14514f5e3Sopenharmony_ci/* 24514f5e3Sopenharmony_ci * Copyright (c) 2022 Huawei Device Co., Ltd. 34514f5e3Sopenharmony_ci * Licensed under the Apache License, Version 2.0 (the "License"); 44514f5e3Sopenharmony_ci * you may not use this file except in compliance with the License. 54514f5e3Sopenharmony_ci * You may obtain a copy of the License at 64514f5e3Sopenharmony_ci * 74514f5e3Sopenharmony_ci * http://www.apache.org/licenses/LICENSE-2.0 84514f5e3Sopenharmony_ci * 94514f5e3Sopenharmony_ci * Unless required by applicable law or agreed to in writing, software 104514f5e3Sopenharmony_ci * distributed under the License is distributed on an "AS IS" BASIS, 114514f5e3Sopenharmony_ci * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 124514f5e3Sopenharmony_ci * See the License for the specific language governing permissions and 134514f5e3Sopenharmony_ci * limitations under the License. 144514f5e3Sopenharmony_ci */ 154514f5e3Sopenharmony_ci 164514f5e3Sopenharmony_ci#include "containerslightweightsetgetindexof_fuzzer.h" 174514f5e3Sopenharmony_ci 184514f5e3Sopenharmony_ci#include "ecmascript/containers/containers_lightweightset.h" 194514f5e3Sopenharmony_ci#include "ecmascript/containers/containers_private.h" 204514f5e3Sopenharmony_ci#include "ecmascript/ecma_string-inl.h" 214514f5e3Sopenharmony_ci#include "ecmascript/ecma_vm.h" 224514f5e3Sopenharmony_ci#include "ecmascript/global_env.h" 234514f5e3Sopenharmony_ci#include "ecmascript/js_handle.h" 244514f5e3Sopenharmony_ci#include "ecmascript/napi/include/jsnapi.h" 254514f5e3Sopenharmony_ci 264514f5e3Sopenharmony_ciusing namespace panda; 274514f5e3Sopenharmony_ciusing namespace panda::test; 284514f5e3Sopenharmony_ciusing namespace panda::ecmascript; 294514f5e3Sopenharmony_ciusing namespace panda::ecmascript::containers; 304514f5e3Sopenharmony_ci 314514f5e3Sopenharmony_cinamespace OHOS { 324514f5e3Sopenharmony_ci 334514f5e3Sopenharmony_ci JSFunction *JSObjectCreate(JSThread *thread) 344514f5e3Sopenharmony_ci { 354514f5e3Sopenharmony_ci EcmaVM *ecmaVM = thread->GetEcmaVM(); 364514f5e3Sopenharmony_ci JSHandle<GlobalEnv> globalEnv = ecmaVM->GetGlobalEnv(); 374514f5e3Sopenharmony_ci return globalEnv->GetObjectFunction().GetObject<JSFunction>(); 384514f5e3Sopenharmony_ci } 394514f5e3Sopenharmony_ci 404514f5e3Sopenharmony_ci EcmaRuntimeCallInfo *CreateEcmaRuntimeCallInfo(JSThread *thread, uint32_t numArgs) 414514f5e3Sopenharmony_ci { 424514f5e3Sopenharmony_ci auto factory = thread->GetEcmaVM()->GetFactory(); 434514f5e3Sopenharmony_ci JSHandle<JSTaggedValue> hclass(thread, JSObjectCreate(thread)); 444514f5e3Sopenharmony_ci JSHandle<JSTaggedValue> callee(factory->NewJSObjectByConstructor(JSHandle<JSFunction>::Cast(hclass), hclass)); 454514f5e3Sopenharmony_ci JSHandle<JSTaggedValue> undefined = thread->GlobalConstants()->GetHandledUndefined(); 464514f5e3Sopenharmony_ci EcmaRuntimeCallInfo *objCallInfo = 474514f5e3Sopenharmony_ci EcmaInterpreter::NewRuntimeCallInfo(thread, undefined, callee, undefined, numArgs); 484514f5e3Sopenharmony_ci return objCallInfo; 494514f5e3Sopenharmony_ci } 504514f5e3Sopenharmony_ci 514514f5e3Sopenharmony_ci JSTaggedValue InitializeLightWeightSetConstructor(JSThread *thread) 524514f5e3Sopenharmony_ci { 534514f5e3Sopenharmony_ci auto factory = thread->GetEcmaVM()->GetFactory(); 544514f5e3Sopenharmony_ci JSHandle<GlobalEnv> env = thread->GetEcmaVM()->GetGlobalEnv(); 554514f5e3Sopenharmony_ci JSHandle<JSTaggedValue> globalObject = env->GetJSGlobalObject(); 564514f5e3Sopenharmony_ci JSHandle<JSTaggedValue> key(factory->NewFromASCII("ArkPrivate")); 574514f5e3Sopenharmony_ci