Reviewing Perl 5 . in @INC at the Perl Toolchain Summit
Location: Lyon, France
Date: 12 May 2017
Attending: SawyerX, Merijn (Tux) Brand, Todd (toddr) Rinaldo, Nicolas (atoomic) Rochelemagne, Lee Johnson, Aaron (arc) Crane, Leon (leont) Timmermans, Matthew (alh) Horsfall, Kenichi (charsbar) Ishigaki, Graham (haarg) Knop, Karen (ether) Etheridge, Stefan (nine) Seifert, Aristotle
We met to discuss the recent changes to @INC for Perl 5.26.
A timeline and summary of CVE-2016-1238 was given to attendees. P5P has not yet disclosed the original report that led to removal of . from @INC in 5.26 but will be doing so soon. It was requested that this be delayed due to the severity of the original bug.
As of 5.26.0, Perl will be compiled without . in @INC by default. There is a Configure option (-Udefault_inc_excludes_dot
) to revert Perl to its 5.24 behavior but this is not recommended.