Skip to content

Build for pyemscripten 2026.0 (Pyodide 314.0.0a1) - #1

Merged
fzumstein merged 6 commits into
mainfrom
pyempscripten-2026-0
Apr 10, 2026
Merged

fzumstein merged 6 commits into
mainfrom
pyempscripten-2026-0

Conversation

@fzumstein

Copy link
Copy Markdown
Member

No description provided.

Copilot AI review requested due to automatic review settings April 10, 2026 14:25

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the Pyodide/pyemscripten build + test harness to support a newer Pyodide toolchain (314.0.0a1) and make local/CI testing less version- and wheel-filename-dependent.

Changes:

  • Add query-param/CLI-based Pyodide version selection and dynamically load pyodide.js.
  • Discover the built Polars wheel dynamically from /wasm-dist/ instead of hardcoding a filename.
  • Update the GitHub Actions build matrix to Pyodide 314.0.0a1 / Python 3.14, adjust LLVM + retag behavior, and pass Pyodide version into Playwright tests.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 7 comments.

File Description
test-smoke.html Dynamically loads Pyodide by version and discovers the wheel from /wasm-dist/.
test-official.html Same dynamic Pyodide loading and wheel discovery for the full test suite runner.
test-runner.mjs Adds --pyodide-version, serves a /wasm-dist/ directory listing, and appends querystring to the test page URL.
.github/workflows/build.yml Switches CI to Pyodide 314 alpha / Python 3.14, adjusts LLVM/retag logic, and threads version into test runs.
Comments suppressed due to low confidence (2)

test-runner.mjs:24

  • Argument validation still checks process.argv[2], which can be a flag. If the user runs node test-runner.mjs --strict (no html file), args[0] becomes undefined and resolve(args[0]) will resolve to an unintended path instead of showing usage and exiting. Please validate args[0] (after flag filtering) and update the usage string accordingly.
const rawArgs = process.argv.slice(2);
const strict = rawArgs.includes('--strict');
const pyodideFlag = rawArgs.find(a => a.startsWith('--pyodide-version='));
const pyodideVersion = pyodideFlag ? pyodideFlag.split('=')[1] : null;
const args = rawArgs.filter(a => a !== '--strict' && !a.startsWith('--pyodide-version='));
const htmlFile = resolve(args[0]);
const wheelDir = resolve(args[1] ?? 'wasm-dist');

if (!process.argv[2]) {
  console.error('Usage: node test-runner.mjs <test-file.html> [wheel-dir]');
  process.exit(1);
}

test-runner.mjs:64

  • filePath is built with resolve(baseDir, userPath) but there is no check that the resolved path stays within wheelDir/htmlDir. Requests containing .. can escape the intended directory (path traversal) and read arbitrary files from the runner's filesystem. After resolving, ensure the result has the expected base prefix (or reject any path with ..) before calling readFile.
  let filePath;
  if (pathname.startsWith('/wasm-dist/')) {
    filePath = resolve(wheelDir, pathname.replace(/^\/wasm-dist\//, ''));
  } else {
    filePath = resolve(htmlDir, pathname.replace(/^\//, ''));
  }

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread test-runner.mjs
Comment thread test-smoke.html
Comment thread test-smoke.html Outdated
Comment thread test-official.html
Comment thread test-official.html Outdated
Comment thread .github/workflows/build.yml
Comment thread test-runner.mjs
…ename and improve directory listing for wasm-dist
@fzumstein
fzumstein force-pushed the pyempscripten-2026-0 branch from 511062c to 32a4275 Compare April 10, 2026 14:49
@fzumstein
fzumstein merged commit cb95f2e into main Apr 10, 2026
1 check passed
@fzumstein
fzumstein deleted the pyempscripten-2026-0 branch April 11, 2026 20:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants