14514f5e3Sopenharmony_ci/*
24514f5e3Sopenharmony_ci * Copyright (c) 2022 Huawei Device Co., Ltd.
34514f5e3Sopenharmony_ci * Licensed under the Apache License, Version 2.0 (the "License");
44514f5e3Sopenharmony_ci * you may not use this file except in compliance with the License.
54514f5e3Sopenharmony_ci * You may obtain a copy of the License at
64514f5e3Sopenharmony_ci *
74514f5e3Sopenharmony_ci *     http://www.apache.org/licenses/LICENSE-2.0
84514f5e3Sopenharmony_ci *
94514f5e3Sopenharmony_ci * Unless required by applicable law or agreed to in writing, software
104514f5e3Sopenharmony_ci * distributed under the License is distributed on an "AS IS" BASIS,
114514f5e3Sopenharmony_ci * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
124514f5e3Sopenharmony_ci * See the License for the specific language governing permissions and
134514f5e3Sopenharmony_ci * limitations under the License.
144514f5e3Sopenharmony_ci */
154514f5e3Sopenharmony_ci
164514f5e3Sopenharmony_ci#include "containerslightweightmapat_fuzzer.h"
174514f5e3Sopenharmony_ci
184514f5e3Sopenharmony_ci#include "ecmascript/containers/containers_lightweightmap.h"
194514f5e3Sopenharmony_ci#include "ecmascript/containers/containers_private.h"
204514f5e3Sopenharmony_ci#include "ecmascript/ecma_string-inl.h"
214514f5e3Sopenharmony_ci#include "ecmascript/ecma_vm.h"
224514f5e3Sopenharmony_ci#include "ecmascript/global_env.h"
234514f5e3Sopenharmony_ci#include "ecmascript/js_handle.h"
244514f5e3Sopenharmony_ci#include "ecmascript/napi/include/jsnapi.h"
254514f5e3Sopenharmony_ci
264514f5e3Sopenharmony_ciusing namespace panda;
274514f5e3Sopenharmony_ciusing namespace panda::test;
284514f5e3Sopenharmony_ciusing namespace panda::ecmascript;
294514f5e3Sopenharmony_ciusing namespace panda::ecmascript::containers;
304514f5e3Sopenharmony_ci
314514f5e3Sopenharmony_cinamespace OHOS {
324514f5e3Sopenharmony_ci
334514f5e3Sopenharmony_ci    JSFunction *JSObjectCreate(JSThread *thread)
344514f5e3Sopenharmony_ci    {
354514f5e3Sopenharmony_ci        EcmaVM *ecmaVM = thread->GetEcmaVM();
364514f5e3Sopenharmony_ci        JSHandle<GlobalEnv> globalEnv = ecmaVM->GetGlobalEnv();
374514f5e3Sopenharmony_ci        return globalEnv->GetObjectFunction().GetObject<JSFunction>();
384514f5e3Sopenharmony_ci    }
394514f5e3Sopenharmony_ci
404514f5e3Sopenharmony_ci    EcmaRuntimeCallInfo *CreateEcmaRuntimeCallInfo(JSThread *thread, uint32_t numArgs)
414514f5e3Sopenharmony_ci    {
424514f5e3Sopenharmony_ci        auto factory = thread->GetEcmaVM()->GetFactory();
434514f5e3Sopenharmony_ci        JSHandle<JSTaggedValue> hclass(thread, JSObjectCreate(thread));
444514f5e3Sopenharmony_ci        JSHandle<JSTaggedValue> callee(factory->NewJSObjectByConstructor(JSHandle<JSFunction>::Cast(hclass), hclass));
454514f5e3Sopenharmony_ci        JSHandle<JSTaggedValue> undefined = thread->GlobalConstants()->GetHandledUndefined();
464514f5e3Sopenharmony_ci        EcmaRuntimeCallInfo *objCallInfo =
474514f5e3Sopenharmony_ci            EcmaInterpreter::NewRuntimeCallInfo(thread, undefined, callee, undefined, numArgs);
484514f5e3Sopenharmony_ci        return objCallInfo;
494514f5e3Sopenharmony_ci    }
504514f5e3Sopenharmony_ci
514514f5e3Sopenharmony_ci    JSTaggedValue InitializeLightWeightMapConstructor(JSThread *thread)
524514f5e3Sopenharmony_ci    {
534514f5e3Sopenharmony_ci        auto factory = thread->GetEcmaVM()->GetFactory();
