1 /*
2  * Copyright (c) 2023 Huawei Device Co., Ltd.
3  * Licensed under the Apache License, Version 2.0 (the "License");
4  * you may not use this file except in compliance with the License.
5  * You may obtain a copy of the License at
6  *
7  * http://www.apache.org/licenses/LICENSE-2.0
8  *
9  * Unless required by applicable law or agreed to in writing, software
10  * distributed under the License is distributed on an "AS IS" BASIS,
11  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12  * See the License for the specific language governing permissions and
13  * limitations under the License.
14  */
15 
16 #include "jsvaluerefislightweightmapandset_fuzzer.h"
17 #include "ecmascript/containers/containers_list.h"
18 #include "ecmascript/containers/containers_private.h"
19 #include "ecmascript/ecma_string-inl.h"
20 #include "ecmascript/ecma_vm.h"
21 #include "ecmascript/global_env.h"
22 #include "ecmascript/js_handle.h"
23 #include "ecmascript/js_tagged_value.h"
24 #include "ecmascript/napi/include/jsnapi.h"
25 #include "ecmascript/js_thread.h"
26 #include "ecmascript/js_global_object.h"
27 #include "ecmascript/napi/jsnapi_helper.h"
28 #include "ecmascript/linked_hash_table.h"
29 #include "ecmascript/ecma_runtime_call_info.h"
30 #include "ecmascript/containers/containers_hashset.h"
31 #include "ecmascript/common.h"
32 #include "ecmascript/frames.h"
33 #include "ecmascript/object_factory.h"
34 #include "ecmascript/js_set.h"
35 #include "ecmascript/js_set_iterator.h"
36 #include "ecmascript/js_map.h"
37 #include "ecmascript/js_weak_container.h"
38 #include "ecmascript/js_map_iterator.h"
39 #include "ecmascript/containers/containers_arraylist.h"
40 #include "ecmascript/js_api/js_api_arraylist.h"
41 #include "ecmascript/builtins/builtins_function.h"
42 #include "ecmascript/builtins/builtins.h"
43 #include "ecmascript/ecma_global_storage.h"
44 #include "ecmascript/js_bigint.h"
45 #include "ecmascript/js_runtime_options.h"
46 #include "ecmascript/object_factory.h"
47 #include "ecmascript/tagged_array.h"
48 #include "ecmascript/js_generator_object.h"
49 #include "ecmascript/js_string_iterator.h"
50 #include "ecmascript/js_date_time_format.h"
51 #include "ecmascript/js_tagged_number.h"
52 #include "ecmascript/js_api/js_api_hashmap.h"
53 #include "ecmascript/builtins/builtins_regexp.h"
54 #include "ecmascript/js_regexp.h"
55 #include "ecmascript/tagged_hash_array.h"
56 #include "ecmascript/containers/containers_lightweightmap.h"
57 #include "ecmascript/containers/containers_lightweightset.h"
58 
59 using namespace panda;
60 using namespace panda::test;
61 using namespace panda::ecmascript;
62 using namespace panda::ecmascript::containers;
63 
64 namespace OHOS {
CreateEcmaRuntimeCallInfo(JSThread *thread, JSTaggedValue newTgt, uint32_t argvLength)65 EcmaRuntimeCallInfo *CreateEcmaRuntimeCallInfo(JSThread *thread, JSTaggedValue newTgt, uint32_t argvLength)
66 {
67     const uint8_t testDecodedSize = 2;
68     int32_t numActualArgs = argvLength / testDecodedSize + 1;
69     JSTaggedType *sp = const_cast<JSTaggedType *>(thread->GetCurrentSPFrame());
70 
71     size_t frameSize = 0;
72     if (thread->IsAsmInterpreter()) {
