Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

[Bug] [netdev] ping crashes the shell with a division by zero when the target is unreachable (received == 0)

未关闭 适合新手
#11,852 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
1/5
预计耗时
1 小时以内
新手友好度
90/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
技术栈
c
领域
networking

调研方向

从 components/net/netdev/src/netdev.c 的 netdev_cmd_ping 函数开始,大约在第 1428 行,avg_time = (uint32_t)(avg_time / received) 在四行之下已有的 if (received > 0) 守卫之前执行;将该守卫移动或复制到除法周围。通过构建 bsp/simulator、注册一个 ops->ping 以 flags UP|LINK_UP 返回 -RT_ETIMEOUT 的 netdev、在 msh 中运行 'ping 192.0.2.1',并确认统计数据打印出 100% loss 而非 FPE 来验证。完成 = 没有 fault,且不可达目标的路径仍然打印 loss 统计。

由索引模型根据 Issue 内容生成。

描述

bug Component component: net
RT-Thread Version

master c3e94f7b (2026-09-23)

Affected area

Networking

Hardware/BSP vendor

Not applicable / Other

Architecture

Not applicable / Other

Board and hardware details

bsp/simulator on Linux x86-64 (kernel ASan enabled by the BSP) — no real board required; the defect is in the generic netdev layer (components/net/netdev/src/netdev.c).

Develop Toolchain

GCC

Describe the bug

netdev_cmd_ping() divides by the reply counter received when printing
statistics, without checking it is non-zero. When every ping attempt times
out (target unreachable — the most common diagnostic scenario), received
stays 0 and the integer division faults: SIGFPE on x86, division-by-zero
HardFault on Cortex-M. The shell thread (rt_kprintf side) dies — the msh
console becomes unusable or the device resets.

Note the guard exists but guards the wrong statement — four lines below the
division:

/* components/net/netdev/src/netdev.c:1428 (master 005d291) */
avg_time = (uint32_t)(avg_time / received);      /* received == 0 -> fault */
...
if (received > 0)                                 /* guard only here */
{
    rt_kprintf("minimum = %dms, ...\n", min_time, max_time, avg_time);
}

Steps to reproduce (any device with ops->ping implemented, up and
link-up — default for a configured netdev):

  1. Register a test netdev through the public API with ops->ping returning
    -RT_ETIMEOUT and flags UP | LINK_UP:
/* in the simulator app, before running "ping" */
static rt_err_t test_ping(struct netdev *d, const char *h, size_t s,
                          struct netdev_ping_resp *r) { return -RT_ETIMEOUT; }
/* netdev_register() with ops = {..., .ping = test_ping}, flags UP|LINK_UP */
  1. Run the standard shell entry:
msh> ping 192.0.2.1
  1. After the 4 timeouts, the statistics path divides by zero:
AddressSanitizer: FPE on unknown address 0x...
    #0 netdev_cmd_ping components/net/netdev/src/netdev.c:1428

(Control: the same netdev registered without LINK_UP returns cleanly
via the guard path — "ping: ... status error", no fault. The division is the
sole crash point.)

Expected behavior: statistics print with 100% loss and no average, no
fault — one-line fix mirroring the existing guard:

if (received > 0) avg_time = (uint32_t)(avg_time / received);
Other additional context
  • The fault hits the shell thread, so the console/monitoring channel dies
    until reset — DoS of the management interface from a routine operation.
主要语言
C
星标
12.3k
派生
5.5k
平均合并
4 天 12 小时
30 天内合并 PR
32

环境准备

在 Codespaces 中打开

在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

RT-Thread/rt-thread 的其他 Issue

查看 RT-Thread/rt-thread 的全部 Issue

相似的 Issue

更多 C Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。