Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

[Bug] [netdev] ping crashes the shell with a division by zero when the target is unreachable (received == 0)

オープン 初心者向け
#11,852 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

@r3wretrhy がすでに取り組んでいます。

2026年10月6日 から。

  • #11853 @r3wretrhy による — オープン

評価

難易度
1/5
見積もり時間
1時間未満
初心者へのやさしさ
90/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
c
領域
networking

調査の方向性

components/net/netdev/src/netdev.c の関数 netdev_cmd_ping、おおむね1428行目付近にある avg_time = (uint32_t)(avg_time / received) が、4行下にある既存の if (received > 0) ガードの前に実行されている箇所から始める。そのガードを割り算の周りに移動するか複製する。bsp/simulator をビルドし、ops->ping が flags UP|LINK_UP で -RT_ETIMEOUT を返す netdev を登録し、msh で 'ping 192.0.2.1' を実行して、FPE の代わりに 100% loss の統計が出力されることを確認する。完了 = fault がなく、到達不能なターゲットの経路でも loss 統計が出力され続けること。

索引モデルが issue の本文から書いたものです。

説明

bug Component component: net
RT-Thread Version

master c3e94f7b (2026-09-23)

Affected area

Networking

Hardware/BSP vendor

Not applicable / Other

Architecture

Not applicable / Other

Board and hardware details

bsp/simulator on Linux x86-64 (kernel ASan enabled by the BSP) — no real board required; the defect is in the generic netdev layer (components/net/netdev/src/netdev.c).

Develop Toolchain

GCC

Describe the bug

netdev_cmd_ping() divides by the reply counter received when printing
statistics, without checking it is non-zero. When every ping attempt times
out (target unreachable — the most common diagnostic scenario), received
stays 0 and the integer division faults: SIGFPE on x86, division-by-zero
HardFault on Cortex-M. The shell thread (rt_kprintf side) dies — the msh
console becomes unusable or the device resets.

Note the guard exists but guards the wrong statement — four lines below the
division:

/* components/net/netdev/src/netdev.c:1428 (master 005d291) */
avg_time = (uint32_t)(avg_time / received);      /* received == 0 -> fault */
...
if (received > 0)                                 /* guard only here */
{
    rt_kprintf("minimum = %dms, ...\n", min_time, max_time, avg_time);
}

Steps to reproduce (any device with ops->ping implemented, up and
link-up — default for a configured netdev):

  1. Register a test netdev through the public API with ops->ping returning
    -RT_ETIMEOUT and flags UP | LINK_UP:
/* in the simulator app, before running "ping" */
static rt_err_t test_ping(struct netdev *d, const char *h, size_t s,
                          struct netdev_ping_resp *r) { return -RT_ETIMEOUT; }
/* netdev_register() with ops = {..., .ping = test_ping}, flags UP|LINK_UP */
  1. Run the standard shell entry:
msh> ping 192.0.2.1
  1. After the 4 timeouts, the statistics path divides by zero:
AddressSanitizer: FPE on unknown address 0x...
    #0 netdev_cmd_ping components/net/netdev/src/netdev.c:1428

(Control: the same netdev registered without LINK_UP returns cleanly
via the guard path — "ping: ... status error", no fault. The division is the
sole crash point.)

Expected behavior: statistics print with 100% loss and no average, no
fault — one-line fix mirroring the existing guard:

if (received > 0) avg_time = (uint32_t)(avg_time / received);
Other additional context
  • The fault hits the shell thread, so the console/monitoring channel dies
    until reset — DoS of the management interface from a routine operation.
主要言語
C
スター
12.3k
フォーク
5.5k
平均マージ
3日 8時間
マージ済み PR(30日)
27

環境構築

Codespaces で開く

このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

RT-Thread/rt-thread のほかの issue

RT-Thread/rt-thread の issue をすべて見る

似ている issue

C の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。