73         frameSize = InterpretedEntryFrame::NumOfMembers() + numActualArgs;
74     } else {
75         frameSize = InterpretedFrame::NumOfMembers() + numActualArgs;
76     }
77     JSTaggedType *newSp = sp - frameSize; // NOLINT(cppcoreguidelines-pro-bounds-pointer-arithmetic)
78     for (int i = numActualArgs; i > 0; i--) {
79         newSp[i - 1] = JSTaggedValue::Undefined().GetRawData();
80     }
81     EcmaRuntimeCallInfo *ecmaRuntimeCallInfo = reinterpret_cast<EcmaRuntimeCallInfo *>(newSp - 2);
82     *(--newSp) = numActualArgs;
83     *(--newSp) = panda::ecmascript::ToUintPtr(thread);
84     ecmaRuntimeCallInfo->SetNewTarget(newTgt);
85     return ecmaRuntimeCallInfo;
86 }
87 
SetupFrame(JSThread *thread, EcmaRuntimeCallInfo *info)88 static JSTaggedType *SetupFrame(JSThread *thread, EcmaRuntimeCallInfo *info)
89 {
90     JSTaggedType *sp = const_cast<JSTaggedType *>(thread->GetCurrentSPFrame());
91     size_t frameSize = 0;
92     const int num = 2;
93     // 2 means thread and numArgs
94     if (thread->IsAsmInterpreter()) {
95         frameSize = InterpretedEntryFrame::NumOfMembers() + info->GetArgsNumber() + NUM_MANDATORY_JSFUNC_ARGS + num;
96     } else {
97         frameSize = InterpretedFrame::NumOfMembers() + info->GetArgsNumber() + NUM_MANDATORY_JSFUNC_ARGS + num;
98     }
99     JSTaggedType *newSp = sp - frameSize; // NOLINT(cppcoreguidelines-pro-bounds-pointer-arithmetic)
100 
101     InterpretedEntryFrame *state = reinterpret_cast<InterpretedEntryFrame *>(newSp) - 1;
102     state->base.type = ecmascript::FrameType::INTERPRETER_ENTRY_FRAME;
103     state->base.prev = sp;
104     state->pc = nullptr;
105     thread->SetCurrentSPFrame(newSp);
106     return sp;
107 }
108 
TearDownFrame(JSThread *thread, JSTaggedType *prev)109 void TearDownFrame(JSThread *thread, JSTaggedType *prev)
110 {
111     thread->SetCurrentSPFrame(prev);
112 }
113 
ConstructobjectLightWeightMap(JSThread *thread)114 JSHandle<JSAPILightWeightMap> ConstructobjectLightWeightMap(JSThread *thread)
115 {
116     ObjectFactory *factory = thread->GetEcmaVM()->GetFactory();
117     JSHandle<GlobalEnv> env = thread->GetEcmaVM()->GetGlobalEnv();
118     JSHandle<JSTaggedValue> globalObject = env->GetJSGlobalObject();
119     JSHandle<JSTaggedValue> key(factory->NewFromASCII("ArkPrivate"));
120     JSHandle<JSTaggedValue> value =
121         JSObject::GetProperty(thread, JSHandle<JSTaggedValue>(globalObject), key).GetValue();
122     auto objCallInfo1 = CreateEcmaRuntimeCallInfo(thread, JSTaggedValue::Undefined(), 6);
123     objCallInfo1->SetFunction(JSTaggedValue::Undefined());
124     objCallInfo1->SetThis(value.GetTaggedValue());
125     objCallInfo1->SetCallArg(0, JSTaggedValue(static_cast<int>(containers::ContainerTag::LightWeightMap)));
126     [[maybe_unused]] auto prev1 = SetupFrame(thread, objCallInfo1);
127     JSTaggedValue result1 = ecmascript::containers::ContainersPrivate::Load(objCallInfo1);
128     JSHandle<JSFunction> newTarget(thread, result1);
129     auto objCallInfo = CreateEcmaRuntimeCallInfo(thread, JSTaggedValue::Undefined(), 4);
130     objCallInfo->SetFunction(newTarget.GetTaggedValue());
