[Bug] [netdev] ping crashes the shell with a division by zero when the target is unreachable (received == 0)
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 1/5
- 预计耗时
- 1 小时以内
- 新手友好度
- 90/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- c
- 领域
- networking
调研方向
从 components/net/netdev/src/netdev.c 的 netdev_cmd_ping 函数开始,大约在第 1428 行,avg_time = (uint32_t)(avg_time / received) 在四行之下已有的 if (received > 0) 守卫之前执行;将该守卫移动或复制到除法周围。通过构建 bsp/simulator、注册一个 ops->ping 以 flags UP|LINK_UP 返回 -RT_ETIMEOUT 的 netdev、在 msh 中运行 'ping 192.0.2.1',并确认统计数据打印出 100% loss 而非 FPE 来验证。完成 = 没有 fault,且不可达目标的路径仍然打印 loss 统计。
由索引模型根据 Issue 内容生成。
描述
RT-Thread Version
master c3e94f7b (2026-09-23)
Affected area
Networking
Hardware/BSP vendor
Not applicable / Other
Architecture
Not applicable / Other
Board and hardware details
bsp/simulator on Linux x86-64 (kernel ASan enabled by the BSP) — no real board required; the defect is in the generic netdev layer (components/net/netdev/src/netdev.c).
Develop Toolchain
GCC
Describe the bug
netdev_cmd_ping() divides by the reply counter received when printing
statistics, without checking it is non-zero. When every ping attempt times
out (target unreachable — the most common diagnostic scenario), received
stays 0 and the integer division faults: SIGFPE on x86, division-by-zero
HardFault on Cortex-M. The shell thread (rt_kprintf side) dies — the msh
console becomes unusable or the device resets.
Note the guard exists but guards the wrong statement — four lines below the
division:
/* components/net/netdev/src/netdev.c:1428 (master 005d291) */
avg_time = (uint32_t)(avg_time / received); /* received == 0 -> fault */
...
if (received > 0) /* guard only here */
{
rt_kprintf("minimum = %dms, ...\n", min_time, max_time, avg_time);
}
Steps to reproduce (any device with ops->ping implemented, up and
link-up — default for a configured netdev):
- Register a test netdev through the public API with
ops->pingreturning
-RT_ETIMEOUTand flagsUP | LINK_UP:
/* in the simulator app, before running "ping" */
static rt_err_t test_ping(struct netdev *d, const char *h, size_t s,
struct netdev_ping_resp *r) { return -RT_ETIMEOUT; }
/* netdev_register() with ops = {..., .ping = test_ping}, flags UP|LINK_UP */
- Run the standard shell entry:
msh> ping 192.0.2.1
- After the 4 timeouts, the statistics path divides by zero:
AddressSanitizer: FPE on unknown address 0x...
#0 netdev_cmd_ping components/net/netdev/src/netdev.c:1428
(Control: the same netdev registered without LINK_UP returns cleanly
via the guard path — "ping: ... status error", no fault. The division is the
sole crash point.)
Expected behavior: statistics print with 100% loss and no average, no
fault — one-line fix mirroring the existing guard:
if (received > 0) avg_time = (uint32_t)(avg_time / received);
Other additional context
- The fault hits the shell thread, so the console/monitoring channel dies
until reset — DoS of the management interface from a routine operation.
- 主要语言
- C
- 星标
- 12.3k
- 派生
- 5.5k
- 平均合并
- 4 天 12 小时
- 30 天内合并 PR
- 32
环境准备
在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
RT-Thread/rt-thread 的其他 Issue
-
[bsp][stm32][bluepill] README「快速上手」缺少重新生成 MDK 工程这一步,按文档操作无法编译通过可能已有人在做 @moment-NEW 于 3 天前认领。 未关闭in progress
难度 2/5 1-3 小时 新手友好度 75/100
RT-Thread/rt-thread#11818 · 4 条评论 · 已指派 1 人 ·
维护者通常 1 天内回复
-
BSP BSP: Loongson bug RT-Smart
难度 2/5 1-3 小时 新手友好度 72/100
RT-Thread/rt-thread#11717 · 2 条评论 ·
维护者通常 1 天内回复
-
Arch: RISC-V BSP BSP: HPMicro bug
难度 2/5 1-3 小时 新手友好度 72/100
RT-Thread/rt-thread#11687 · 3 条评论 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
RT-Thread/rt-thread#11472 · 1 条评论 ·
维护者通常 1 天内回复
-
[Bug] Heap Buffer Overflow in FinSH `msh_auto_complete_path` via Oversized Input可能已有人在做 @Acen28 于 10 天前认领。 未关闭Arch: ARM/AArch64 BSP BSP: STM32 bug Component component: finsh in progress
RT-Thread/rt-thread#11839 · 3 条评论 · 已指派 1 人 ·
维护者通常 1 天内回复
查看 RT-Thread/rt-thread 的全部 Issue
相似的 Issue
-
bug
难度 2/5 1-3 小时 新手友好度 74/100
EchoTools/nevr-runtime#117 · 2 条评论 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 67/100
DarkFlippers/qUnleashed#240 ·
维护者通常 1 天内回复
-
enhancement
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 84/100
AFLplusplus/AFLplusplus#2899 ·
-
难度 2/5 1-3 小时 新手友好度 78/100
HarbourMasters/Shipwright#7320 ·
维护者通常 1 天内回复