 64-mapped-gene and declared row/value budgets; whole-assay streamed workflows have separate limits. This is not raw GeoMx decoding. |
| GeoJSON overlay/entities | Feature/FeatureCollection or supported Point/MultiPoint, line, polygon/multipolygon and bounded geometry collections. Source feature IDs, multipart identity, holes, explicit classes/entity kinds and qualified observation joins are retained. | Polygon count is not cell count; supplied classifications are not verified cell types. The ordinary parser is a bounded whole-object path, not automatic million-object LOD. Generic overlay bounds include 10,000 geometries, depth 8 and 65,536 total positions. Persistent indexed query/import has its own contract. |
| Native ASAP XML annotations | Explicit `kind: "asap-xml"` scientific-layer import of UTF-8 XML: Dot, PointSet, two-endpoint Measurement, Polygon and four-corner Rectangle. Original ordinal IDs, repeated/empty names, group hierarchy/attributes and supplied/inherited colors survive indexing, queries and project recipes. | At most 32 MiB XML, 100,000 annotations, one million coordinates and 10,000 coordinates per entity including closure. Unsupported Spline/None, malformed geometry, ambiguous groups, namespaces and DTD/entity declarations reject the complete import. Level-zero pixel coordinates belong to the XML source; image binding and calibration must be declared and verified separately. This is not native ASAP XML export, instrument segmentation, or a qualified native-application round trip. |
| Pathology reference polygons | Authorized source GeoJSON; explicit source/ROI coordinate space, class mapping, overlap policy and annotation coverage, then pixel-center rasterization. | A model-provided mask is not authenticated truth. Partial reference coverage cannot establish false positives, precision, F1 or whole-field PQ/Dice/IoU. |
**Evidence:** processed-table tests are controlled data, not whole vendor-dataset qualification. Independently acquired PUMA tissue/nucleus polygons and BBBC007-derived manual interiors were exercised with their actual image sources; [PATHOLOGY.md](PATHOLOGY.md) explains provenance, conversion, partial coverage and research-only accuracy limits. A generated million-point SQLite workload measures an implementation boundary, not an acquired million-cell/transcript specimen.
Sources: [processed schemas](src/analysis/processed-spatial-types.ts), [table parser](src/analysis/processed-table-reader.ts), [processed tests](src/analysis/processed-spatial-tables.test.ts), [GeoJSON](src/slide/geojson-overlay.ts), [ASAP parser and controls](src/interop/asap-annotations.test.ts), [native ASAP adapter](src/server-scientific-layer-asap.ts), [reference reader](src/server-pathology-reference.ts), [scientific-layer tools](src/server-scientific-layer-tools.ts).
## DICOM whole-slide microscopy
SOP class: VL Whole Slide Microscopy Image Storage `1.2.840.10008.5.1.4.1.1.77.1.6`.
| Transfer syntax | Accepted pixel profile |
| ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- |
| Implicit VR Little Endian `1.2.840.10008.1.2`; Explicit VR Little Endian `1.2.840.10008.1.2.1` | Native unsigned 8/16-bit, interleaved RGB or MONOCHROME2. |
| RLE Lossless `1.2.840.10008.1.2.5` | Qualified unsigned 8/16-bit RGB/MONOCHROME2. |
| JPEG Baseline `1.2.840.10008.1.2.4.50` | Actual 8-bit SOF0 codestream; RGB, MONOCHROME2, YBR_FULL or YBR_FULL_422. |
| JPEG-2000 Part 1 `.4.90` / `.4.91` | Qualified unsigned 8-bit RGB/MONOCHROME2/YBR_RCT/YBR_ICT through the pinned shared OpenJPEG backend. |
BitsStored must equal BitsAllocated; RGB planar configuration must be zero. Public gaps include signed/12-bit samples, MONOCHROME1, native YBR, planar RGB, 16-bit JPEG/JPEG-2000, JPEG-LS, JPEG-lossless/extended/progressive, HTJ2K, big-endian and deflated datasets. A baseline transfer-syntax UID with progressive SOF2 bytes is rejected; it is not silently treated as conforming baseline or supported progressive JPEG.
The WSI profile is **VOLUME + TILED_FULL, one optical path and one focal plane**. No sparse WSI, concatenations or C/Z/T optical-plane selection. LABEL/OVERVIEW/THUMBNAIL are not admitted as this adapter's pyramid levels; that is an implementation limitation, not a DICOM prohibition. Native/BOT/EOT64 indexes are supported with explicit fragment constraints; EOT and qualified empty-BOT fallback require one fragment per frame. Defaults bound reads to 1 MiB, header to 4 MiB, frame to 32 MiB and index to 8 MiB.
An explicitly supplied authorized instance list can form a pyramid only with matching study/series/frame-of-reference, optical/sample identity, calibration and compatible physical geometry. The core allows up to 32 instances; the current default `open_dicom_series` tool accepts at most 16. No directory discovery or invented registration. The local display provider requires compatible axis-aligned transforms; decoded UInt16 samples remain quantitative values, while PNG display uses a stated full-range conversion, not VOI/autoscale.
**Acquisition evidence:** unmodified CC0 OpenSlide `3DHISTECH-1` small-intestine instances `000009`/`000010` exercise a real calibrated two-level pyramid, actual baseline-JPEG pixels, cropped edges and half-pixel origins; `000014` has an additional small-level check. `000005`–`000008` declare baseline but contain progressive frames and are negative evidence. Neither the entire archive nor its full high-resolution pyramid is qualified. Native16/RLE/JPEG-2000/EOT coverage is separately identified as generated controls.
Sources/evidence: [WSI types/limits](src/interop/dicom-wsi-types.ts), [header/layout admission](src/interop/dicom-wsi-header.ts), [codecs](src/interop/dicom-frame-codecs.ts), [pyramid assembly](src/interop/dicom-wsi-series.ts), [acquired-object checks](src/interop/dicom-wsi-real-fixture.test.ts), [series tests](src/interop/dicom-wsi-series.test.ts), [local display tests](src/slide/local-svs.test.ts).
## DICOM derived objects and web operations
Derived readers accept qualified **native Implicit/Explicit VR Little Endian**; writers emit Explicit VR Little Endian. Bounds: 32 MiB/object, 4,194,304 raster pixels and 4,096 frames. Encapsulated derived rasters, big-endian and deflate remain gaps. Roundtrip means supported typed semantics, not byte preservation or all private/unknown attributes. Re-encoded artifacts have new SOP/series identifiers. Retained SR text can remain sensitive: this is **not de-identification**.
| Object | Current semantics | Explicit gaps |
| ----------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| ANN, SOP suffix `.91.1` | 2D pixel/3D-mm points, polylines, polygons, ellipses and rectangles; OF/OD coordinates, one-based OL indices, coded classes/algorithm, optical/Z applicability, Float32 measurements/subsets and CIELab. Verified indexed layers retain analytic ellipses and source annotation identities. | The editable native polygon bridge is not an exact ellipse representation; holes require another representation such as SEG. Alignment still requires verified source geometry, never caller-supplied reference flags. |
| Comprehensive 3D SR, `.88.34` | Bounded TID1500-style CONTAINER/CODE/TEXT/PNAME/UIDREF/NUM/SCOORD/SCOORD3D/IMAGE trees, units/qualifiers, circles, multiple image references and measurement groups without ROI. Verified layer projections retain tracking/content identities and the scope of numeric associations. | Not all SR templates. VERIFIED state, by-reference/unsupported semantic attributes and unqualified auxiliary raster/presentation/real-world-mapping semantics reject. Patient or foreign coordinate frames remain unaligned; a displayed annotation is not the complete report tree. |
| SEG `.66.4`; LABELMAP `.66.7` | Binary continuous 1-bit LSB packing; fractional unsigned8 PROBABILITY/OCCUPANCY with exact maximum fractional value; labelmap UInt8/16 with declared segment IDs. Per-frame/shared derivation evidence, qualified explicit/implicit positions, SLIDE/PATIENT distinction; labelmap palette/ICC retained. | Encapsulated pixel data and unsupported reference/mapping forms reject. Multi-reference SEG may be inspected unbound, not falsely bound to one WSI. ICC retention is not applied color-management evidence; no patient-to-slide inference or unsupported REORIENTED_ONLY mapping. |
| Parametric Map `.30` | Single-component MONOCHROME2 UInt16/Int16/Float32/Float64, including IEEE special values; one shared linear slope/intercept mapping with actual coded units and optional quantity. | Per-frame/multiple/LUT mappings require another implementation. Units do not supply an invented measured quantity. |
| DICOMweb QIDO/WADO | Bounded explicit-study/series queries, metadata inspection and derived Part10 reads; explicit-instance WSI opening with exact syntax/multipart checks, native-grid stitching and calibrated transforms. Complete SHA recipes support portable projects; verified metadata supports annotation/measurement exports, and the native profile below supports PNG/TIFF/OME-TIFF. | At most 16 selected SOP instances and 100,000 metadata/frame resources. The same single-optical-path, single-focal-plane TILED_FULL profile applies. Selection is not whole-series/full-resolution proof. Other remote pixel profiles, installed browser parity and authenticated clinical endpoints remain unestablished. |
| STOW-RS | Actually registered prepare/submit flow; exact endpoint, original SOPs, source revisions, bytes and multipart digest bound to a private 30-second single-use intent. Up to 16 files/32 MiB including framing; unchanged original Part10 uploads. | No external POST or remote stored-byte verification performed. No credentials/cookies/custom headers/redirect/retry adapter. Generic network permission is not upload consent; accepted SOP receipts are not stored-byte checks. Partial/timeout/revoked submissions can be indeterminate and must not silently retry. |
STOW's metadata-only transfer-syntax allowlist is broader than the pixel reader. It permits native LE/RLE and JPEG-family suffixes `.4.{50,51,57,70,80,81,90,91,92,93,201,202,203}` for unchanged-file upload; it performs identity preflight, **not** complete IOD/pixel qualification. This does not add decoder support.
An indexed `dicom-annotation` layer requires an authorized local ANN/SR object and an exact already-opened local or public WSI target. The plugin checks actual Study/Series/SOP/frame/optical/plane references and geometry; borrowed image handles are never minted from saved IDs. Native ellipses retain center/axes for analytic queries and use a bounded, disclosed polygon only for display. MultiPoint annotations retain one source identity. Codes, algorithm/group/tracking identities, exact numeric associations, sparse measurements and missing qualifiers remain inspectable. A nested SR measurement retains its actual TEXT/CODE parent context rather than being relabeled as group-wide; unsupported parent contexts fail explicitly. Foreign or unqualified selected geometry fails the import, not a silently filtered subset. These objects are research annotations, not a verified clinical report or a full SR document viewer.
Remote project JSON/own-format ZIP recipes retain canonical endpoint/instance selection, complete metadata/frame SHA pins and exact topology/delivery representations, but no lease or live handle. Reopening reauthorizes the explicit resources and checks metadata, topology and bounded codec probes; unrequested frame bodies are not eagerly downloaded. Later reads must match every saved pin. Strong-validator-only sources cannot become durable snapshots by silently fetching the full slide during save. Metadata-only GeoJSON/measurement exports do not include or authorize source pixels.
**Native WADO export:** strong-ETag and complete-SHA sources support level-zero, single-optical-path/Z TILED_FULL unsigned MONOCHROME2 u8/u16 with full-width stored bits and native Explicit VR Little Endian delivery. The profile requires explicit `LossyImageCompression=00` and no declared transforms; that declaration does not prove acquisition history. Samples are read before display scaling, with exact SOP/frame/resource revisions and `originalStoredTransferSyntax: "unknown"`. RGB, compressed/transcoded deliveries, reduced levels and multiple optical/Z planes remain unsupported. Actual current user image capture and source/destination authorization remain required.
At most 16 source frames may be requested. Complete provenance reservation and actual TIFF/OME writer planning retain the 64 KiB PNG-metadata, 48 KiB numeric-JSON, 64 KiB escaped TIFF-description and 32 MiB output limits; escaping and padded output can reject smaller regions before frames, destination authorization or private state. Generated 8/16-bit [default-server tests](src/server-dicomweb-viewer.test.ts) check edge pixels, both validator modes, exact exported bytes, capture/source fences, cancellation and early rejection. This is not acquired native-16-bit WADO or installed-host qualification. See the [native adapter](src/server-dicomweb-export-source.ts) and [shared export planner](src/persistent/slide-native-tiff.ts).
**Public WADO evidence:** actual default-SDK opening and source-matching interior/edge PNGs were checked against an explicitly acquired 55-frame, 2,677 × 1,164 reduced IDC instance. GeoJSON, calibrated measurement CSV and portable JSON/ZIP exports also passed; fresh server instances reopened both project formats after deletion of the original manifest file, with every saved pin checked against the acquired source manifest. These reopen checks are not a separate-process or installed-host restart. The public endpoint supplies no strong ETags and ignores `If-Match`; its SOP UID alone is not content integrity. The test used complete metadata and encoded-frame SHA pins from the acquired snapshot, not a publisher-authenticated manifest or full-resolution slide. Its reported zero slice thickness is retained as an `invalid-zero` warning with unusable/null physical depth, only under the explicit single-plane 2D-display policy. This does not qualify the source as fully DICOM-conformant or provide Z calibration; strict local/derived-object paths remain unchanged. No specimen or frame bodies are bundled.
That acquired IDC instance is lossy RGB8 JPEG: its PNGs are display-tile evidence, not qualification of the native MONOCHROME2 export profile.
**Object evidence:** SHA/Git-blob-pinned originals from highdicom/pydicom test corpora cover ANN, tiled SEG, labelmap/palette, fractional CT SEG and float/double maps; these are independent upstream **test objects**, not scanner acquisition data. Their exact samples and references are checked in [derived original-object tests](src/interop/dicom-derived-real-fixture.test.ts). Original SR objects have [semantic tests](src/interop/dicom-sr.test.ts). Additional DICOMweb/STOW registration and withdrawn-permission tests use controlled transport: [web](src/interop/dicom-web.test.ts), [upload](src/server-dicom-upload-tools.test.ts). See [object types](src/interop/dicom-object-types.ts), [derived codec](src/interop/dicom-derived-objects.ts) and [upload transport](src/interop/dicom-stow-transport.ts).
## OME-NGFF on Zarr v2/v3
“V2/v3” denotes **Zarr storage**, not NGFF metadata versions. Qualified source profiles are NGFF **0.4 + Zarr 2** individual `.zgroup`/`.zattrs`/`.zarray` metadata, and NGFF **0.5 + Zarr 3** `zarr.json` with `attributes.ome`.
| Aspect | Implemented | Public gaps/rejections |
| ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Axes/scenes | Two to five named XY plus optional C/Z/T axes; explicit scale/translation, physical units, multiscales, OMERO channels/windows/colors/inversion/default planes; HCS plate/well fields and qualified bioformats2raw series discovery. | No arbitrary coordinate transforms or volume rendering. Limits: 32 scenes, 128 levels, C≤64, Z/T≤4,096. No automatic NGFF semantic-label/transcript interpretation. |
| Scalar pixels | Bool, signed/unsigned8/16/32, Float16/32/64; explicit multibyte endianness. Raw native-level windows and streamed min/max/mean/sum projections. | Int64/UInt64 image pixels, Float8, complex/structured/object/string arrays reject. UInt64 shard offsets are not UInt64 image support. Nearest-neighbor display tiles are not resampled quantitative measurements. |
| Chunks/codecs | Regular chunks; v2 C/F order and dot/slash keys; v3 bytes serialization, one complete transpose, default/v2 chunk-key encoding and optional CRC32C. Raw/gzip/zlib/Zstd; Blosc LZ4/LZ4HC/zlib/Zstd with no shuffle, byte shuffle, or qualified format-2 bitshuffle. | Bitshuffle retains exact block/split and incomplete-element semantics under existing decode limits. Historical format-1 bitshuffle is not qualified. V2 pre-compression filters, BloscLZ/Snappy, nonregular grids, arbitrary/nested codecs and unknown codec variants remain unsupported. |
| V3 sharding | `sharding_indexed`, evenly dividing inner chunks; fixed-size C-order UInt64 index, optional CRC32C, start/end index placement and bounded actual range/suffix reads. | Outer-codec-wrapped/nested shards, compressed or transposed shard indexes are not qualified. A simulated 5-GB sparse shard is a generated addressing control. |
| Source consistency | Authorized directory; anonymous public HTTPS with strong per-object validators or a complete integrity manifest. | No ZIP, kerchunk or authenticated cloud-store adapter. Validators do not establish an atomic whole-store snapshot. |
Portable OME-Zarr projects require either a bounded `directory-inventory` identity for the same unchanged local store, or an explicitly supplied public `ome-zarr-sha256-manifest` (`manifestPath`, at most 4 MiB). Public recipes are **manifest-defined**: they retain object size/SHA pins and separately declared missing metadata probes, not a claim that the origin was atomically inventoried. An unlisted data chunk fails before fetching and cannot become fabricated fill pixels. ETag-only public and lazy-directory sources may be viewed, but cannot be saved as durable source recipes. Reopening checks parser-consumed metadata and topology and issues fresh bindings under current permission; source copies or changed inventory/metadata are not silently rebound.
Reader bounds: 1 MiB/object metadata, 8 MiB aggregate metadata/256 requests, 8 MiB decoded chunk, 32 MiB operation encoded/decoded/resident accounting, 4,096 chunk work, 1,048,576 raw-region pixels, 1 MiB shard index, two concurrent reads and a 30-second deadline. These are accounting ceilings, not measured process/GPU memory guarantees.
**Acquisition evidence:** the public OME IDR0062A image `6001240` is C2×Z236×Y275×X271 fluorescence microscopy. Only cached metadata and two actual Z=118 channel chunks were qualified, with complete decoded-plane/256²-window SHA agreement against independent NumPy/numcodecs and actual RGBA composite comparison. This is not a whole-volume, histology, spatial-transcriptomics or real-v3-acquisition qualification. One real public `.zattrs` GET also passed through the unchanged public provider; it does not qualify authenticated endpoints or installed-host rendering. The 24 independent codec vectors and v3/shard tests are generated controls.
Sources/evidence: [metadata](src/interop/ome-zarr-metadata.ts), [codecs](src/interop/ome-zarr-codecs.ts), [reader/limits](src/interop/ome-zarr-types.ts), [controls](src/interop/ome-zarr.test.ts), [pinned IDR/independent-codec checks](src/interop/ome-zarr-real-fixture.test.ts), [default adapter tests](src/server-ome-zarr-tools.test.ts).
## Captured-view exports
These are the default plugin's model-facing `slide.control_viewer` → `export_view` operations, not an optional host exporter. The app captures current state only for the exact prepared command; model-supplied state, pixels or approval flags cannot replace it. All writes require current source/destination authority, no-clobber publication and an actual byte/hash receipt.
| Output | Supported meaning | Boundary |
| ----------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Annotation GeoJSON | Sanitized geometry with stable safe IDs in the verified image-pixel frame; actual names only with explicit inclusion. | Up to 10,000 annotations. Unsupported/overlong IDs reject rather than silently dropping or renaming features. A portable project preserves broader original authored IDs. |
| Measurement CSV | Server-recomputed line/polygon geometry, including holes and anisotropic physical calibration when supplied by the actual source. | Unknown or foreign coordinate frames cannot be labeled as pixels or micrometers. Readable IDs are spreadsheet-safe; exact typed IDs are separately encoded. |
| Spatial CSV | Every loaded original observation for one exact indexed source gene and matrix descriptor, including original row/ID, source coordinates, value scale and missingness. Matrix path/revision accompany the values and receipt. | At most 4,096 loaded rows, not a full-assay export. Legacy omission means `X` only; a visible layer cannot silently export `X`. A separate expression overlay binds its expression source, not the primary image file. |
| Project JSON / annotation ZIP | Genuine portable project state and explicit source recipes. ZIP includes a project copy and its declared annotations, not specimen bytes. | Labels/history are not de-identified. Reopening requires fresh authorization; saved native IDs, image consent and unfinished-job authority are never restored. |
| Source PNG | Eligible source-native unsigned 8/16-bit grayscale or qualified RGB at an exact level-zero ROI and selected source plane, with sample/provenance metadata. | No false-color composite, display-quantized substitute, alpha/extra-sample dropping or arbitrary projection. Requires genuine current user ROI capture consent; a written file is not new image context. Use numeric TIFF/OME-TIFF for other supported sample layouts. |
The separate `export_microscopy_region` operation writes numeric TIFF/OME-TIFF from the actual selected microscopy planes, qualified local native Gray/RGB 8/16-bit samples, or the strict level-zero native WADO profile above. Metadata advertises only qualified native levels; BlackIsZero/RGB profile checks do not silently discard alpha, invert WhiteIsZero, or fabricate C/Z/T. Nonzero levels use their actual native pixel-edge mapping and an inward-snapped window inside the same live user capture. NGFF physical Z/projection membership must map exactly, not to a nearest displayed plane. IFD/SOP/frame identities, source color decoding, actual native geometry, and declared versus inferred physical calibration accompany the samples. Display opacity/gamma and PNG quantization do not alter the numeric input, and an invisible image cannot grant capture consent.
