1/*
2 * Copyright (c) 2022 Huawei Device Co., Ltd.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at
6 *
7 *     http://www.apache.org/licenses/LICENSE-2.0
8 *
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
14 */
15
16#include "containersstackpop_fuzzer.h"
17#include "ecmascript/containers/containers_private.h"
18#include "ecmascript/containers/containers_stack.h"
19#include "ecmascript/ecma_string-inl.h"
20#include "ecmascript/ecma_vm.h"
21#include "ecmascript/global_env.h"
22#include "ecmascript/js_handle.h"
23#include "ecmascript/napi/include/jsnapi.h"
24
25using namespace panda;
26using namespace panda::test;
27using namespace panda::ecmascript;
28using namespace panda::ecmascript::containers;
29
30#define MAXBYTELEN sizeof(uint32_t)
31
32namespace OHOS {
33    JSFunction *JSObjectCreate(JSThread *thread)
34    {
35        EcmaVM *ecmaVM = thread->GetEcmaVM();
36        JSHandle<GlobalEnv> globalEnv = ecmaVM->GetGlobalEnv();
37        return globalEnv->GetObjectFunction().GetObject<JSFunction>();
38    }
39
40    EcmaRuntimeCallInfo *CreateEcmaRuntimeCallInfo(JSThread *thread, uint32_t numArgs)
41    {
42        auto factory = thread->GetEcmaVM()->GetFactory();
43        JSHandle<JSTaggedValue> hclass(thread, JSObjectCreate(thread));
44        JSHandle<JSTaggedValue> callee(factory->NewJSObjectByConstructor(JSHandle<JSFunction>::Cast(hclass), hclass));
45        JSHandle<JSTaggedValue> undefined = thread->GlobalConstants()->GetHandledUndefined();
46        EcmaRuntimeCallInfo *objCallInfo =
47            EcmaInterpreter::NewRuntimeCallInfo(thread, undefined, callee, undefined, numArgs);
48        return objCallInfo;
49    }
50
51    JSTaggedValue InitializeStackConstructor(JSThread *thread)
52    {
53        auto factory = thread->GetEcmaVM()->GetFactory();
54        JSHandle<GlobalEnv> env = thread->GetEcmaVM()->GetGlobalEnv();
55        JSHandle<JSTaggedValue> globalObject = env->GetJSGlobalObject();
56        JSHandle<JSTaggedValue> key(factory->NewFromASCII("ArkPrivate"));
57        JSHandle<JSTaggedValue> value =
58            JSObject::GetProperty(thread, JSHandle<JSTaggedValue>(globalObject), key).GetValue();
59        auto objCallInfo = CreateEcmaRuntimeCallInfo(thread, 6); // 6 : means the argv length
60        objCallInfo->SetFunction(JSTaggedValue::Undefined());
61        objCallInfo->SetThis(value.GetTaggedValue());
62        objCallInfo->SetCallArg(0, JSTaggedValue(static_cast<int>(ContainerTag::Stack)));
63        JSTaggedValue result = ContainersPrivate::Load(objCallInfo);
64        return result;
65    }
66
67    JSHandle<JSAPIStack> CreateJSAPIStack(JSThread *thread, JSTaggedValue compare = JSTaggedValue::Undefined())
68    {
69        JSHandle<JSTaggedValue> compareHandle(thread, compare);
70        JSHandle<JSFunction> newTarget(thread, InitializeStackConstructor(thread));
71        auto objCallInfo = CreateEcmaRuntimeCallInfo(thread, 6); // 6 : means the argv length
72        objCallInfo->SetFunction(newTarget.GetTaggedValue());
73        objCallInfo->SetNewTarget(newTarget.GetTaggedValue());
74        objCallInfo->SetThis(JSTaggedValue::Undefined());
75        objCallInfo->SetCallArg(0, compareHandle.GetTaggedValue());
76        JSTaggedValue result = ContainersStack::StackConstructor(objCallInfo);
77        JSHandle<JSAPIStack> stack(thread, result);
78        return stack;
79    }
80
81    void ContainersStackPopFuzzTest(const uint8_t* data, size_t size)
82    {
83        RuntimeOption option;
84        option.SetLogLevel(RuntimeOption::LOG_LEVEL::ERROR);
85        EcmaVM *vm = JSNApi::CreateJSVM(option);
86        {
87            JsiFastNativeScope scope(vm);
88            auto thread = vm->GetAssociatedJSThread();
89
90            if (size <= 0) {
91                return;
92            }
93            double input = 0;
94            if (size > MAXBYTELEN) {
95                size = MAXBYTELEN;
96            }
97            if (memcpy_s(&input, MAXBYTELEN, data, size) != 0) {
98                std::cout << "memcpy_s failed!";
99                UNREACHABLE();
100            }
101
102            JSHandle<JSAPIStack> stack = CreateJSAPIStack(thread);
103            {
104                EcmaRuntimeCallInfo *callInfo = CreateEcmaRuntimeCallInfo(thread, 8); // 8 : means the argv length
105                callInfo->SetFunction(JSTaggedValue::Undefined());
106                callInfo->SetThis(stack.GetTaggedValue());
107                callInfo->SetCallArg(0, JSTaggedValue(input));
108                ContainersStack::Push(callInfo);
109            }
110
111            {
112                EcmaRuntimeCallInfo *callInfo = CreateEcmaRuntimeCallInfo(thread, 6); // 6 : means the argv length
113                callInfo->SetFunction(JSTaggedValue::Undefined());
114                callInfo->SetThis(stack.GetTaggedValue());
115                callInfo->SetCallArg(0, JSTaggedValue(input));
116                ContainersStack::Pop(callInfo);
117            }
118        }
119        JSNApi::DestroyJSVM(vm);
120    }
121}
122
123// Fuzzer entry point.
124extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size)
125{
126    // Run your code on data.
127    OHOS::ContainersStackPopFuzzTest(data, size);
128    return 0;
129}