Home / Alt manpages / perl5142delta(1)

  • perl5142delta(1)
  • User command
  • linux

Read Perl 5.14.2 Changes Without Misreading Your Installed Perl

You will finish with a reliable way to read perl5142delta, confirm which Perl documentation package is installed, and decide which historical changes matter to an upgrade review. The page describes the difference between Perl 5.14.1 and 5.14.2. It is not a guide to the Perl version currently running on your host.

Allow about ten minutes. You need a shell and the perl-doc package. The examples below were checked on a machine running Perl 5.38.2 with perl-doc package version 5.38.2-3.2ubuntu0.6. Your package version and module versions may differ.

1. Confirm the document and installed Perl

Start with ordinary, read-only checks. They do not need sudo and they change no configuration:

$ command -v perl
/usr/bin/perl
$ perl -e 'print "$^V\n"'
v5.38.2
$ dpkg-query -W -f='${Package} ${Version}\n' perl-doc
perl-doc 5.38.2-3.2ubuntu0.6

The installed interpreter is 5.38.2, while this page is about the 5.14.2 release from 2011. That distinction is the main trap. The delta document is useful for release archaeology, compatibility review and checking whether an old deployment included a fix. It does not mean that your current interpreter has only the fixes listed there.

Checkpoint: record both versions before copying a finding into a ticket. If perl-doc is absent, do not guess the contents from an online summary. Install the documentation through your normal package-management process, or read the matching upstream page linked in the metadata for this guide.

2. Read the delta through the installed documentation

Ask perldoc for the exact local page:

$ perldoc perl5142delta

This opens the installed manual in the configured pager. Press q to leave it. To make a text copy for searching without changing the source file, send the rendered output to a temporary file:

$ perldoc -T perl5142delta > /tmp/perl5142delta.txt
$ rg -n 'Security|Updated Modules|Bug Fixes|Known Problems' /tmp/perl5142delta.txt

The -T option asks perldoc for plain text. The redirection creates or replaces only the named temporary file, so choose that path deliberately. Remove it when finished if it contains information you do not want to retain. Nothing in this workflow requires elevated privileges.

3. Start with the security fixes

The 5.14.2 page records two security issues. An unsupported GLOB_ALTDIRFUNC flag passed to File::Glob::bsd_glob() could lead to an access violation or segmentation fault, with denial of service or possible code execution consequences when a program accepted flags from an external source. The release disabled unsupported flags and cleared unused function pointers.

It also records a heap overflow in Encode for certain inputs. These are release notes, not safe demonstrations. Do not try to recreate either fault against a production interpreter or feed hostile input to an old Perl merely to see whether it crashes.

Use the installed module versions to frame an audit:

$ perl -MFile::Glob -MEncode -MPerlIO::scalar -e \
  'printf "File::Glob %s\nEncode %s\nPerlIO::scalar %s\n", $File::Glob::VERSION, $Encode::VERSION, $PerlIO::scalar::VERSION'
File::Glob 1.40
Encode 3.19
PerlIO::scalar 0.31

Those values are from the checked host, not universal defaults. Compare them with the versions supplied by the Perl distribution under review. A modern-looking module version is useful evidence, but it is not a substitute for checking the complete package update history and the application code's input boundaries.

4. Separate module changes from language compatibility

The release notes say that CPAN moved from 1.9600 to 1.9600_01, CPAN::Distribution from 1.9602 to 1.9602_01, Encode from 2.42 to 2.42_01, File::Glob from 1.12 to 1.13, and PerlIO::scalar from 0.11 to 0.11_01. The notes describe bug fixes and metadata handling, including safer treatment of configure_requires in CPAN META files.

Do not turn those historical numbers into requirements for a 5.38 installation. First identify the interpreter and distribution being upgraded, then inspect its own bundled module versions:

$ perl -MCPAN -MCPAN::Distribution -MEncode -MFile::Glob -MPerlIO::scalar -e \
  'printf "CPAN %s\nCPAN::Distribution %s\nEncode %s\nFile::Glob %s\nPerlIO::scalar %s\n", $CPAN::VERSION, $CPAN::Distribution::VERSION, $Encode::VERSION, $File::Glob::VERSION, $PerlIO::scalar::VERSION'

This command prints local facts only. If a module is not installed or cannot be loaded, treat that as an audit finding to investigate, not as proof that the 5.14.2 release notes apply directly.

5. Check the bug-fix and platform sections

The bug-fix section covers edge cases in @INC filters, packing with U*, caller memory handling in the DB package, copy-on-write scalars, tied variables, restricted hashes, glob copies and the interaction between the /aa regular-expression modifiers and \b. These entries are valuable when an application depends on those internals, but they are not a list of new syntax to enable.

The platform notes mention HP-UX PA-RISC/64 with gcc-4.x and building on Mac OS X 10.7 with Xcode 4. The page also calls out a known problem: builds using PERL_GLOBAL_STRUCT were broken since 5.14.0, affecting platforms such as Symbian. If your deployment is ordinary Linux on a supported current distribution, do not let these specialised notes distract from checking the security and dependency sections first.

6. Turn the reading into an upgrade decision

For a real upgrade review, capture the old and new interpreter versions, package versions, enabled modules and test results. Run the application's test suite under the candidate interpreter. Pay particular attention to code that parses externally supplied glob flags, decodes untrusted byte strings, loads modules through @INC, or relies on copy-on-write behaviour.

If you find a suspected defect, reduce it to a small test case and gather perl -V, as the manual advises. Do not paste security-sensitive input into a public issue. The release notes point to perlbug for ordinary reports and a private Perl security address for Perl-core security issues; follow the reporting policy appropriate to the version you actually run.

There is no undo step because every example above only reads documentation or reports version information. If you created /tmp/perl5142delta.txt, remove that single temporary file after checking it, and leave the installed packages untouched.

Done means

  • You confirmed the running Perl version and the installed perl-doc package version.
  • You read the local perl5142delta page rather than treating its title as the current interpreter version.
  • You reviewed the two recorded security fixes without attempting to reproduce them.
  • You checked relevant module versions on the host under review.
  • You separated historical 5.14.2 changes from current Perl behaviour and platform notes.
  • You have an upgrade test plan for code touching external input, module loading or Perl internals.