[Bug] [netdev] ping crashes the shell with a division by zero when the target is unreachable (received == 0)
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 1/5
- Tempo estimado
- Menos de uma hora
- Facilidade para iniciantes
- 90/100
- Tipo de issue
- Bug
- Clareza
- Claramente especificada
- Status de atividade
- Ativa
- Stack de tecnologia
- c
- Domínio
- networking
Direção de pesquisa
Comece em components/net/netdev/src/netdev.c, função netdev_cmd_ping, por volta da linha 1428, onde avg_time = (uint32_t)(avg_time / received) é executado antes do guard if (received > 0) existente quatro linhas abaixo; mova ou duplique esse guard em torno da divisão. Verifique compilando bsp/simulator, registrando um netdev cujo ops->ping retorna -RT_ETIMEOUT com flags UP|LINK_UP, executando 'ping 192.0.2.1' no msh e confirmando que as estatísticas são impressas com 100% de perda em vez de um FPE. Concluído = sem fault e o caminho do destino inalcançável continua imprimindo estatísticas de perda.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
RT-Thread Version
master c3e94f7b (2026-09-23)
Affected area
Networking
Hardware/BSP vendor
Not applicable / Other
Architecture
Not applicable / Other
Board and hardware details
bsp/simulator on Linux x86-64 (kernel ASan enabled by the BSP) — no real board required; the defect is in the generic netdev layer (components/net/netdev/src/netdev.c).
Develop Toolchain
GCC
Describe the bug
netdev_cmd_ping() divides by the reply counter received when printing
statistics, without checking it is non-zero. When every ping attempt times
out (target unreachable — the most common diagnostic scenario), received
stays 0 and the integer division faults: SIGFPE on x86, division-by-zero
HardFault on Cortex-M. The shell thread (rt_kprintf side) dies — the msh
console becomes unusable or the device resets.
Note the guard exists but guards the wrong statement — four lines below the
division:
/* components/net/netdev/src/netdev.c:1428 (master 005d291) */
avg_time = (uint32_t)(avg_time / received); /* received == 0 -> fault */
...
if (received > 0) /* guard only here */
{
rt_kprintf("minimum = %dms, ...\n", min_time, max_time, avg_time);
}
Steps to reproduce (any device with ops->ping implemented, up and
link-up — default for a configured netdev):
- Register a test netdev through the public API with
ops->pingreturning
-RT_ETIMEOUTand flagsUP | LINK_UP:
/* in the simulator app, before running "ping" */
static rt_err_t test_ping(struct netdev *d, const char *h, size_t s,
struct netdev_ping_resp *r) { return -RT_ETIMEOUT; }
/* netdev_register() with ops = {..., .ping = test_ping}, flags UP|LINK_UP */
- Run the standard shell entry:
msh> ping 192.0.2.1
- After the 4 timeouts, the statistics path divides by zero:
AddressSanitizer: FPE on unknown address 0x...
#0 netdev_cmd_ping components/net/netdev/src/netdev.c:1428
(Control: the same netdev registered without LINK_UP returns cleanly
via the guard path — "ping: ... status error", no fault. The division is the
sole crash point.)
Expected behavior: statistics print with 100% loss and no average, no
fault — one-line fix mirroring the existing guard:
if (received > 0) avg_time = (uint32_t)(avg_time / received);
Other additional context
- The fault hits the shell thread, so the console/monitoring channel dies
until reset — DoS of the management interface from a routine operation.
- Linguagem predominante
- C
- Estrelas
- 12.3k
- Forks
- 5.5k
- Merge médio
- 4d 12h
- PRs com merge (30d)
- 32
Preparar o ambiente
Inicia o contêiner de desenvolvimento do projeto no navegador, com a sua própria conta do GitHub.
- Sem Dockerfile nem arquivo Docker Compose
- Tem um modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de RT-Thread/rt-thread
-
[bsp][stm32][bluepill] README「快速上手」缺少重新生成 MDK 工程这一步,按文档操作无法编译通过Talvez já em andamento @moment-NEW assumiu há 3 dias. Abertain progress
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
RT-Thread/rt-thread#11818 · 4 comentários · 1 responsável ·
Mantenedores costumam responder em até 1 dia
-
BSP BSP: Loongson bug RT-Smart
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
RT-Thread/rt-thread#11717 · 2 comentários ·
Mantenedores costumam responder em até 1 dia
-
Arch: RISC-V BSP BSP: HPMicro bug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
RT-Thread/rt-thread#11687 · 3 comentários ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
RT-Thread/rt-thread#11472 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
[Bug] Heap Buffer Overflow in FinSH `msh_auto_complete_path` via Oversized InputTalvez já em andamento @Acen28 assumiu há 10 dias. AbertaArch: ARM/AArch64 BSP BSP: STM32 bug Component component: finsh in progress
RT-Thread/rt-thread#11839 · 3 comentários · 1 responsável ·
Mantenedores costumam responder em até 1 dia
Todas as issues de RT-Thread/rt-thread
Issues semelhantes
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 65/100
dkfans/keeperfx#5415 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 66/100
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 67/100
void-linux/void-runit#141 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
ARM-software/sysarch-acs#600 ·
Mantenedores costumam responder em até 1 dia
-
bug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
Mantenedores costumam responder em até 1 dia