544514f5e3Sopenharmony_ci        JSHandle<GlobalEnv> env = thread->GetEcmaVM()->GetGlobalEnv();
554514f5e3Sopenharmony_ci        JSHandle<JSTaggedValue> globalObject = env->GetJSGlobalObject();
564514f5e3Sopenharmony_ci        JSHandle<JSTaggedValue> key(factory->NewFromASCII("ArkPrivate"));
574514f5e3Sopenharmony_ci        JSHandle<JSTaggedValue> value =
584514f5e3Sopenharmony_ci            JSObject::GetProperty(thread, JSHandle<JSTaggedValue>(globalObject), key).GetValue();
594514f5e3Sopenharmony_ci
604514f5e3Sopenharmony_ci        auto objCallInfo = CreateEcmaRuntimeCallInfo(thread, 6); // 6 : means the argv length
614514f5e3Sopenharmony_ci        objCallInfo->SetFunction(JSTaggedValue::Undefined());
624514f5e3Sopenharmony_ci        objCallInfo->SetThis(value.GetTaggedValue());
634514f5e3Sopenharmony_ci        objCallInfo->SetCallArg(0, JSTaggedValue(static_cast<int>(ContainerTag::LightWeightMap)));
644514f5e3Sopenharmony_ci        JSTaggedValue result = ContainersPrivate::Load(objCallInfo);
654514f5e3Sopenharmony_ci
664514f5e3Sopenharmony_ci        return result;
674514f5e3Sopenharmony_ci    }
684514f5e3Sopenharmony_ci
694514f5e3Sopenharmony_ci    JSHandle<JSAPILightWeightMap> CreateJSAPILightWeightMap(JSThread *thread)
704514f5e3Sopenharmony_ci    {
714514f5e3Sopenharmony_ci        JSHandle<JSFunction> newTarget(thread, InitializeLightWeightMapConstructor(thread));
724514f5e3Sopenharmony_ci        auto objCallInfo = CreateEcmaRuntimeCallInfo(thread, 4);
734514f5e3Sopenharmony_ci        objCallInfo->SetFunction(newTarget.GetTaggedValue());
744514f5e3Sopenharmony_ci        objCallInfo->SetNewTarget(newTarget.GetTaggedValue());
754514f5e3Sopenharmony_ci        objCallInfo->SetThis(JSTaggedValue::Undefined());
764514f5e3Sopenharmony_ci
774514f5e3Sopenharmony_ci        JSTaggedValue result = ContainersLightWeightMap::LightWeightMapConstructor(objCallInfo);
784514f5e3Sopenharmony_ci        JSHandle<JSAPILightWeightMap> map(thread, result);
794514f5e3Sopenharmony_ci        return map;
804514f5e3Sopenharmony_ci    }
814514f5e3Sopenharmony_ci
824514f5e3Sopenharmony_ci    void ContainersLightWeightMapAtFuzzTest(const uint8_t* data, size_t size)
834514f5e3Sopenharmony_ci    {
844514f5e3Sopenharmony_ci        RuntimeOption option;
854514f5e3Sopenharmony_ci        option.SetLogLevel(RuntimeOption::LOG_LEVEL::ERROR);
864514f5e3Sopenharmony_ci        EcmaVM *vm = JSNApi::CreateJSVM(option);
874514f5e3Sopenharmony_ci        {
884514f5e3Sopenharmony_ci            JsiFastNativeScope scope(vm);
894514f5e3Sopenharmony_ci            auto thread = vm->GetAssociatedJSThread();
904514f5e3Sopenharmony_ci
914514f5e3Sopenharmony_ci            if (size <= 0) {
924514f5e3Sopenharmony_ci                return;
934514f5e3Sopenharmony_ci            }
944514f5e3Sopenharmony_ci            double input = 0;
954514f5e3Sopenharmony_ci            const double maxByteLen = 4;
964514f5e3Sopenharmony_ci            if (size > maxByteLen) {
974514f5e3Sopenharmony_ci                size = maxByteLen;
984514f5e3Sopenharmony_ci            }
994514f5e3Sopenharmony_ci            if (memcpy_s(&input, maxByteLen, data, size) != 0) {
1004514f5e3Sopenharmony_ci                std::cout << "memcpy_s failed!";
1014514f5e3Sopenharmony_ci                UNREACHABLE();
1024514f5e3Sopenharmony_ci            }
1034514f5e3Sopenharmony_ci            JSHandle<JSAPILightWeightMap> lightWeightMap = CreateJSAPILightWeightMap(thread);
1044514f5e3Sopenharmony_ci
