Security Advisories (1)
CVE-2025-40909 (2025-05-30)

Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit. The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6

NAME

Test2::Tools::AsyncSubtest - Tools for writing async subtests.

DESCRIPTION

These are tools for writing async subtests. Async subtests are subtests which can be started and stashed so that they can continue to receive events while other events are also being generated.

SYNOPSIS

use Test2::Bundle::Extended;
use Test2::Tools::AsyncSubtest;

my $ast1 = async_subtest local => sub {
    ok(1, "Inside subtest");
};

my $ast2 = fork_subtest child => sub {
    ok(1, "Inside subtest in another process");
};

# You must call finish on the subtests you create. Finish will wait/join on
# any child processes and threads.
$ast1->finish;
$ast2->finish;

done_testing;

EXPORTS

Everything is exported by default.

$ast = async_subtest $name
$ast = async_subtest $name => sub { ... }
$ast = async_subtest $name => \%hub_params, sub { ... }

Create an async subtest. Run the codeblock if it is provided.

$ast = fork_subtest $name => sub { ... }
$ast = fork_subtest $name => \%hub_params, sub { ... }

Create an async subtest. Run the codeblock in a forked process.

$ast = thread_subtest $name => sub { ... }
$ast = thread_subtest $name => \%hub_params, sub { ... }

** DISCOURAGED ** Threads are fragile. Thread tests are not even run unless the AUTHOR_TESTING or T2_DO_THREAD_TESTS env vars are enabled.

Create an async subtest. Run the codeblock in a thread.

NOTES

Async Subtests are always buffered.

Always buffered.

Do not use done_testing() yourself.

using done_testing() inside an async subtest will not work properly, the async subtest must be finalized by calling $st->finish.

SOURCE

The source code repository for Test2-AsyncSubtest can be found at https://github.com/Test-More/test-more/.

MAINTAINERS

Chad Granum <exodist@cpan.org>

AUTHORS

Chad Granum <exodist@cpan.org>

COPYRIGHT

Copyright Chad Granum <exodist7@gmail.com>.

This program is free software; you can redistribute it and/or modify it under the same terms as Perl itself.

See http://dev.perl.org/licenses/