Changes for version 1.19_01 - 2026-10-10

  • Fix Class::XSAccessor::Array method installation: ensure getters and predicates are not accidentally overwritten as read-write accessors.
  • Use key length comparison and memcmp instead of strcmp in hash registry to prevent key aliasing on embedded NUL bytes and improve lookup speed; eliminate redundant key re-allocation on shared hash keys and enforce bounded key copy in hash table storage (XSA-04, XSA-05).
  • Safe package stash resolution and invocant validation in constructors: use gv_stashsv to support full package names, validate that invocants are defined and blessed (if references), and check for NULL stash (XSA-11).
  • Validate hash key length against I32 limits to prevent integer wrapping and buffer overflows with excessive key lengths (XSA-05).
  • Normalize old package separator (') to (::) in subroutine names and package parameters, and reject subroutine names containing embedded NUL bytes in both Perl and XS layers (XSA-03).
  • Validate array index bounds (must be 0..10_000_000) to prevent negative index out-of-bounds access, realloc(0) deallocation, and excessive memory allocation, with portable IVdf error formatting (XSA-02).
  • B::C compatibility fix (thanks, Todd Rinaldo)
  • Clean up macros (thanks, Nicolas R)
  • Re-enable erroneously disabled test (thanks, Peter Rabbitson)

Documentation

Modules

Generate fast XS accessors without runtime compilation
Generate fast XS accessors without runtime compilation
Guts you don't care about