1054514f5e3Sopenharmony_ci            EcmaRuntimeCallInfo *callInfo1 = CreateEcmaRuntimeCallInfo(thread, 8);
1064514f5e3Sopenharmony_ci            callInfo1->SetFunction(JSTaggedValue::Undefined());
1074514f5e3Sopenharmony_ci            callInfo1->SetThis(lightWeightMap.GetTaggedValue());
1084514f5e3Sopenharmony_ci            callInfo1->SetCallArg(0, JSTaggedValue(input));
1094514f5e3Sopenharmony_ci            callInfo1->SetCallArg(1, JSTaggedValue(input + 1));
1104514f5e3Sopenharmony_ci            ContainersLightWeightMap::Set(callInfo1);
1114514f5e3Sopenharmony_ci
1124514f5e3Sopenharmony_ci            {
1134514f5e3Sopenharmony_ci                EcmaRuntimeCallInfo *callInfo = CreateEcmaRuntimeCallInfo(thread, 6);
1144514f5e3Sopenharmony_ci                callInfo->SetFunction(JSTaggedValue::Undefined());
1154514f5e3Sopenharmony_ci                callInfo->SetThis(lightWeightMap.GetTaggedValue());
1164514f5e3Sopenharmony_ci                callInfo->SetCallArg(0, JSTaggedValue(input));
1174514f5e3Sopenharmony_ci                ContainersLightWeightMap::GetKeyAt(callInfo);
1184514f5e3Sopenharmony_ci            }
1194514f5e3Sopenharmony_ci
1204514f5e3Sopenharmony_ci            {
1214514f5e3Sopenharmony_ci                EcmaRuntimeCallInfo *callInfo = CreateEcmaRuntimeCallInfo(thread, 6);
1224514f5e3Sopenharmony_ci                callInfo->SetFunction(JSTaggedValue::Undefined());
1234514f5e3Sopenharmony_ci                callInfo->SetThis(lightWeightMap.GetTaggedValue());
1244514f5e3Sopenharmony_ci                callInfo->SetCallArg(0, JSTaggedValue(input));
1254514f5e3Sopenharmony_ci                ContainersLightWeightMap::GetValueAt(callInfo);
1264514f5e3Sopenharmony_ci            }
1274514f5e3Sopenharmony_ci
1284514f5e3Sopenharmony_ci            {
1294514f5e3Sopenharmony_ci                EcmaRuntimeCallInfo *callInfo = CreateEcmaRuntimeCallInfo(thread, 6);
1304514f5e3Sopenharmony_ci                callInfo->SetFunction(JSTaggedValue::Undefined());
1314514f5e3Sopenharmony_ci                callInfo->SetThis(lightWeightMap.GetTaggedValue());
1324514f5e3Sopenharmony_ci                callInfo->SetCallArg(0, JSTaggedValue(input));
1334514f5e3Sopenharmony_ci                ContainersLightWeightMap::SetValueAt(callInfo);
1344514f5e3Sopenharmony_ci            }
1354514f5e3Sopenharmony_ci
1364514f5e3Sopenharmony_ci            {
1374514f5e3Sopenharmony_ci                EcmaRuntimeCallInfo *callInfo = CreateEcmaRuntimeCallInfo(thread, 6);
1384514f5e3Sopenharmony_ci                callInfo->SetFunction(JSTaggedValue::Undefined());
1394514f5e3Sopenharmony_ci                callInfo->SetThis(lightWeightMap.GetTaggedValue());
1404514f5e3Sopenharmony_ci                callInfo->SetCallArg(0, JSTaggedValue(input));
1414514f5e3Sopenharmony_ci                ContainersLightWeightMap::RemoveAt(callInfo);
1424514f5e3Sopenharmony_ci            }
1434514f5e3Sopenharmony_ci        }
1444514f5e3Sopenharmony_ci        JSNApi::DestroyJSVM(vm);
1454514f5e3Sopenharmony_ci    }
1464514f5e3Sopenharmony_ci}
1474514f5e3Sopenharmony_ci
1484514f5e3Sopenharmony_ci// Fuzzer entry point.
1494514f5e3Sopenharmony_ciextern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size)
1504514f5e3Sopenharmony_ci{
1514514f5e3Sopenharmony_ci    // Run your code on data.
1524514f5e3Sopenharmony_ci    OHOS::ContainersLightWeightMapAtFuzzTest(data, size);
1534514f5e3Sopenharmony_ci    return 0;
1544514f5e3Sopenharmony_ci}