Skip to content

Improve first Python run reliability for CSG pilot - #49

Merged
leonshimizu merged 3 commits into
mainfrom
codex/hafa-python-startup-20260926
Sep 28, 2026
Merged

leonshimizu merged 3 commits into
mainfrom
codex/hafa-python-startup-20260926

Conversation

@leonshimizu

@leonshimizu leonshimizu commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Purpose

Make Python's first browser run more reliable for CSG's invited December pilot while documenting Hafa Code's role in a broader online course path. This PR is held for Leon's review and must not be merged until he approves it.

What changed

  • Allows up to 90 seconds for the first Python runtime download/startup; the three-second execution limit and other languages' startup limits stay unchanged.
  • Explains the first-load delay in the runner.
  • Documents Hafa Code as the browser coding workspace for independent practice and later guided courses, including learners outside Guam. CSG Learn remains the submission and feedback record. Current snapshot links import a copy, so they are not the sole grading record. Youth account and sharing rules need review before youth enrollment.

Verification

  • The earlier full ./scripts/gate.sh passed: 273 frontend tests, 22 browser tests, 58 Rails tests, lint, build, and high-severity dependency audit.
  • A browser test delayed the Pyodide WASM download by 31 seconds and verified cold and warm runs. A preview Python run succeeded in about 9.96 seconds.
  • The new change is documentation-only; git diff --check passed on the current head.

Deployment

The code change is frontend-only. No new service, secret, schema change, or public enrollment is included.

  • Python startup timeout is now 90 seconds. Other languages’ startup limits and the three-second execution limit remain unchanged.
  • The Python runner tells learners that the first run downloads a larger browser runtime and may take longer on mobile connections. Later runs should be faster.
  • End-to-end coverage delays the Pyodide WASM download by 31 seconds, then checks successful cold and warm runs. Runner tests check Python’s longer startup timeout.
  • The roadmap describes the invited adult Python Fundamentals pilot, the roles of Hafa Code and CSG Learn, and safeguards to review before courses include minors.
  • The PR reports that ./scripts/gate.sh passed 273 frontend tests, 22 browser tests, 58 Rails tests, lint, build, and a high-severity dependency audit. It also reports that git diff --check passed.
  • No schema or service changes are reported. No breaking changes are identified. The PR requires Leon’s approval before merge.

RetriggerConfidence Score: 5/5

The PR appears safe to merge after the requested Leon review.

Summary

The PR gives Python runtime startup 90 seconds without changing the execution timeout or other languages’ startup limits, explains the first-load delay to learners, and adds cold- and warm-run coverage. It also documents the planned Code School pilot workflow.

Reviews (2) · Last reviewed commit: "Document Hafa role in focused course pat..."

@netlify

netlify Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for hafa-code canceled.

Name Link
🔨 Latest commit cfccb69
🔍 Latest deploy log https://app.netlify.com/projects/hafa-code/deploys/6ab9e7e0b478180008202c9a

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 35d4375d-d617-409c-bea1-c156fd948e5d

📥 Commits

Reviewing files that changed from the base of the PR and between 558f194 and cfccb69.

📒 Files selected for processing (1)
  • docs/PRODUCT_ROADMAP.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The Python runner now allows 90 seconds for startup and displays a first-run download note. Tests cover delayed startup and repeated execution. The product roadmap describes an invited adult Python Fundamentals pilot and related course workflows.

Changes

Python startup handling

Layer / File(s) Summary
Python startup timeout and runner note
web/src/lib/languageRegistry.ts, web/src/lib/codeRunner.ts
The Python runner uses a 90,000 ms startup timeout. It displays a note about the first-run browser runtime download.
Python startup tests
web/src/components/RunnerPanel.test.tsx, web/e2e/languages.spec.ts
Unit tests check that a cold Python run can complete after the default startup limit but before the Python-specific limit. The end-to-end test delays the Pyodide download, checks loading and first-run messaging, then verifies successful first and subsequent runs.

Python course roadmap

Layer / File(s) Summary
Python Fundamentals pilot
docs/PRODUCT_ROADMAP.md
The roadmap describes an invited adult pilot, its relationship to CSG Learn, snapshot-copy behavior, assessment records, the teaching sequence, longer-term course formats, and safeguards before enrollment opens to minors.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to cfccb

The change extends Python startup time without extending its execution limit. The roadmap keeps the initial pilot adult-only and treats safeguards for minors as future prerequisites; no concrete merge-blocking risk remains.

Security Architecture Review

Security architecture risk: 🔵 Low · up to cfccb

The pilot plan keeps assessed work in CSG Learn, limits the first course to invited adults, and does not enable a new sharing route. Python’s longer wait is confined to browser startup. Existing link-sharing controls still need operational confirmation before the planned pilot.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — A disclosed snapshot link can expose the project-code copy to its holder while the token remains valid; an offline hash copy can persist independently of the server. The supplied changes do not establish a newly reachable sharing path or public youth audience.

Security Findings and Attack Paths

  • inferred — Token disclosure is an existing project-code exposure path, not an established PR-introduced finding. The roadmap explicitly avoids treating an editable imported copy as the sole grading record.

Trust Boundaries and Controls

  • observed — The server checks an operator flag and user organization membership for organization-tagged share creation. Snapshot resolution instead looks up the bearer token and expiry; imported code becomes a private personal copy.

Resilience and Maintainability Implications

  • observed — The incident procedure calls for disabling external sharing, revoking affected links where supported or treating them as disclosed, preserving an audit trail, and recording a policy decision before re-enablement. This procedure does not establish that each step is operationally available for the pilot.

Hardening Proposals

  • proposed — Before relying on sharing for the pilot, verify the deployed classroom-sharing flag and document who handles existing token links and offline copies after a disclosure; retain the stated safeguards review before any minors rollout.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 4 files. (1 skipped: 1 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: improving reliability for Python's first browser run in support of the CSG pilot. It is concise, specific, and consistent with the code and documentation …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 4 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@leonshimizu
leonshimizu merged commit 452f5a7 into main Sep 28, 2026
8 checks passed
@leonshimizu
leonshimizu deleted the codex/hafa-python-startup-20260926 branch September 28, 2026 13:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant