14514f5e3Sopenharmony_ci/* 24514f5e3Sopenharmony_ci * Copyright (c) 2022 Huawei Device Co., Ltd. 34514f5e3Sopenharmony_ci * Licensed under the Apache License, Version 2.0 (the "License"); 44514f5e3Sopenharmony_ci * you may not use this file except in compliance with the License. 54514f5e3Sopenharmony_ci * You may obtain a copy of the License at 64514f5e3Sopenharmony_ci * 74514f5e3Sopenharmony_ci * http://www.apache.org/licenses/LICENSE-2.0 84514f5e3Sopenharmony_ci * 94514f5e3Sopenharmony_ci * Unless required by applicable law or agreed to in writing, software 104514f5e3Sopenharmony_ci * distributed under the License is distributed on an "AS IS" BASIS, 114514f5e3Sopenharmony_ci * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 124514f5e3Sopenharmony_ci * See the License for the specific language governing permissions and 134514f5e3Sopenharmony_ci * limitations under the License. 144514f5e3Sopenharmony_ci */ 154514f5e3Sopenharmony_ci 164514f5e3Sopenharmony_ci#include "functionrefcall_fuzzer.h" 174514f5e3Sopenharmony_ci 184514f5e3Sopenharmony_ci#include "ecmascript/napi/include/jsnapi.h" 194514f5e3Sopenharmony_ci 204514f5e3Sopenharmony_ciusing namespace panda; 214514f5e3Sopenharmony_ciusing namespace panda::ecmascript; 224514f5e3Sopenharmony_ci 234514f5e3Sopenharmony_cinamespace OHOS { 244514f5e3Sopenharmony_ci Local<JSValueRef> FuncRefCallCallbackForTest(JsiRuntimeCallInfo* info) 254514f5e3Sopenharmony_ci { 264514f5e3Sopenharmony_ci EscapeLocalScope scope(info->GetVM()); 274514f5e3Sopenharmony_ci return scope.Escape(ArrayRef::New(info->GetVM(), info->GetArgsNumber())); 284514f5e3Sopenharmony_ci } 294514f5e3Sopenharmony_ci 304514f5e3Sopenharmony_ci void FunctionRefCallFuzzTest(const uint8_t* data, size_t size) 314514f5e3Sopenharmony_ci { 324514f5e3Sopenharmony_ci RuntimeOption option; 334514f5e3Sopenharmony_ci option.SetLogLevel(RuntimeOption::LOG_LEVEL::ERROR); 344514f5e3Sopenharmony_ci EcmaVM *vm = JSNApi::CreateJSVM(option); 354514f5e3Sopenharmony_ci if (size <= 0) { 364514f5e3Sopenharmony_ci return; 374514f5e3Sopenharmony_ci } 384514f5e3Sopenharmony_ci FunctionCallback nativeFunc = FuncRefCallCallbackForTest; 394514f5e3Sopenharmony_ci NativePointerCallback deleter = nullptr; 404514f5e3Sopenharmony_ci Local<FunctionRef> func = FunctionRef::New(vm, nativeFunc, deleter, (void *)(data + size)); 414514f5e3Sopenharmony_ci const int32_t argvLen = 3; 424514f5e3Sopenharmony_ci Local<JSValueRef> thisObj(JSValueRef::Undefined(vm)); 434514f5e3Sopenharmony_ci Local<JSValueRef> argv[argvLen]; 444514f5e3Sopenharmony_ci for (int32_t i = 0; i < argvLen; i++) { 454514f5e3Sopenharmony_ci argv[i] = JSValueRef::Undefined(vm); 464514f5e3Sopenharmony_ci } 474514f5e3Sopenharmony_ci func->Call(vm, thisObj, argv, argvLen); 484514f5e3Sopenharmony_ci JSNApi::DestroyJSVM(vm); 494514f5e3Sopenharmony_ci } 504514f5e3Sopenharmony_ci} 514514f5e3Sopenharmony_ci 524514f5e3Sopenharmony_ci// Fuzzer entry point. 534514f5e3Sopenharmony_ciextern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) 544514f5e3Sopenharmony_ci{ 554514f5e3Sopenharmony_ci // Run your code on data. 564514f5e3Sopenharmony_ci OHOS::FunctionRefCallFuzzTest(data, size); 574514f5e3Sopenharmony_ci return 0; 584514f5e3Sopenharmony_ci}