Conversation
…s and review nits Functional follow-ups from the deep review of the Pyodide transport: - Enforce the gRPC deadline through an AbortController with the timer cleared in finally, capped at 2^31-1 ms. asyncio.wait_for left one live JS timer per call for its full timeout (Node kept running ~90 s after the e2e suite) and overflowed on pre-314 Pyodide. run.mjs now exits explicitly. - Stop forwarding httpx's user-agent from the fetch transport (Firefox honours it and preflights it; core's REST allowlist does not cover it). - Pin the [grpc-web] extra to the same version as the base package from setup.py via setuptools_scm; micropip does not backtrack. - Add a CORS hint under Emscripten to transport errors and the grpc-web health-check error; report a transport failure before the first response as UNKNOWN so a blocked or misrouted endpoint fails at once instead of after the UNAVAILABLE retry loop. - Reject conflicting repeats of grpc-status/grpc-message in one trailer. - Validate call metadata against the gRPC spec before sending; normalise the grpc-web path prefix; fix the sync-client prefix error target, the Con006 wording, the endpoint wording in WeaviateGRPCUnavailableError and the companion's import error on CPython. - Tests for cancellation, the HTTP 405 diagnosis, the fake grpc version tie, the default-port Con006 case; drop the dead OSError branch in the PyPI version check; share the wheel check and the lockstep assert between the harness scripts and CI. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CCHAmyQF69W7K9CTEzCpEd
There was a problem hiding this comment.
Orca Security Scan Summary
| Status | Check | Issues by priority | |
|---|---|---|---|
| Infrastructure as Code | View in Orca | ||
| SAST | View in Orca | ||
| Secrets | View in Orca | ||
| Vulnerabilities | View in Orca |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What & why
Functional follow-ups from the deep review of #2142 (merged). The comment/docs pass landed there as 0ce4cd4; this PR carries the behaviour changes on top of it.
asyncio.wait_forleft one live JS timer per gRPC call for its full timeout — Node kept the e2e process alive ~90 s after the suite finished, a browser page accumulates them — and overflowedsetTimeouton pre-314 Pyodide. The deadline is now anAbortControllerwith its timer cleared infinally, capped at 2³¹−1 ms;run.mjsexits explicitly.user-agentfrom the fetch transport. httpx's default was forwarded; Firefox honours it and preflights it, and core's REST allowlist does not include it.[grpc-web]extra pinned in lockstep fromsetup.pyvia setuptools_scm. micropip does not backtrack, so an unpinned extra breaksmicropip.install("weaviate-client[grpc-web]==X")for any non-latest X.CORS_ALLOW_ORIGIN/CORS_ALLOW_HEADERSand the Weaviate Cloud setting. A transport failure on a channel that has not yet received any response is reported asUNKNOWNand fails at once (was:UNAVAILABLE, 63 s of retries); after the first response it staysUNAVAILABLE.grpc-status/grpc-messageinside one trailer frame are rejected asINTERNALinstead of letting the last value win.ValueError, as grpcio does); path-prefix normalisation (" "→ native,"//a//b/"→/a/b); the sync-client prefix error points atWeaviateAsyncClient(ConnectionParams.from_params(..., grpc_path_prefix=...)); portable Con006 wording; "REST endpoint" only when gRPC and HTTP addresses match, plus an Emscripten branch for hand-built params without a prefix; a clearImportErrorwhenweaviate_client_webis imported on CPython; Pyodide terminology in runtime strings.OSErrorbranch in the PyPI version check is gone; the wheel check and the lockstep assert are shared (ci/pyodide-e2e/wheels.mjs,ci/assert-lockstep.sh).Decisions to confirm
UNKNOWNbefore the first response means a transient failure on the very first call is not retried whenskip_init_checks=True.[0-9a-z_.-]+, non--binvalues printable ASCII).extras_requirenow live insetup.py(setuptools ignoressetup.cfgextras oncesetup.pydefines any), soagentsmoved too.set_sendermust enforcetimeoutand raiseTimeoutError.Verification
Pyodide unit suite 169 passed (139 before).
run.mjse2e: ALL STEPS OK in 4 s (was ~94 s). Timer probe: +0 pending timers per 200 gRPC calls (was +200).pytest test mock_tests proto_test: 524 passed. ruff / flake8 / pyright clean. Real Chrome, cross-origin: 12/12 operations against local 1.39.3 and 1.40.0-rc.1, grpc-web health check against Weaviate Cloud. Wheel metadata carriesweaviate-client-web==<same version>including when built from the sdist.🤖 Generated with Claude Code
https://claude.ai/code/session_01CCHAmyQF69W7K9CTEzCpEd