Source and replacement instructions

The complete laz 0.5.2 crate is included under laz-0.5.2/. Its LGPL2.1 license and static-linking exception are original. Binding source is pinned to commit 714d70b9bc5cf5d8fcdff15e0c87d265d0114594.

Build with Rust, the wasm32-unknown-unknown target and wasm-pack. The official instructions are cargo build; wasm-pack build --target web. To ensure the supplied library version is used, add to binding/Cargo.toml:
[patch.crates-io]
laz = { path = "../laz-0.5.2" }

Run wasm-pack build --target web in binding/. Replace platform/web/laz-rs/laz_rs_wasm.mjs with generated pkg/laz_rs_wasm.js, and laz_rs_wasm_bg.wasm with generated pkg/laz_rs_wasm_bg.wasm. Keep both files together. The default generated import.meta.url lookup remains valid after the .mjs rename. No application hash gate prohibits replacement. Run point-editing.test.cjs to check the public constructor/decompress_many/free interface and fixture records.

The upstream npm artifact has no original Cargo.lock or precise build recipe. Toolchain reproducibility is not claimed. A locally rebuilt pair can differ from the vendor hashes while remaining replaceable. This archive supplies the exact LGPL library source identified by the binary, and the pinned matching public wrapper source and instructions.
