[Bug] [netdev] ping crashes the shell with a division by zero when the target is unreachable (received == 0)
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 1/5
- Thời gian dự kiến
- Dưới một giờ
- Mức phù hợp với người mới
- 90/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- c
- Lĩnh vực
- networking
Hướng nghiên cứu
Bắt đầu tại components/net/netdev/src/netdev.c, hàm netdev_cmd_ping, quanh dòng 1428 nơi avg_time = (uint32_t)(avg_time / received) được thực thi trước guard if (received > 0) có sẵn bốn dòng bên dưới; di chuyển hoặc nhân bản guard đó quanh phép chia. Kiểm chứng bằng cách build bsp/simulator, đăng ký một netdev có ops->ping trả về -RT_ETIMEOUT với flags UP|LINK_UP, chạy 'ping 192.0.2.1' trong msh và xác nhận thống kê được in ra với 100% loss thay vì một FPE. Xong = không có fault và đường dẫn tới đích không thể truy cập vẫn in ra thống kê loss.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
RT-Thread Version
master c3e94f7b (2026-09-23)
Affected area
Networking
Hardware/BSP vendor
Not applicable / Other
Architecture
Not applicable / Other
Board and hardware details
bsp/simulator on Linux x86-64 (kernel ASan enabled by the BSP) — no real board required; the defect is in the generic netdev layer (components/net/netdev/src/netdev.c).
Develop Toolchain
GCC
Describe the bug
netdev_cmd_ping() divides by the reply counter received when printing
statistics, without checking it is non-zero. When every ping attempt times
out (target unreachable — the most common diagnostic scenario), received
stays 0 and the integer division faults: SIGFPE on x86, division-by-zero
HardFault on Cortex-M. The shell thread (rt_kprintf side) dies — the msh
console becomes unusable or the device resets.
Note the guard exists but guards the wrong statement — four lines below the
division:
/* components/net/netdev/src/netdev.c:1428 (master 005d291) */
avg_time = (uint32_t)(avg_time / received); /* received == 0 -> fault */
...
if (received > 0) /* guard only here */
{
rt_kprintf("minimum = %dms, ...\n", min_time, max_time, avg_time);
}
Steps to reproduce (any device with ops->ping implemented, up and
link-up — default for a configured netdev):
- Register a test netdev through the public API with
ops->pingreturning
-RT_ETIMEOUTand flagsUP | LINK_UP:
/* in the simulator app, before running "ping" */
static rt_err_t test_ping(struct netdev *d, const char *h, size_t s,
struct netdev_ping_resp *r) { return -RT_ETIMEOUT; }
/* netdev_register() with ops = {..., .ping = test_ping}, flags UP|LINK_UP */
- Run the standard shell entry:
msh> ping 192.0.2.1
- After the 4 timeouts, the statistics path divides by zero:
AddressSanitizer: FPE on unknown address 0x...
#0 netdev_cmd_ping components/net/netdev/src/netdev.c:1428
(Control: the same netdev registered without LINK_UP returns cleanly
via the guard path — "ping: ... status error", no fault. The division is the
sole crash point.)
Expected behavior: statistics print with 100% loss and no average, no
fault — one-line fix mirroring the existing guard:
if (received > 0) avg_time = (uint32_t)(avg_time / received);
Other additional context
- The fault hits the shell thread, so the console/monitoring channel dies
until reset — DoS of the management interface from a routine operation.
- Ngôn ngữ chính
- C
- Star
- 12.3k
- Fork
- 5.5k
- Merge trung bình
- 4 ngày 12 giờ
- Pull request đã merge (30 ngày)
- 32
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của RT-Thread/rt-thread
-
[bsp][stm32][bluepill] README「快速上手」缺少重新生成 MDK 工程这一步,按文档操作无法编译通过Có thể đã có người làm @moment-NEW đã nhận 2 ngày trước. Đang mởin progress
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
RT-Thread/rt-thread#11818 · 4 bình luận · 1 người được giao ·
Maintainer thường phản hồi trong vòng 1 ngày
-
BSP BSP: Loongson bug RT-Smart
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
RT-Thread/rt-thread#11717 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Arch: RISC-V BSP BSP: HPMicro bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
RT-Thread/rt-thread#11687 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
RT-Thread/rt-thread#11472 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[Bug] Heap Buffer Overflow in FinSH `msh_auto_complete_path` via Oversized InputCó thể đã có người làm @Acen28 đã nhận 9 ngày trước. Đang mởArch: ARM/AArch64 BSP BSP: STM32 bug Component component: finsh in progress
RT-Thread/rt-thread#11839 · 3 bình luận · 1 người được giao ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của RT-Thread/rt-thread
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
libsdl-org/SDL#16444 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
MiSTer-devel/ao486_MiSTer#243 ·
-
Dropped last row with parallel scan of attached SQLite tables if the rowid range is a multiple of 122,880Có thể đã có người làm @staticlibs đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
duckdb/duckdb-sqlite#240 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 66/100
siderolabs/pkgs#1710 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày