Skip to content

v1.8.1-alpha : WASM bindings and IDL sanitization

Pre-release
Pre-release

Choose a tag to compare

@gangatp gangatp released this 30 Sep 10:39

Changelog

v1.8.1-alpha — WASM bindings and IDL sanitization (2026-09-30)

Security release addressing PSIRT-3497 (code injection via crafted IDL). Also bundles all binding fixes and features that landed since v1.8.0-alpha, including new WebAssembly bindings, Node.js binding improvements, and C++ thread-safety options.

Upgrade is recommended for all users, especially anyone building components from untrusted or externally-authored IDL files.

🔒 Security

  • #240 — Sanitize IDL text written into generated comments and strings (PSIRT-3497). A crafted IDL could break out of a generated /* */, (* *), ''', or CMake bracketed comment — including via Java \uXXXX unicode escapes and C/C++ backslash line-splicing — and inject arbitrary code into generated bindings. Fix adds both input validation and output sanitization, with unit tests.

✨ New features

  • #225 — WebAssembly (WASM) bindings via emscripten. (@vijaiaeroastro)
  • #220 — C++ binding/implementation thread-safety options (none / soft / strict). (@Kimeek42)
  • #222 — Command-line flag to suppress CMakeLists.txt generation. (@spywo)

🟩 Node.js bindings

  • #239 — Support basicarray / structarray parameters and class inheritance (V8 API). Previously arrays were emitted as 0, nullptr stubs. Compatibility fixes for newer V8 APIs (verified on Node 12+). (@YackerYan)

🐍 Python bindings

  • #234 — Harden Python bindings against shutdown-time destructor errors.
  • #230 — Add getter methods on the generated Python exception class.
  • #229 — Fix Python bindings struct out-parameter handling.
  • #228 — Fix Python out-parameter handling (also improves C# wrapper visibility).
  • #227 — Loosen overly-restrictive regex validation for IDL descriptions.

#️⃣ C# bindings

  • #231 — Generate a project-specific C# exception class.
  • #228 — Improve C# wrapper visibility (bundled with Python fix above).
  • #215 — C# crash fix: pass structs through bindings by ref.

☕ Java bindings

  • #235 — Fix JNI prefix for Function.

🅲 C++ bindings

  • #232 — Use specific class type instead of BaseClassName in ParameterCache template generation.
  • #221 — Fix C++ include header being written in lowercase.

📚 Examples & documentation

  • #223 — Fix existing examples and add documentation to the Primes example.

🔧 CI / build

  • #224 — Update GitHub Actions Windows runner from 2019 to 2022.
  • Pin emsdk to 4.0.21 in the example build image (bundled with #240; Python 3.10 unavailable on CentOS 8).

👋 New contributors

Full changelog: v1.8.0-alpha...v1.8.1-alpha