[Bug] [netdev] ping crashes the shell with a division by zero when the target is unreachable (received == 0)
I maintainer di solito rispondono entro 1 giorno
Valutazione
- Difficoltà
- 1/5
- Tempo stimato
- Meno di un'ora
- Idoneità per principianti
- 90/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- c
- Ambito
- networking
Direzione di ricerca
Parti da components/net/netdev/src/netdev.c, funzione netdev_cmd_ping, intorno alla riga 1428 dove avg_time = (uint32_t)(avg_time / received) viene eseguito prima del guard if (received > 0) esistente quattro righe sotto; sposta o duplica quel guard attorno alla divisione. Verifica compilando bsp/simulator, registrando un netdev il cui ops->ping restituisce -RT_ETIMEOUT con flags UP|LINK_UP, eseguendo 'ping 192.0.2.1' in msh e confermando che le statistiche vengano stampate con 100% di perdita invece di un FPE. Fatto = nessun fault e il percorso del destinazione irraggiungibile stampa ancora le statistiche di perdita.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
RT-Thread Version
master c3e94f7b (2026-09-23)
Affected area
Networking
Hardware/BSP vendor
Not applicable / Other
Architecture
Not applicable / Other
Board and hardware details
bsp/simulator on Linux x86-64 (kernel ASan enabled by the BSP) — no real board required; the defect is in the generic netdev layer (components/net/netdev/src/netdev.c).
Develop Toolchain
GCC
Describe the bug
netdev_cmd_ping() divides by the reply counter received when printing
statistics, without checking it is non-zero. When every ping attempt times
out (target unreachable — the most common diagnostic scenario), received
stays 0 and the integer division faults: SIGFPE on x86, division-by-zero
HardFault on Cortex-M. The shell thread (rt_kprintf side) dies — the msh
console becomes unusable or the device resets.
Note the guard exists but guards the wrong statement — four lines below the
division:
/* components/net/netdev/src/netdev.c:1428 (master 005d291) */
avg_time = (uint32_t)(avg_time / received); /* received == 0 -> fault */
...
if (received > 0) /* guard only here */
{
rt_kprintf("minimum = %dms, ...\n", min_time, max_time, avg_time);
}
Steps to reproduce (any device with ops->ping implemented, up and
link-up — default for a configured netdev):
- Register a test netdev through the public API with
ops->pingreturning
-RT_ETIMEOUTand flagsUP | LINK_UP:
/* in the simulator app, before running "ping" */
static rt_err_t test_ping(struct netdev *d, const char *h, size_t s,
struct netdev_ping_resp *r) { return -RT_ETIMEOUT; }
/* netdev_register() with ops = {..., .ping = test_ping}, flags UP|LINK_UP */
- Run the standard shell entry:
msh> ping 192.0.2.1
- After the 4 timeouts, the statistics path divides by zero:
AddressSanitizer: FPE on unknown address 0x...
#0 netdev_cmd_ping components/net/netdev/src/netdev.c:1428
(Control: the same netdev registered without LINK_UP returns cleanly
via the guard path — "ping: ... status error", no fault. The division is the
sole crash point.)
Expected behavior: statistics print with 100% loss and no average, no
fault — one-line fix mirroring the existing guard:
if (received > 0) avg_time = (uint32_t)(avg_time / received);
Other additional context
- The fault hits the shell thread, so the console/monitoring channel dies
until reset — DoS of the management interface from a routine operation.
- Lingua principale
- C
- Stelle
- 12.3k
- Fork
- 5.5k
- Merge medio
- 4g 12h
- PR unite (30g)
- 32
Preparare l'ambiente
Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di RT-Thread/rt-thread
-
[bsp][stm32][bluepill] README「快速上手」缺少重新生成 MDK 工程这一步,按文档操作无法编译通过Forse già presa @moment-NEW l’ha presa 3 giorni fa. Apertain progress
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
RT-Thread/rt-thread#11818 · 4 commenti · 1 assegnatario ·
I maintainer di solito rispondono entro 1 giorno
-
BSP BSP: Loongson bug RT-Smart
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
RT-Thread/rt-thread#11717 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
Arch: RISC-V BSP BSP: HPMicro bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
RT-Thread/rt-thread#11687 · 3 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
RT-Thread/rt-thread#11472 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
[Bug] Heap Buffer Overflow in FinSH `msh_auto_complete_path` via Oversized InputForse già presa @Acen28 l’ha presa 11 giorni fa. ApertaArch: ARM/AArch64 BSP BSP: STM32 bug Component component: finsh in progress
RT-Thread/rt-thread#11839 · 3 commenti · 1 assegnatario ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di RT-Thread/rt-thread
Issue simili
-
[P2] Workspace updates silently ignore forbidden assignments while staging the rowForse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 70/100
I maintainer di solito rispondono entro 4 giorni
-
sdl3-image update to 3.4.8Apertacategory:port-update
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
microsoft/vcpkg#54338 · 1 commento ·
I maintainer di solito rispondono entro 2 giorni
-
area:http-gateway good first issue priority:low type:docs
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
crazy-goat/php-fpm-ng#828 ·
I maintainer di solito rispondono entro 1 giorno
-
enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 63/100
SunDevilRocketry/Flight-Computer-Firmware#347 ·
I maintainer di solito rispondono entro 3 giorni