14514f5e3Sopenharmony_ci/* 24514f5e3Sopenharmony_ci * Copyright (c) 2022 Huawei Device Co., Ltd. 34514f5e3Sopenharmony_ci * Licensed under the Apache License, Version 2.0 (the "License"); 44514f5e3Sopenharmony_ci * you may not use this file except in compliance with the License. 54514f5e3Sopenharmony_ci * You may obtain a copy of the License at 64514f5e3Sopenharmony_ci * 74514f5e3Sopenharmony_ci * http://www.apache.org/licenses/LICENSE-2.0 84514f5e3Sopenharmony_ci * 94514f5e3Sopenharmony_ci * Unless required by applicable law or agreed to in writing, software 104514f5e3Sopenharmony_ci * distributed under the License is distributed on an "AS IS" BASIS, 114514f5e3Sopenharmony_ci * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 124514f5e3Sopenharmony_ci * See the License for the specific language governing permissions and 134514f5e3Sopenharmony_ci * limitations under the License. 144514f5e3Sopenharmony_ci */ 154514f5e3Sopenharmony_ci 164514f5e3Sopenharmony_ci#include "containershashsetclear_fuzzer.h" 174514f5e3Sopenharmony_ci 184514f5e3Sopenharmony_ci#include "ecmascript/containers/containers_hashset.h" 194514f5e3Sopenharmony_ci#include "ecmascript/containers/containers_private.h" 204514f5e3Sopenharmony_ci#include "ecmascript/ecma_string-inl.h" 214514f5e3Sopenharmony_ci#include "ecmascript/ecma_vm.h" 224514f5e3Sopenharmony_ci#include "ecmascript/global_env.h" 234514f5e3Sopenharmony_ci#include "ecmascript/js_handle.h" 244514f5e3Sopenharmony_ci#include "ecmascript/napi/include/jsnapi.h" 254514f5e3Sopenharmony_ci 264514f5e3Sopenharmony_ciusing namespace panda; 274514f5e3Sopenharmony_ciusing namespace panda::ecmascript; 284514f5e3Sopenharmony_ciusing namespace panda::ecmascript::containers; 294514f5e3Sopenharmony_ci 304514f5e3Sopenharmony_ci#define MAXBYTELEN sizeof(uint32_t) 314514f5e3Sopenharmony_ci 324514f5e3Sopenharmony_cinamespace OHOS { 334514f5e3Sopenharmony_ci 344514f5e3Sopenharmony_ci JSFunction *JSObjectCreate(JSThread *thread) 354514f5e3Sopenharmony_ci { 364514f5e3Sopenharmony_ci EcmaVM *ecmaVM = thread->GetEcmaVM(); 374514f5e3Sopenharmony_ci JSHandle<GlobalEnv> globalEnv = ecmaVM->GetGlobalEnv(); 384514f5e3Sopenharmony_ci return globalEnv->GetObjectFunction().GetObject<JSFunction>(); 394514f5e3Sopenharmony_ci } 404514f5e3Sopenharmony_ci 414514f5e3Sopenharmony_ci EcmaRuntimeCallInfo *CreateEcmaRuntimeCallInfo(JSThread *thread, uint32_t numArgs) 424514f5e3Sopenharmony_ci { 434514f5e3Sopenharmony_ci auto factory = thread->GetEcmaVM()->GetFactory(); 444514f5e3Sopenharmony_ci JSHandle<JSTaggedValue> hclass(thread, JSObjectCreate(thread)); 454514f5e3Sopenharmony_ci JSHandle<JSTaggedValue> callee(factory->NewJSObjectByConstructor(JSHandle<JSFunction>::Cast(hclass), hclass)); 464514f5e3Sopenharmony_ci JSHandle<JSTaggedValue> undefined = thread->GlobalConstants()->GetHandledUndefined(); 474514f5e3Sopenharmony_ci EcmaRuntimeCallInfo *objCallInfo = 484514f5e3Sopenharmony_ci EcmaInterpreter::NewRuntimeCallInfo(thread, undefined, callee, undefined, numArgs); 494514f5e3Sopenharmony_ci return objCallInfo; 504514f5e3Sopenharmony_ci } 514514f5e3Sopenharmony_ci JSTaggedValue InitializeHashSetConstructor(JSThread *thread) 524514f5e3Sopenharmony_ci { 534514f5e3Sopenharmony_ci ObjectFactory *factory = thread->GetEcmaVM()->GetFactory(); 544514f5e3Sopenharmony_ci JSHandle<GlobalEnv> env = thread->GetEcmaVM()->GetGlobalEnv(); 554514f5e3Sopenharmony_ci 564514f5e3Sopenharmony_ci JSHandle<JSTaggedValue> globalObject = env->GetJSGlobalObject(); 574514f5e3Sopenharmony_ci JSHandle<JSTaggedValue> key(factory->NewFromASCII("ArkPrivate")); 584514f5e3Sopenharmony_ci JSHandle<JSTaggedValue> value = 594514f5e3Sopenharmony_ci JSObject::GetProperty(thread, JSHandle<JSTaggedValue>(globalObject), key).GetValue(); 