Skip to content

Scope the browser floor guard to compiled packages - #402

Merged
neuromechanist merged 1 commit into
developfrom
fix/browser-floor-scope
Sep 21, 2026
Merged

neuromechanist merged 1 commit into
developfrom
fix/browser-floor-scope

Conversation

@neuromechanist

Copy link
Copy Markdown
Member

What was wrong

I justified part of #399 by saying threadpoolctl>=3.6.0 was a live browser-install bug against a
Pyodide that ships 3.5.0. That is wrong. threadpoolctl publishes
threadpoolctl-3.6.0-py3-none-any.whl, so micropip pulls it straight from PyPI and never touches
the bundled build. The floor costs a download, not an install.

What is actually true

Pyodide's bundled build is the only one a browser can have when the package publishes no
pure-Python wheel. Checked against PyPI:

package universal wheel on PyPI floor is a ceiling
numpy none yes
scipy none yes
h5py none yes
matplotlib none yes
threadpoolctl py3-none-any no

The change

tests/test_browser_dependency_floors.py now enforces PYODIDE_COMPILED, the four packages where
the constraint binds, and records PYODIDE_PURE_PYTHON separately with the reason it is
deliberately not enforced. The pyproject.toml comment carried the same wrong claim and is
corrected.

The four floors that shipped in #399 are correct and unchanged. What was wrong was the stated
reason for one of them, and a test that enforced a constraint that does not exist.

Verification

Still non-vacuous, which is the point of the guard: raising the non-darwin scipy floor to 1.15.0,
above the 1.14.1 Pyodide ships, fails three tests by name. 10 passed unmodified. ruff check and
ruff format --check clean.

Correction also filed as a comment on #400, whose original example was this same mistake. That
issue stays open, because the gate does have a real blind spot for compiled packages, but the naive
fix (comparing lockfile-resolved versions) reports false failures since uv.lock resolves ahead of
Pyodide by design.

I claimed threadpoolctl>=3.6.0 was a live browser-install bug against a
Pyodide shipping 3.5.0. It is not. threadpoolctl publishes a
py3-none-any wheel, so micropip pulls any version straight from PyPI
and never touches the bundled build. The floor costs a download, not an
install.

The constraint is real only where no pure-Python wheel exists, because
then Pyodide's build is the only one a browser can have. Checked
against PyPI: numpy, scipy, h5py and matplotlib publish none, so their
floors genuinely are a ceiling; threadpoolctl does, so its floor is not
constrained this way.

So the test now enforces the four compiled packages and records
threadpoolctl in PYODIDE_PURE_PYTHON, deliberately unenforced, with the
reason. Still verified non-vacuous: raising the non-darwin scipy floor
to 1.15.0, above the 1.14.1 Pyodide ships, fails three tests by name.

The four floors that shipped in #399 were correct and remain unchanged.
What was wrong was the stated reason for one of them. Correction also
filed on #400, whose original example was the same mistake.

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Code review skipped — your organization has no extra usage available to pay for this review.

If your organization's extra usage balance is empty, an organization admin can add extra usage credits at claude.ai/admin-settings/usage. If its monthly spend limit was reached, an admin can raise it on the same page. If neither applies, contact Anthropic support.

Once extra usage is available, reopen this pull request to trigger a review.

@claude

claude Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Claude encountered an error after 0s —— View job


I'll analyze this and get back to you.

neuromechanist added a commit to nemarOrg/nemar-cli that referenced this pull request Sep 21, 2026
Both the memory entry and the eegprep-lean contract said every
dependency floor is a ceiling in the browser. That is only true of
compiled packages.

The test is whether the package publishes a pure-Python wheel, not
whether Pyodide bundles it. A py3-none-any wheel means micropip fetches
any version straight from PyPI and the bundled build goes unused. numpy,
scipy, h5py and matplotlib publish none and are genuinely capped;
threadpoolctl is bundled but pure Python and is not.

The memory cited threadpoolctl>=3.6.0 on the epic branch as a live
broken install, which was wrong. Kept as the instructive part rather
than quietly deleted: being bundled made it look identical to the scipy
case, and presence in pyodide-lock.json says nothing about whether
another version is reachable. Over-applying the rule has its own cost,
which is false alarms and a guard nobody trusts.

Superseded claims removed rather than left beside the correction, per
the directory's own rules. Test fix is sccn/eegprep#402.
@neuromechanist
neuromechanist merged commit 36c0ea1 into develop Sep 21, 2026
11 of 12 checks passed
@neuromechanist
neuromechanist deleted the fix/browser-floor-scope branch September 21, 2026 06:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant