fix: prevent division by zero in intHandler when no events received
@MarioHewardt 已经在做这个了。
开始于 2026年4月4日。
评估
这个 Issue 还没有评估数据。
描述
Summary
Fix a potential division by zero crash in the intHandler signal
handler when Sysmon is stopped before processing any events
(totalEvents == 0).
Problem
In intHandler(), the following line:
printf("Total events: %ld, bad events: %ld, ratio = %f\n",
totalEvents, badEvents, (double)badEvents / totalEvents);
...will produce a division by zero (resulting in NaN or crash) if
Sysmon is interrupted immediately after startup before any eBPF
events are received.
Fix
Guard the division with a ternary check:
(double)badEvents / totalEvents
→
totalEvents > 0 ? (double)badEvents / totalEvents : 0.0
Testing
- Start Sysmon and immediately send SIGINT (Ctrl+C)
- Confirm clean output showing ratio = 0.000000 instead of crash/NaN
Notes
- No functional change to normal operation
- Zero risk of regression
- Fixes undefined behavior per C standard (integer division by zero)
- 主要语言
- C
- 星标
- 2.2k
- 派生
- 220
- 平均合并
- 11 天 22 小时
- 30 天内合并 PR
- 2
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
microsoft/SysmonForLinux 的其他 Issue
-
microsoft/SysmonForLinux#238 · 已指派 1 人 ·
-
难度 4/5 3-5 天 新手友好度 35/100
microsoft/SysmonForLinux#233 ·
-
microsoft/SysmonForLinux#226 · 已指派 1 人 ·
-
难度 5/5 一周以上 新手友好度 25/100
microsoft/SysmonForLinux#220 · 2 个 reaction ·
-
microsoft/SysmonForLinux#219 · 1 条评论 · 已指派 1 人 ·
查看 microsoft/SysmonForLinux 的全部 Issue
相似的 Issue
-
bug
难度 1/5 1 小时以内 新手友好度 60/100
-
Nmap
难度 1/5 1 小时以内 新手友好度 85/100
-
难度 2/5 1-3 小时 新手友好度 65/100
-
难度 2/5 1-3 小时 新手友好度 65/100
-
flang:fir-hlfir
难度 2/5 1-3 小时 新手友好度 70/100
llvm/llvm-project#225935 ·