CSV companion fields `annotation_id_json`, `observation_id_json` and `gene_symbol_json` use `identifier_encoding=json-object-v1`; `JSON.parse(cell).value` recovers the exact string/number identity. Do not infer identity by removing formula-safety apostrophes from readable fields. Finite negative numeric values remain numeric.
The request is bounded to 9 MiB and the published artifact to 32 MiB. Retries must retain the exact source, captured revision, destination and request; reopening a session is not a general retry-recovery contract. Real local DICOM collections support annotation, measurement, eligible PNG and portable project/bundle exports. Projects preserve the exact ordered member recipes, SOP identities and source-derived pyramid geometry/calibration; reopening independently reauthorizes every member and constructs a fresh aggregate binding. Saved collection digests are not live source handles or grants. Geometry from another source, scene, Z/T plane or library is retained but withheld until its original frame is verified; legacy state without frame provenance is not automatically aligned.
`load_project` accepts plain project JSON (8 MiB maximum) or the plugin's own three-entry, uncompressed annotation ZIP profile (32 MiB maximum, the same 8 MiB inner-project limit). Direct bundle loading checks exact entry names, contiguous local/central/end records, CRCs, SHA-256 manifest entries and JSON structural limits without extraction or decompression. Arbitrary ZIP profiles, compression, duplicate/extra entries and inconsistent structure are not supported. The full archive hash remains the base-file identity for conflict detection; exporting or reopening a bundle never includes specimen bytes or restores old permissions/image consent. A project admits at most 16 physical-file bindings, while a viewer session admits 32 total source handles including virtual DICOM aggregates. Atomic replacement can therefore fail at capacity even for a valid 16-member collection; it rolls back only newly prepared handles and preserves the old scene. A fresh session with sufficient capacity can reopen that project.
Evidence: [default six-format SDK/byte tests](src/persistent/slide-view-export.test.ts), [default DICOM collection tests](src/server-dicom-tools.test.ts), [source-native PNG tests](src/slide/local-source-png.test.ts), [publication/privacy](src/persistent/slide-artifact-privacy.test.ts). These are controlled protocol and disk-artifact checks, not installed-host/browser acceptance.
## Acceptance still required
No family above establishes specialist-product parity, arbitrary public-format coverage, clinical equivalence or installed-host success. Keep every listed public gap open. Final acceptance must use the actual immutable package and independently acquired specimens for the claimed profiles, count executed cases rather than discovery/skips, and retain source/pixel/semantic hashes plus machine/runtime details. Measure documented cold/warm p95, RSS/GPU/transfer budgets and cancellation before claiming large-data limits; generated address space and isolated decoder success cannot substitute for that evidence.
Optional pathology models/runtime require the explicit setup in [PATHOLOGY.md](PATHOLOGY.md). The shipped-license gate excludes the scran native engine and checks the retained runtime's source and notices. Packaging and successful decoding do not provide legal or publication approval; see [third-party notices](THIRD_PARTY_NOTICES.md).
SHA-256: d33914b7c467c3842b9f4ed2d1c4e3ddb3b5f8e8205eeb1c5478a4c948cdfe24