604514f5e3Sopenharmony_ci 614514f5e3Sopenharmony_ci auto objCallInfo = CreateEcmaRuntimeCallInfo(thread, 6); 624514f5e3Sopenharmony_ci objCallInfo->SetFunction(JSTaggedValue::Undefined()); 634514f5e3Sopenharmony_ci objCallInfo->SetThis(value.GetTaggedValue()); 644514f5e3Sopenharmony_ci objCallInfo->SetCallArg(0, JSTaggedValue(static_cast<int>(ContainerTag::HashSet))); 654514f5e3Sopenharmony_ci JSTaggedValue result = ContainersPrivate::Load(objCallInfo); 664514f5e3Sopenharmony_ci return result; 674514f5e3Sopenharmony_ci } 684514f5e3Sopenharmony_ci 694514f5e3Sopenharmony_ci JSHandle<JSAPIHashSet> CreateJSAPIHashSet(JSThread *thread) 704514f5e3Sopenharmony_ci { 714514f5e3Sopenharmony_ci JSHandle<JSFunction> newTarget(thread, InitializeHashSetConstructor(thread)); 724514f5e3Sopenharmony_ci auto objCallInfo = CreateEcmaRuntimeCallInfo(thread, 4); 734514f5e3Sopenharmony_ci objCallInfo->SetFunction(newTarget.GetTaggedValue()); 744514f5e3Sopenharmony_ci objCallInfo->SetNewTarget(newTarget.GetTaggedValue()); 754514f5e3Sopenharmony_ci objCallInfo->SetThis(JSTaggedValue::Undefined()); 764514f5e3Sopenharmony_ci 774514f5e3Sopenharmony_ci JSTaggedValue result = ContainersHashSet::HashSetConstructor(objCallInfo); 784514f5e3Sopenharmony_ci JSHandle<JSAPIHashSet> map(thread, result); 794514f5e3Sopenharmony_ci return map; 804514f5e3Sopenharmony_ci } 814514f5e3Sopenharmony_ci 824514f5e3Sopenharmony_ci void ContainersHashSetClearFuzzTest(const uint8_t* data, size_t size) 834514f5e3Sopenharmony_ci { 844514f5e3Sopenharmony_ci RuntimeOption option; 854514f5e3Sopenharmony_ci option.SetLogLevel(RuntimeOption::LOG_LEVEL::ERROR); 864514f5e3Sopenharmony_ci EcmaVM *vm = JSNApi::CreateJSVM(option); 874514f5e3Sopenharmony_ci { 884514f5e3Sopenharmony_ci JsiFastNativeScope scope(vm); 894514f5e3Sopenharmony_ci auto thread = vm->GetAssociatedJSThread(); 904514f5e3Sopenharmony_ci 914514f5e3Sopenharmony_ci uint32_t input; 924514f5e3Sopenharmony_ci if (size <= 0) { 934514f5e3Sopenharmony_ci return; 944514f5e3Sopenharmony_ci } 954514f5e3Sopenharmony_ci if (size > MAXBYTELEN) { 964514f5e3Sopenharmony_ci size = MAXBYTELEN; 974514f5e3Sopenharmony_ci } 984514f5e3Sopenharmony_ci if (memcpy_s(&input, MAXBYTELEN, data, size) != 0) { 994514f5e3Sopenharmony_ci std::cout << "memcpy_s failed!"; 1004514f5e3Sopenharmony_ci UNREACHABLE(); 1014514f5e3Sopenharmony_ci } 1024514f5e3Sopenharmony_ci 1034514f5e3Sopenharmony_ci JSHandle<JSAPIHashSet> hashSet = CreateJSAPIHashSet(thread); 1044514f5e3Sopenharmony_ci EcmaRuntimeCallInfo *callInfo = CreateEcmaRuntimeCallInfo(thread, 6); 1054514f5e3Sopenharmony_ci callInfo->SetFunction(JSTaggedValue::Undefined()); 1064514f5e3Sopenharmony_ci callInfo->SetThis(hashSet.GetTaggedValue()); 1074514f5e3Sopenharmony_ci callInfo->SetCallArg(0, JSTaggedValue(input)); 1084514f5e3Sopenharmony_ci [[maybe_unused]] JSTaggedValue resultAdd = ContainersHashSet::Add(callInfo); 1094514f5e3Sopenharmony_ci EcmaRuntimeCallInfo *callInfoIsEmpty = CreateEcmaRuntimeCallInfo(thread, 6); 1104514f5e3Sopenharmony_ci callInfoIsEmpty->SetFunction(JSTaggedValue::Undefined()); 1114514f5e3Sopenharmony_ci callInfoIsEmpty->SetThis(hashSet.GetTaggedValue()); 1124514f5e3Sopenharmony_ci ContainersHashSet::Clear(callInfoIsEmpty); 1134514f5e3Sopenharmony_ci } 1144514f5e3Sopenharmony_ci JSNApi::DestroyJSVM(vm); 1154514f5e3Sopenharmony_ci } 1164514f5e3Sopenharmony_ci} 1174514f5e3Sopenharmony_ci 1184514f5e3Sopenharmony_ci// Fuzzer entry point. 1194514f5e3Sopenharmony_ciextern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) 1204514f5e3Sopenharmony_ci{ 1214514f5e3Sopenharmony_ci // Run your code on data. 1224514f5e3Sopenharmony_ci OHOS::ContainersHashSetClearFuzzTest(data, size); 1234514f5e3Sopenharmony_ci return 0; 1244514f5e3Sopenharmony_ci}