JSHandle<JSTaggedValue> value = 584514f5e3Sopenharmony_ci JSObject::GetProperty(thread, JSHandle<JSTaggedValue>(globalObject), key).GetValue(); 594514f5e3Sopenharmony_ci auto objCallInfo = CreateEcmaRuntimeCallInfo(thread, 6); // 6 : means the argv length 604514f5e3Sopenharmony_ci objCallInfo->SetFunction(JSTaggedValue::Undefined()); 614514f5e3Sopenharmony_ci objCallInfo->SetThis(value.GetTaggedValue()); 624514f5e3Sopenharmony_ci objCallInfo->SetCallArg(0, JSTaggedValue(static_cast<int>(ContainerTag::LightWeightSet))); 634514f5e3Sopenharmony_ci JSTaggedValue result = ContainersPrivate::Load(objCallInfo); 644514f5e3Sopenharmony_ci return result; 654514f5e3Sopenharmony_ci } 664514f5e3Sopenharmony_ci 674514f5e3Sopenharmony_ci JSHandle<JSAPILightWeightSet> CreateJSAPILightWeightSet(JSThread *thread) 684514f5e3Sopenharmony_ci { 694514f5e3Sopenharmony_ci JSHandle<JSFunction> newTarget(thread, InitializeLightWeightSetConstructor(thread)); 704514f5e3Sopenharmony_ci auto objCallInfo = CreateEcmaRuntimeCallInfo(thread, 4); 714514f5e3Sopenharmony_ci objCallInfo->SetFunction(newTarget.GetTaggedValue()); 724514f5e3Sopenharmony_ci objCallInfo->SetNewTarget(newTarget.GetTaggedValue()); 734514f5e3Sopenharmony_ci objCallInfo->SetThis(JSTaggedValue::Undefined()); 744514f5e3Sopenharmony_ci JSTaggedValue result = ContainersLightWeightSet::LightWeightSetConstructor(objCallInfo); 754514f5e3Sopenharmony_ci JSHandle<JSAPILightWeightSet> map(thread, result); 764514f5e3Sopenharmony_ci return map; 774514f5e3Sopenharmony_ci } 784514f5e3Sopenharmony_ci 794514f5e3Sopenharmony_ci void ContainersLightWeightSetFuzzTest(const uint8_t* data, size_t size) 804514f5e3Sopenharmony_ci { 814514f5e3Sopenharmony_ci RuntimeOption option; 824514f5e3Sopenharmony_ci option.SetLogLevel(RuntimeOption::LOG_LEVEL::ERROR); 834514f5e3Sopenharmony_ci EcmaVM *vm = JSNApi::CreateJSVM(option); 844514f5e3Sopenharmony_ci { 854514f5e3Sopenharmony_ci JsiFastNativeScope scope(vm); 864514f5e3Sopenharmony_ci auto thread = vm->GetAssociatedJSThread(); 874514f5e3Sopenharmony_ci if (size <= 0) { 884514f5e3Sopenharmony_ci return; 894514f5e3Sopenharmony_ci } 904514f5e3Sopenharmony_ci double input = 0; 914514f5e3Sopenharmony_ci const double maxByteLen = 4; 924514f5e3Sopenharmony_ci if (size > maxByteLen) { 934514f5e3Sopenharmony_ci size = maxByteLen; 944514f5e3Sopenharmony_ci } 954514f5e3Sopenharmony_ci if (memcpy_s(&input, maxByteLen, data, size) != 0) { 964514f5e3Sopenharmony_ci std::cout << "memcpy_s failed!"; 974514f5e3Sopenharmony_ci UNREACHABLE(); 984514f5e3Sopenharmony_ci } 994514f5e3Sopenharmony_ci JSHandle<JSAPILightWeightSet> lightWeightSet = CreateJSAPILightWeightSet(thread); 1004514f5e3Sopenharmony_ci EcmaRuntimeCallInfo *callInfo = CreateEcmaRuntimeCallInfo(thread, 6); // 6 : means the argv length 1014514f5e3Sopenharmony_ci callInfo->SetFunction(JSTaggedValue::Undefined()); 1024514f5e3Sopenharmony_ci callInfo->SetThis(lightWeightSet.GetTaggedValue()); 1034514f5e3Sopenharmony_ci callInfo->SetCallArg(0, JSTaggedValue(input)); 1044514f5e3Sopenharmony_ci ContainersLightWeightSet::GetIndexOf(callInfo); 1054514f5e3Sopenharmony_ci } 1064514f5e3Sopenharmony_ci JSNApi::DestroyJSVM(vm); 1074514f5e3Sopenharmony_ci } 1084514f5e3Sopenharmony_ci} 1094514f5e3Sopenharmony_ci 1104514f5e3Sopenharmony_ci// Fuzzer entry point. 1114514f5e3Sopenharmony_ciextern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) 1124514f5e3Sopenharmony_ci{ 1134514f5e3Sopenharmony_ci // Run your code on data. 1144514f5e3Sopenharmony_ci OHOS::ContainersLightWeightSetFuzzTest(data, size); 1154514f5e3Sopenharmony_ci return 0; 1164514f5e3Sopenharmony_ci}