1/* 2 * Copyright (c) 2023 Huawei Device Co., Ltd. 3 * Licensed under the Apache License, Version 2.0 (the "License"); 4 * you may not use this file except in compliance with the License. 5 * You may obtain a copy of the License at 6 * 7 * http://www.apache.org/licenses/LICENSE-2.0 8 * 9 * Unless required by applicable law or agreed to in writing, software 10 * distributed under the License is distributed on an "AS IS" BASIS, 11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 12 * See the License for the specific language governing permissions and 13 * limitations under the License. 14 */ 15 16#include "jsvaluerefishashmap_fuzzer.h" 17#include "ecmascript/containers/containers_list.h" 18#include "ecmascript/containers/containers_private.h" 19#include "ecmascript/ecma_string-inl.h" 20#include "ecmascript/ecma_vm.h" 21#include "ecmascript/global_env.h" 22#include "ecmascript/js_handle.h" 23#include "ecmascript/js_tagged_value.h" 24#include "ecmascript/napi/include/jsnapi.h" 25#include "ecmascript/js_thread.h" 26#include "ecmascript/js_global_object.h" 27#include "ecmascript/napi/jsnapi_helper.h" 28#include "ecmascript/linked_hash_table.h" 29#include "ecmascript/ecma_runtime_call_info.h" 30#include "ecmascript/common.h" 31#include "ecmascript/frames.h" 32#include "ecmascript/object_factory.h" 33#include "ecmascript/js_set.h" 34#include "ecmascript/js_set_iterator.h" 35#include "ecmascript/js_map.h" 36#include "ecmascript/js_weak_container.h" 37#include "ecmascript/js_map_iterator.h" 38#include "ecmascript/containers/containers_arraylist.h" 39#include "ecmascript/js_api/js_api_arraylist.h" 40 41using namespace panda; 42using namespace panda::test; 43using namespace panda::ecmascript; 44using namespace panda::ecmascript::containers; 45 46namespace OHOS { 47EcmaRuntimeCallInfo *CreateEcmaRuntimeCallInfo(JSThread *thread, JSTaggedValue newTgt, uint32_t argvLength) 48{ 49 const uint8_t testDecodedSize = 2; 50 int32_t numActualArgs = argvLength / testDecodedSize + 1; 51 JSTaggedType *sp = const_cast<JSTaggedType *>(thread->GetCurrentSPFrame()); 52 53 size_t frameSize = 0; 54 if (thread->IsAsmInterpreter()) { 55 frameSize = InterpretedEntryFrame::NumOfMembers() + numActualArgs; 56 } else { 57 frameSize = InterpretedFrame::NumOfMembers() + numActualArgs; 58 } 59 JSTaggedType *newSp = sp - frameSize; // NOLINT(cppcoreguidelines-pro-bounds-pointer-arithmetic) 60 for (int i = numActualArgs; i > 0; i--) { 61 newSp[i - 1] = JSTaggedValue::Undefined().GetRawData(); 62 } 63 EcmaRuntimeCallInfo *ecmaRuntimeCallInfo = reinterpret_cast<EcmaRuntimeCallInfo *>(newSp - 2); 64 *(--newSp) = numActualArgs; 65 *(--newSp) = panda::ecmascript::ToUintPtr(thread); 66 ecmaRuntimeCallInfo->SetNewTarget(newTgt); 67 return ecmaRuntimeCallInfo; 68} 69 70static JSTaggedType *SetupFrame(JSThread *thread, EcmaRuntimeCallInfo *info) 71{ 72 JSTaggedType *sp = const_cast<JSTaggedType *>(thread->GetCurrentSPFrame()); 73 size_t frameSize = 0; 74 const int num = 2; 75 // 2 means thread and numArgs 76 if (thread->IsAsmInterpreter()) { 77 frameSize = InterpretedEntryFrame::NumOfMembers() + info->GetArgsNumber() + NUM_MANDATORY_JSFUNC_ARGS + num; 78 } else { 79 frameSize = InterpretedFrame::NumOfMembers() + info->GetArgsNumber() + NUM_MANDATORY_JSFUNC_ARGS + num; 80 } 81 JSTaggedType *newSp = sp - frameSize; // NOLINT(cppcoreguidelines-pro-bounds-pointer-arithmetic) 82 83 InterpretedEntryFrame *state = reinterpret_cast<InterpretedEntryFrame *>(newSp) - 1; 84 state->base.type = ecmascript::FrameType::INTERPRETER_ENTRY_FRAME; 85 state->base.prev = sp; 86 state->pc = nullptr; 87 thread->SetCurrentSPFrame(newSp); 88 return sp; 89} 90 91void TearDownFrame(JSThread *thread, JSTaggedType *prev) 92{ 93 thread->SetCurrentSPFrame(prev); 94} 95 96JSHandle<JSAPIHashMap> ConstructobjectHashMap(JSThread *thread) 97{ 98 ObjectFactory *factory = thread->GetEcmaVM()->GetFactory(); 99 JSHandle<GlobalEnv> env = thread->GetEcmaVM()->GetGlobalEnv(); 100 101 JSHandle<JSTaggedValue> globalObject = env->GetJSGlobalObject(); 102 JSHandle<JSTaggedValue> key(factory->NewFromASCII("ArkPrivate")); 103 JSHandle<JSTaggedValue> value = 104 JSObject::GetProperty(thread, JSHandle<JSTaggedValue>(globalObject), key).GetValue(); 105 auto objCallInfo = CreateEcmaRuntimeCallInfo(thread, JSTaggedValue::Undefined(), 6); 106 objCallInfo->SetFunction(JSTaggedValue::Undefined()); 107 objCallInfo->SetThis(value.GetTaggedValue()); 108 objCallInfo->SetCallArg(0, JSTaggedValue(static_cast<int>(containers::ContainerTag::HashMap))); 109 [[maybe_unused]] auto prev = SetupFrame(thread, objCallInfo); 110 JSTaggedValue result = containers::ContainersPrivate::Load(objCallInfo); 111 TearDownFrame(thread, prev); 112 JSHandle<JSTaggedValue> constructor(thread, result); 113 JSHandle<JSAPIHashMap> map(factory->NewJSObjectByConstructor(JSHandle<JSFunction>(constructor), constructor)); 114 return map; 115} 116 117 118void JSValueRefIsHashMapFuzzTest([[maybe_unused]] const uint8_t *data, size_t size) 119{ 120 RuntimeOption option; 121 option.SetLogLevel(RuntimeOption::LOG_LEVEL::ERROR); 122 EcmaVM *vm = JSNApi::CreateJSVM(option); 123 { 124 JsiFastNativeScope scope(vm); 125 if (size <= 0) { 126 LOG_ECMA(ERROR) << "Parameter out of range.."; 127 return; 128 } 129 auto thread = vm->GetAssociatedJSThread(); 130 JSHandle<JSAPIHashMap> map = ConstructobjectHashMap(thread); 131 JSHandle<JSTaggedValue> jshashmap = JSHandle<JSTaggedValue>::Cast(map); 132 Local<JSValueRef> tag = JSNApiHelper::ToLocal<JSValueRef>(jshashmap); 133 tag->IsHashMap(vm); 134 } 135 JSNApi::DestroyJSVM(vm); 136} 137} 138 139// Fuzzer entry point. 140extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) 141{ 142 // Run your code on data. 143 OHOS::JSValueRefIsHashMapFuzzTest(data, size); 144 return 0; 145}