Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

[Bug] [netdev] ping crashes the shell with a division by zero when the target is unreachable (received == 0)

Offen Anfängerfreundlich
#11,852 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

@r3wretrhy arbeitet bereits daran.

Seit 06.10.2026.

  • #11853 von @r3wretrhy — offen

Bewertung

Schwierigkeit
1/5
Geschätzter Aufwand
Unter einer Stunde
Anfängerfreundlichkeit
90/100
Issue-Typ
Bug
Klarheit
Klar beschrieben
Aktivitätsstatus
Aktiv
Tech-Stack
c
Bereich
networking

Rechercherichtung

Beginne in components/net/netdev/src/netdev.c, Funktion netdev_cmd_ping, um Zeile 1428, wo avg_time = (uint32_t)(avg_time / received) vor dem bestehenden if (received > 0) Guard vier Zeilen darunter ausgeführt wird; verschiebe oder dupliziere diesen Guard um die Division herum. Verifiziere durch Bauen von bsp/simulator, Registrieren eines netdev, dessen ops->ping -RT_ETIMEOUT mit flags UP|LINK_UP zurückgibt, Ausführen von 'ping 192.0.2.1' in msh und Bestätigen, dass die Statistik mit 100% Verlust statt mit einem FPE ausgegeben wird. Fertig = kein Fault und der Pfad für ein nicht erreichbares Ziel gibt weiterhin Verluststatistiken aus.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

bug Component component: net
RT-Thread Version

master c3e94f7b (2026-09-23)

Affected area

Networking

Hardware/BSP vendor

Not applicable / Other

Architecture

Not applicable / Other

Board and hardware details

bsp/simulator on Linux x86-64 (kernel ASan enabled by the BSP) — no real board required; the defect is in the generic netdev layer (components/net/netdev/src/netdev.c).

Develop Toolchain

GCC

Describe the bug

netdev_cmd_ping() divides by the reply counter received when printing
statistics, without checking it is non-zero. When every ping attempt times
out (target unreachable — the most common diagnostic scenario), received
stays 0 and the integer division faults: SIGFPE on x86, division-by-zero
HardFault on Cortex-M. The shell thread (rt_kprintf side) dies — the msh
console becomes unusable or the device resets.

Note the guard exists but guards the wrong statement — four lines below the
division:

/* components/net/netdev/src/netdev.c:1428 (master 005d291) */
avg_time = (uint32_t)(avg_time / received);      /* received == 0 -> fault */
...
if (received > 0)                                 /* guard only here */
{
    rt_kprintf("minimum = %dms, ...\n", min_time, max_time, avg_time);
}

Steps to reproduce (any device with ops->ping implemented, up and
link-up — default for a configured netdev):

  1. Register a test netdev through the public API with ops->ping returning
    -RT_ETIMEOUT and flags UP | LINK_UP:
/* in the simulator app, before running "ping" */
static rt_err_t test_ping(struct netdev *d, const char *h, size_t s,
                          struct netdev_ping_resp *r) { return -RT_ETIMEOUT; }
/* netdev_register() with ops = {..., .ping = test_ping}, flags UP|LINK_UP */
  1. Run the standard shell entry:
msh> ping 192.0.2.1
  1. After the 4 timeouts, the statistics path divides by zero:
AddressSanitizer: FPE on unknown address 0x...
    #0 netdev_cmd_ping components/net/netdev/src/netdev.c:1428

(Control: the same netdev registered without LINK_UP returns cleanly
via the guard path — "ping: ... status error", no fault. The division is the
sole crash point.)

Expected behavior: statistics print with 100% loss and no average, no
fault — one-line fix mirroring the existing guard:

if (received > 0) avg_time = (uint32_t)(avg_time / received);
Other additional context
  • The fault hits the shell thread, so the console/monitoring channel dies
    until reset — DoS of the management interface from a routine operation.
Vorherrschende Sprache
C
Sterne
12.3k
Forks
5.5k
Ø Merge
4 T. 12 Std.
Gemergte PRs (30 T.)
32

Entwicklungsumgebung

In Codespaces öffnen

Startet den Dev-Container des Projekts im Browser, mit Ihrem eigenen GitHub-Konto.

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus RT-Thread/rt-thread

Alle Issues in RT-Thread/rt-thread

Ähnliche Issues

Weitere Issues zu C

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.