Skip to content

Releases: Autodesk/AutomaticComponentToolkit

v1.8.1-alpha : WASM bindings and IDL sanitization

Choose a tag to compare

@gangatp gangatp released this 30 Sep 10:39

Changelog

v1.8.1-alpha — WASM bindings and IDL sanitization (2026-09-30)

Security release addressing PSIRT-3497 (code injection via crafted IDL). Also bundles all binding fixes and features that landed since v1.8.0-alpha, including new WebAssembly bindings, Node.js binding improvements, and C++ thread-safety options.

Upgrade is recommended for all users, especially anyone building components from untrusted or externally-authored IDL files.

🔒 Security

  • #240 — Sanitize IDL text written into generated comments and strings (PSIRT-3497). A crafted IDL could break out of a generated /* */, (* *), ''', or CMake bracketed comment — including via Java \uXXXX unicode escapes and C/C++ backslash line-splicing — and inject arbitrary code into generated bindings. Fix adds both input validation and output sanitization, with unit tests.

✨ New features

  • #225 — WebAssembly (WASM) bindings via emscripten. (@vijaiaeroastro)
  • #220 — C++ binding/implementation thread-safety options (none / soft / strict). (@Kimeek42)
  • #222 — Command-line flag to suppress CMakeLists.txt generation. (@spywo)

🟩 Node.js bindings

  • #239 — Support basicarray / structarray parameters and class inheritance (V8 API). Previously arrays were emitted as 0, nullptr stubs. Compatibility fixes for newer V8 APIs (verified on Node 12+). (@YackerYan)

🐍 Python bindings

  • #234 — Harden Python bindings against shutdown-time destructor errors.
  • #230 — Add getter methods on the generated Python exception class.
  • #229 — Fix Python bindings struct out-parameter handling.
  • #228 — Fix Python out-parameter handling (also improves C# wrapper visibility).
  • #227 — Loosen overly-restrictive regex validation for IDL descriptions.

#️⃣ C# bindings

  • #231 — Generate a project-specific C# exception class.
  • #228 — Improve C# wrapper visibility (bundled with Python fix above).
  • #215 — C# crash fix: pass structs through bindings by ref.

☕ Java bindings

  • #235 — Fix JNI prefix for Function.

🅲 C++ bindings

  • #232 — Use specific class type instead of BaseClassName in ParameterCache template generation.
  • #221 — Fix C++ include header being written in lowercase.

📚 Examples & documentation

  • #223 — Fix existing examples and add documentation to the Primes example.

🔧 CI / build

  • #224 — Update GitHub Actions Windows runner from 2019 to 2022.
  • Pin emsdk to 4.0.21 in the example build image (bundled with #240; Python 3.10 unavailable on CentOS 8).

👋 New contributors

Full changelog: v1.8.0-alpha...v1.8.1-alpha

v1.8.0-alpha : Java Bindings and RTTI support

Choose a tag to compare

@gangatp gangatp released this 05 Feb 10:15

What's Changed to v1.6.0

Major

Minor

New Contributors

Full Changelog: v1.6.0...v1.8.0-alpha

Version 1.6.0: Component-Injection and Shared Ownership

Choose a tag to compare

@martinweismann martinweismann released this 05 Aug 14:51

Changes compared to version 1.5.0:

  • Upgrading an existing (pre v1.6-)ACT component to use v1.6.0 does not require a major version increment of that component:

    • The binaries created with ACT-v1.6.0 are binary compatible to binaries that have been created with ACT-v1.5.0. Since v1.6.0 requires to provide an acquiremethod (see below), the minor version of the ACT-v1.6.0-binary must be increased compared to the ACT-v1.5.0-component.
  • ACT now supports shared ownership of class instances between implementation and bindings:
    Components now MUST define an acquiremethod, which acquires shared ownership of an instance.

    See the Injection-example for details.

  • ACT now allows components to be injected at runtime into other components.
    This is specified via the importcomponent-element and injectionmethod-attribute in the outer component and the symbollookupmethod-attribute in the inner (injected) component. These features are OPTIONAL.
    See the Injection-example for details.

  • ACT now offers the optionalclass-parameter type:
    The optionalclass-type for parameters behaves just like class, however, this instance may be empty, or null. A use case for optionalclass is e.g. a "findElementByName"-method of a list, which might or might not return a class instance.

    See the example of optionalclass for details.

  • Minor improvements and bugfixes:

    • Go-bindings have been substantially improved
    • Fix C#-return values
    • Fix go-out-strings
    • ACT now avoids warnings (size_t and C4250)
    • The memory footprint of C++-error-handling has been reduced to 8 byte per class instance (vs. 32 byte before)
    • C++: strings are now passed through the interface explicitly as null-terminated strings.
    • C++-types are used more consistently
    • ACT now checks special method signatures early in the generation-process
    • Autogenerated C++-Bindings+Implementations now also work if BaseName != NameSpace

Hint: the tutorial has been updated to work with v1.6.0.

Version 1.6.0-RC1: Component-Injection and Shared Ownership

Choose a tag to compare

@martinweismann martinweismann released this 09 Jul 08:38

This is release candidate 1 for ACT v1.6.0. It has been deprecated.

Version 1.5.0: Overhauling C-based languages

Choose a tag to compare

@martinweismann martinweismann released this 10 Apr 09:56
ba20316

Changes compared to version 1.4.0:

  • Upgrading an existing (pre v1.5-)ACT component to use v1.5.0 does not require a major version increment of that component:
    • The binaries created with ACT-v1.5.0 are binary compatible to binaries that have been created with ACT-v1.4.0. Since v1.5.0 requires to provide an errormethod (see below), the minor version of the ACT-v1.5.0-binary must be increased compared to the ACT-v1.4.0-component.
    • Most bindings (esp. the C++) created with ACT-v1.5.0 differ substantially from the ones generated with ACT-v1.4.0. Consumers will have to adapt their code.
  • Added Error Propagation:
    The error messages of internal exceptions in both C++ and Pascal-implementation are now translated into native error messages of exceptions in most binding languages. Implementers MUST implement an errormethod now (see global section).
  • The C++-binding is now header-only, too, and its usage is nearly identical to the C++-dynamic header.
  • All classes are now derived from a common base class. This base class MUST be explicitly specified via the baseclassname-attribute in the global-section.
    Note: This resolves the previously unmotivated/undefined class="BaseClass" in the releasemethods signature.
  • C++- and Python-Bindings and the C++-Implementation now make more use of namespaces. The main change is that the names of class-, enum-, struct-, and functionpointer-definitions do not contain the NameSpace anymore. E.g. a <class name="TheClass"> ... is now called NameSpace::CTheClass instead of NameSpace::CNameSpaceTheClass (the old behavior can be resurrected by setting the classidentifier-attribute of the CPP-implementation to equal the namespace of the component.
  • The C++-bindings and -Implementation now describe the thin-layer of the API using C++ terms for the simple types (e.g. enum classes).
  • A scalar type pointer has been introduced (you do not have to use "uint64" for addresses anymore). It maps to a void* in C++ world. (with all the ramifications that come with that, e.g. 64/32bit dependence)
  • ACT components now contain prerelease- and build-information according to https://semver.org/#spec-item-9 .
  • The type="handle" has been replaced by type="class" (type="handle" still works).
  • The NodeJS-bindings have been heavily improved.
  • C#-bindings have been added (experimental).
  • Bugfixes:
    • Fix const and noexcept specifiers in C++ exceptions
    • Fix python struct in parameter
    • Replace WIN32 with _WIN32
    • Parsing the IDL file is now more verbose and informative if errors arise
    • Fix circular dependency in Pascal implementation
    • Fix boolean return and out-values in Pascal bindings

Hint: the tutorial has been updated to work with v1.5.0.

-- DEPRECATED -- Version 1.5.0-RC2: Overhaul of C-based languages

Choose a tag to compare

@martinweismann martinweismann released this 05 Apr 11:14

This is release candidate 2 for ACT v1.5.0. It has been deprecated.

-- DEPRECATED -- Version 1.5.0-RC1: Overhaul of C-based languages

Choose a tag to compare

@martinweismann martinweismann released this 01 Apr 08:36
82b03e1

This is release candidate 1 for ACT v1.5.0. It has been deprecated.

Version 1.4.0: Nested Namespaces in C++

Pre-release

Choose a tag to compare

@martinweismann martinweismann released this 11 Jan 10:08
82b03e1

Changes compared to version 1.3.2:

  • boolean values are now specified (and implemented) as 8 bit values in the C89-layer of the hourglass
  • C++ implementation now uses a nested namespace SomeNameSpace::Impl to avoid potential namespace clashes with the C++ binding
  • Bugfixes:
    • added missing inline specifier in dynamic C++ bindings
    • fixed structs in Pascal implementation and bindings
    • fixed raising of exceptions in Pascal implementation
    • fixed generation of Python example code

Version 1.3.2: Improvements to bindings

Pre-release

Choose a tag to compare

@martinweismann martinweismann released this 12 Dec 14:55

Changes compared to version 1.3.1:

  • Improve NodeJS- and Golang-bindings (arrays, minor other improvements)
  • Fixes to Python- and Pascal-bindings
  • C++-dynamic bindings now separate definition from declaration (within header)

Version 1.3.1: Bugfixes

Pre-release

Choose a tag to compare

@martinweismann martinweismann released this 12 Dec 14:53

Changes compared to version 1.3.0:

  • Fixed missing function-types in Pascal implementation and binding
  • ACT now checks the parents of classes
  • ACT now writes out a license file according to the license in the IDL-XML