develooper Front page | perl.perl5.porters | Postings from August 2021

Re: Pre-RFC: Configure option for whether to include taint support

Thread Previous | Thread Next
August 13, 2021 18:20
Re: Pre-RFC: Configure option for whether to include taint support
Message ID:
On Fri, 13 Aug 2021 at 11:31, Neil Bowers <> wrote:

> Anyway, I really wish we completely removed that misfeature, but if wecan't,
> adding it as an option to Configure is the next best thing.
> I think/hope that adding a Configure option is the first step on a path
> that looks something like the following:
>    1. Add Configure option, with taint included by default
>    2. Toggle so that taint isn’t included by default
>    3. Remove taint, so there isn’t a Configure option
> Once step 1 is done, we can find out how many things on CPAN break, and do
> something about those. We’d need to give people time to adjust, so I guess
> we’d have to stay on step 1 for at least two annual releases.

I can double check, but we have been running with this in all our builds
for ages. When we rolled it out I think we had some turbulence learning
which test files could be ignored/skipped, I think we might have pushed
some patches upstream so they would test that taint was available and skip
the test, and i think we also just built something into our build process
so we know what test files not to run. But other than build issues I am not
aware it caused any issues.

perl -Mre=debug -e "/just|another|perl|hacker/"

Thread Previous | Thread Next Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at | Group listing | About