Security Advisories (1)
CVE-2025-40909 (2025-05-30)

Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit. The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6

NAME

Test2::IPC::Driver::Files - Temp dir + Files concurrency model.

DESCRIPTION

This is the default, and fallback concurrency model for Test2. This sends events between processes and threads using serialized files in a temporary directory. This is not particularly fast, but it works everywhere.

SYNOPSIS

use Test2::IPC::Driver::Files;

# IPC is now enabled

ENVIRONMENT VARIABLES

T2_KEEP_TEMPDIR=0

When true, the tempdir used by the IPC driver will not be deleted when the test is done.

T2_TEMPDIR_TEMPLATE='test2-XXXXXX'

This can be used to set the template for the IPC temp dir. The template should follow template specifications from File::Temp.

SEE ALSO

See Test2::IPC::Driver for methods.

SOURCE

The source code repository for Test2 can be found at https://github.com/Test-More/test-more/.

MAINTAINERS

Chad Granum <exodist@cpan.org>

AUTHORS

Chad Granum <exodist@cpan.org>

COPYRIGHT

Copyright Chad Granum <exodist@cpan.org>.

This program is free software; you can redistribute it and/or modify it under the same terms as Perl itself.

See https://dev.perl.org/licenses/