Build for pyemscripten 2026.0 (Pyodide 314.0.0a1) - #1
Merged
Merged
Conversation
There was a problem hiding this comment.
Pull request overview
Updates the Pyodide/pyemscripten build + test harness to support a newer Pyodide toolchain (314.0.0a1) and make local/CI testing less version- and wheel-filename-dependent.
Changes:
- Add query-param/CLI-based Pyodide version selection and dynamically load
pyodide.js. - Discover the built Polars wheel dynamically from
/wasm-dist/instead of hardcoding a filename. - Update the GitHub Actions build matrix to Pyodide
314.0.0a1/ Python3.14, adjust LLVM + retag behavior, and pass Pyodide version into Playwright tests.
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 7 comments.
| File | Description |
|---|---|
test-smoke.html |
Dynamically loads Pyodide by version and discovers the wheel from /wasm-dist/. |
test-official.html |
Same dynamic Pyodide loading and wheel discovery for the full test suite runner. |
test-runner.mjs |
Adds --pyodide-version, serves a /wasm-dist/ directory listing, and appends querystring to the test page URL. |
.github/workflows/build.yml |
Switches CI to Pyodide 314 alpha / Python 3.14, adjusts LLVM/retag logic, and threads version into test runs. |
Comments suppressed due to low confidence (2)
test-runner.mjs:24
- Argument validation still checks
process.argv[2], which can be a flag. If the user runsnode test-runner.mjs --strict(no html file),args[0]becomes undefined andresolve(args[0])will resolve to an unintended path instead of showing usage and exiting. Please validateargs[0](after flag filtering) and update the usage string accordingly.
const rawArgs = process.argv.slice(2);
const strict = rawArgs.includes('--strict');
const pyodideFlag = rawArgs.find(a => a.startsWith('--pyodide-version='));
const pyodideVersion = pyodideFlag ? pyodideFlag.split('=')[1] : null;
const args = rawArgs.filter(a => a !== '--strict' && !a.startsWith('--pyodide-version='));
const htmlFile = resolve(args[0]);
const wheelDir = resolve(args[1] ?? 'wasm-dist');
if (!process.argv[2]) {
console.error('Usage: node test-runner.mjs <test-file.html> [wheel-dir]');
process.exit(1);
}
test-runner.mjs:64
filePathis built withresolve(baseDir, userPath)but there is no check that the resolved path stays withinwheelDir/htmlDir. Requests containing..can escape the intended directory (path traversal) and read arbitrary files from the runner's filesystem. After resolving, ensure the result has the expected base prefix (or reject any path with..) before callingreadFile.
let filePath;
if (pathname.startsWith('/wasm-dist/')) {
filePath = resolve(wheelDir, pathname.replace(/^\/wasm-dist\//, ''));
} else {
filePath = resolve(htmlDir, pathname.replace(/^\//, ''));
}
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
…ename and improve directory listing for wasm-dist
fzumstein
force-pushed
the
pyempscripten-2026-0
branch
from
April 10, 2026 14:49
511062c to
32a4275
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.