Home / Alt manpages / perl5124delta(1)

  • perl5124delta(1)
  • User command
  • linux

Check Perl 5.12.4 Compatibility Fixes on a Modern Linux Host

You will finish with a small, repeatable compatibility check for the changes documented by perl5124delta: the undefined-hash edge case, taint propagation through case conversion, here-document parsing, the bundled Module::CoreList version, and the Linux multi-architecture note. The checks are read-only and run as an ordinary user.

Allow about 15 minutes. You need the perl-doc package for the manual and a Perl interpreter. This machine provides perl-doc and perl-base version 5.38.2-3.2ubuntu0.6, so the examples demonstrate how to assess an old release note with a newer interpreter. They do not turn Perl 5.38 into Perl 5.12.4.

1. Confirm the manual and interpreter you are checking

Start by recording the local files and versions. These commands only read package metadata and print version information:

$ command -v perl
/usr/bin/perl
$ man -w perl5124delta
/usr/share/man/man1/perl5124delta.1.gz
$ dpkg-query -W -f='${Package} ${Version}\n' perl-doc perl-base
perl-doc 5.38.2-3.2ubuntu0.6
perl-base 5.38.2-3.2ubuntu0.6
$ perl -e 'print "$^V\n"'
v5.38.2

The manpage itself describes the difference between Perl 5.12.3 and 5.12.4. Its installed header may carry the version of the documentation generator rather than the historical Perl release. Treat the release named in the title as the subject of the document, not as the version installed by the package manager.

Checkpoint

If man -w perl5124delta fails, install or repair perl-doc through your normal package-management process. Do not change the interpreter merely to read a release note.

2. Test the undefined hash edge case

Perl 5.12.4 fixed an optimisation around keys and an undefined hash reference when strict references are disabled. The useful boundary is deliberate: the expression should be accepted without strict references, while strict mode should reject it.

$ perl -we 'no strict "refs"; my $x; my $ok = eval { keys %$x; 1 }; print "ok=$ok err=$@"'
ok=1 err=
$ perl -we 'use strict "refs"; my $x; my $ok = eval { keys %$x; 1 }; print "ok=$ok err=$@"'
ok= err=Can't use an undefined value as a HASH reference at -e line 1.

The exact diagnostic wording can vary between Perl releases, but the distinction matters. An application that accidentally depends on an undefined reference should be fixed rather than relying on permissive behaviour. The first command is a compatibility probe, not a recommendation to disable strictness.

Keep this test isolated from application data. It creates no files and changes no process-wide setting.

3. Check taint propagation through case conversion

The release note records a security-relevant correction: lc, uc, lcfirst and ucfirst must preserve taint. Taint mode is enabled with -T; the sample reads the environment, which Perl treats as tainted, and uses Scalar::Util::tainted to inspect the converted value.

$ perl -T -we 'my $x = $ENV{PATH}; my $y = lc $x; require Scalar::Util; print Scalar::Util::tainted($y) ? "tainted\n" : "untainted\n"'
tainted

This does not make an environment variable safe for a shell, file path or network request. It verifies that the taint marker survives one transformation. Keep validation and untainting decisions at the point where the value enters your application.

Security boundary

Do not remove -T just to make a legacy script run. If an old program fails under taint mode, inspect the data flow and validate the value explicitly. No elevated privileges are needed for this check.

4. Keep here-document fixes in the parser category

The manpage describes a possible use-after-free while parsing a here document. That is an interpreter memory-safety fix, not a shell feature that you can enable with a flag. You can still run a harmless parser smoke test to confirm that your installed interpreter handles the syntax:

$ perl -we 'my $text = <<"END";
line one
line two
END
print $text'
line one
line two

A successful result shows that this simple input parsed and ran. It cannot prove the absence of every parser bug, and it cannot reproduce the vulnerable historical allocator state on demand. For an application that must run an older Perl, use its supported update path and test the actual interpreter version in a disposable environment.

5. Compare the bundled module version

perl5124delta says that Module::CoreList moved from 2.43 to 2.50 in Perl 5.12.4. Query the installed module directly instead of inferring it from the Perl interpreter version:

$ perl -MModule::CoreList -e 'print "$Module::CoreList::VERSION\n"'
5.20231129

That version is much newer than 2.50, which is expected on the Perl 5.38.2 installation used here. It is evidence about this host only. If a build script requires a particular module API, test that API or declare a dependency; do not compare version strings from unrelated Perl releases as if they were interchangeable.

6. Treat the platform note as a packaging check

The document records support for Ubuntu 11.04's multi-architecture library layout. This is a historical platform note, not a command-line option. On a modern Debian or Ubuntu system, inspect the architecture and package manager's configured foreign architectures without changing them:

$ dpkg --print-architecture
amd64
$ dpkg --print-foreign-architectures
<no output on this host>

Do not run dpkg --add-architecture as part of this guide. It changes package-management state and can lead to package downloads or dependency changes. If you are diagnosing a real multi-architecture installation, record the current output first, then follow your distribution's packaging procedure with an explicit change plan and rollback point.

7. Use the release note when triaging an old application

Read perl5123delta and perl5120delta as well when the application is moving from an earlier 5.12 release. The 5.12.4 document deliberately limits itself to the 5.12.3 to 5.12.4 delta. Its testing note about HTTPS environment variables is relevant to the old cpan/CGI/t/http.t test, not proof that every CGI application handles proxy settings correctly.

For a bug report, capture the smallest failing input and include the output of perl -V, as the manpage requests. If the report has Perl-core security implications, use the security reporting route documented by the installed manual rather than posting sensitive details publicly. Avoid sending application secrets, tokens or customer data in a reproduction.

Done means

  • The local perl5124delta manual and installed Perl version are recorded.
  • The undefined-hash, taint and here-document probes have been run without elevated privileges.
  • The installed Module::CoreList version has been queried directly.
  • The Ubuntu multi-architecture note has been treated as historical packaging context, without changing dpkg state.
  • You know which results describe Perl 5.12.4 and which describe the newer interpreter installed on this host.