Changes for version 1.19_01 - 2026-10-10
- Fix Class::XSAccessor::Array method installation: ensure getters and predicates are not accidentally overwritten as read-write accessors.
- Use key length comparison and memcmp instead of strcmp in hash registry to prevent key aliasing on embedded NUL bytes and improve lookup speed; eliminate redundant key re-allocation on shared hash keys and enforce bounded key copy in hash table storage (XSA-04, XSA-05).
- Safe package stash resolution and invocant validation in constructors: use gv_stashsv to support full package names, validate that invocants are defined and blessed (if references), and check for NULL stash (XSA-11).
- Validate hash key length against I32 limits to prevent integer wrapping and buffer overflows with excessive key lengths (XSA-05).
- Normalize old package separator (') to (::) in subroutine names and package parameters, and reject subroutine names containing embedded NUL bytes in both Perl and XS layers (XSA-03).
- Validate array index bounds (must be 0..10_000_000) to prevent negative index out-of-bounds access, realloc(0) deallocation, and excessive memory allocation, with portable IVdf error formatting (XSA-02).
- B::C compatibility fix (thanks, Todd Rinaldo)
- Clean up macros (thanks, Nicolas R)
- Re-enable erroneously disabled test (thanks, Peter Rabbitson)
Documentation
Modules
Generate fast XS accessors without runtime compilation
Generate fast XS accessors without runtime compilation
Guts you don't care about