Home / Alt manpages / perl5242delta(1)

  • perl5242delta(1)
  • User command
  • linux

Use perl5242delta to Audit a Perl 5.24.2 Upgrade

You will finish with a small audit for a Perl 5.24.2 upgrade: identify what the delta document actually covers, check the interpreter and core module versions on a Linux host, and test the security-sensitive PATH rule without changing system configuration. Allow about fifteen minutes. You need a shell and the perl-doc package for the local manual page. No elevated privileges are needed.

There is one version trap up front. perl5242delta is documentation, not an executable that upgrades Perl. It describes changes between Perl 5.24.1 and 5.24.2. The installed machine used for these examples has Perl 5.38.2 and perl-doc 5.38.2-3.2ubuntu0.6, so its current module versions are useful for comparison but are not proof that a host runs 5.24.2.

1. Read the local delta document

Start with the installed copy. This is an ordinary, read-only command:

$ man 1 perl5242delta

The document is deliberately narrow. It records two security changes, two core module updates, and one selected bug fix. It does not list every change in the Perl release. If you are moving from 5.24.0, read perl5241delta as well, because the 5.24.2 page assumes that the 5.24.1 changes are already known.

Checkpoint: find these headings in the page:

  • Improved handling of '.' in @INC in base.pm
  • "Escaped" colons and relative paths in PATH
  • Updated Modules and Pragmata
  • Selected Bug Fixes

If your local page does not show those headings, stop. You may be reading a different document, an incomplete package, or a page for another Perl release.

2. Confirm which Perl you are auditing

Use the interpreter on the same PATH as the application or service. Do not infer its version from the name of the documentation package:

$ command -v perl
/usr/bin/perl
$ perl -v | sed -n '1,8p'

This is perl 5, version 38, subversion 2 (v5.38.2) built for x86_64-linux-gnu-thread-multi
...
$ dpkg-query -W -f='${Package} ${Version}\n' perl perl-doc
perl 5.38.2-3.2ubuntu0.6
perl-doc 5.38.2-3.2ubuntu0.6

On another distribution, use its package query tool, but keep the interpreter check. A host can have several Perl installations, and a service may use an absolute path, a virtual environment, or a different container image.

Checkpoint: record the complete perl -v result and the output of command -v perl in the upgrade notes. If the result is not 5.24.2, this page is historical context rather than a direct statement about the running interpreter.

3. Compare the core modules without changing them

The delta document says that base moved from 2.23 to 2.23_01 and Module::CoreList moved from 5.20170114_24 to 5.20170715_24. Ask the current interpreter what it has:

$ perl -Mbase -e 'print "base $base::VERSION\n"'
base 2.27
$ perl -MModule::CoreList -e 'print "Module::CoreList $Module::CoreList::VERSION\n"'
Module::CoreList 5.20231129

Those values are expected on the example Perl 5.38.2 installation. They are not a failed 5.24.2 check: later Perl releases naturally contain later module versions. The useful question is whether the application is using the interpreter you identified and whether its package update brought the expected release family with it.

Do not install an older module merely to reproduce the numbers in the historical page. That would change the runtime and could create a new dependency problem. For a precise 5.24.2 compatibility investigation, use an isolated test image or a disposable build environment.

4. Test the fixed PATH boundary safely

The PATH fix matters when Perl runs an external program in taint mode. On Unix, relative directories in PATH are unsafe because a command can be found relative to the current working directory. The 5.24.2 change also closes a case where a backslash appeared to escape a colon, even though the operating system still treats the colon as a PATH separator.

First run a harmless child process with an explicitly trusted PATH. The assignment occurs inside Perl so taint mode can accept the value after you have chosen it:

$ perl -T -e '$ENV{PATH} = "/usr/bin:/bin"; system "true"; print "status=$?\n"'
status=0

Now try a PATH containing a relative entry. This does not create a file, start a service, or alter the host. It should be rejected by taint mode before true runs:

$ perl -T -e '$ENV{PATH} = "/\\:."; system "true"; print "status=$?\n"'
Insecure directory in $ENV{PATH} while running with -T switch at -e line 1.

The exact diagnostic wording can vary with the Perl build. The important result is that the command does not report status=0. Treat a relative PATH as a deployment error, not as a warning to suppress.

For a real service, set a known absolute PATH in its service definition or launcher, then verify the service with its normal non-destructive health check. That may require elevated privileges to inspect or edit, and it is outside this guide. Do not edit a unit file or restart a production service just to test the manual page.

5. Treat the @INC and substitution fixes as upgrade requirements

The other security item concerns removal of the current-directory entry, ., from Perl's module search path in base.pm. A module found in the working directory can be loaded accidentally when a program expects only trusted library locations. The delta says that the handling introduced in 5.24.1 was improved in 5.24.2.

Do not try to prove this by adding files to a production working directory. Instead, inspect the interpreter's search path and application startup configuration:

$ perl -V | sed -n '/^  @INC:/,/^$/p'
$ perl -e 'print join("\n", @INC), "\n"'

Look for an unexpected empty entry or a literal current-directory entry in the path used by the application. The output is host-specific, so there is no single correct list to paste into a runbook. If the application intentionally loads local libraries, make that location explicit and controlled rather than relying on the current directory.

The selected bug fix covers a crash in a locale-aware substitution, written as s///l, when Perl incorrectly treated non-UTF-8 data as UTF-8. You do not need to manufacture a crashing input to validate an upgrade. Confirm the interpreter version, run the application's regression tests with locale coverage, and record failures with a minimal test case if one appears.

6. Record the result and stop at the boundary

The page also points maintainers to perlbug and asks for a trimmed test case plus perl -V. If you find a reproducible problem, preserve the command, input, locale, interpreter path and full version output. Security-sensitive reports should follow Perl's private vulnerability-reporting guidance rather than being posted to a public list.

Nothing in this guide changes Perl, the PATH of another process, @INC, a service definition, or a running service. If you changed a shell variable while experimenting, close that shell or run unset PATH only if you deliberately replaced your interactive PATH. The examples above change only the environment of their short-lived Perl process.

Done means

  • You read the local perl5242delta page and confirmed it describes 5.24.1 to 5.24.2.
  • You recorded the actual Perl binary and version used by the host or application.
  • You checked base and Module::CoreList without changing installed modules.
  • You verified that taint mode rejects the unsafe relative PATH example.
  • You separated historical 5.24.2 fixes from claims about the installed Perl release.