131     objCallInfo->SetNewTarget(newTarget.GetTaggedValue());
132     objCallInfo->SetThis(JSTaggedValue::Undefined());
133     [[maybe_unused]] auto prev = SetupFrame(thread, objCallInfo);
134     JSTaggedValue result = ecmascript::containers::ContainersLightWeightMap::LightWeightMapConstructor(objCallInfo);
135     TearDownFrame(thread, prev);
136     JSHandle<JSAPILightWeightMap> mapHandle(thread, result);
137     return mapHandle;
138 }
139 
ConstructobjectLightWeightSet(JSThread *thread)140 JSHandle<JSAPILightWeightSet> ConstructobjectLightWeightSet(JSThread *thread)
141 {
142     ObjectFactory *factory = thread->GetEcmaVM()->GetFactory();
143     JSHandle<GlobalEnv> env = thread->GetEcmaVM()->GetGlobalEnv();
144     JSHandle<JSTaggedValue> globalObject = env->GetJSGlobalObject();
145     JSHandle<JSTaggedValue> key(factory->NewFromASCII("ArkPrivate"));
146     JSHandle<JSTaggedValue> value =
147         JSObject::GetProperty(thread, JSHandle<JSTaggedValue>(globalObject), key).GetValue();
148     auto objCallInfo1 = CreateEcmaRuntimeCallInfo(thread, JSTaggedValue::Undefined(), 6);
149     objCallInfo1->SetFunction(JSTaggedValue::Undefined());
150     objCallInfo1->SetThis(value.GetTaggedValue());
151     objCallInfo1->SetCallArg(0, JSTaggedValue(static_cast<int>(containers::ContainerTag::LightWeightSet)));
152     [[maybe_unused]] auto prev1 = SetupFrame(thread, objCallInfo1);
153     JSTaggedValue result1 = ecmascript::containers::ContainersPrivate::Load(objCallInfo1);
154     JSHandle<JSFunction> newTarget(thread, result1);
155     auto objCallInfo = CreateEcmaRuntimeCallInfo(thread, JSTaggedValue::Undefined(), 4);
156     objCallInfo->SetFunction(newTarget.GetTaggedValue());
157     objCallInfo->SetNewTarget(newTarget.GetTaggedValue());
158     objCallInfo->SetThis(JSTaggedValue::Undefined());
159     [[maybe_unused]] auto prev = SetupFrame(thread, objCallInfo);
160     JSTaggedValue result = ecmascript::containers::ContainersLightWeightSet::LightWeightSetConstructor(objCallInfo);
161     TearDownFrame(thread, prev);
162     JSHandle<JSAPILightWeightSet> mapHandle(thread, result);
163     return mapHandle;
164 }
165 
JSValueRefIsLightWeightMapFuzzTest([[maybe_unused]] const uint8_t *data, size_t size)166 void JSValueRefIsLightWeightMapFuzzTest([[maybe_unused]] const uint8_t *data, size_t size)
167 {
168     RuntimeOption option;
169     option.SetLogLevel(RuntimeOption::LOG_LEVEL::ERROR);
170     EcmaVM *vm = JSNApi::CreateJSVM(option);
171     {
172         JsiFastNativeScope scope(vm);
173         if (size <= 0) {
174             LOG_ECMA(ERROR) << "Parameter out of range..";
175             return;
176         }
177         auto thread = vm->GetAssociatedJSThread();
178         JSHandle<JSAPILightWeightMap> mapHandle = ConstructobjectLightWeightMap(thread);
179         JSHandle<JSTaggedValue> jshashmap = JSHandle<JSTaggedValue>::Cast(mapHandle);
180         Local<JSValueRef> tag = JSNApiHelper::ToLocal<JSValueRef>(jshashmap);
181         tag->IsLightWeightMap(vm);
182     }
183     JSNApi::DestroyJSVM(vm);
184 }
185 
JSValueRefIsLightWeightSetFuzzTest([[maybe_unused]] const uint8_t *data, size_t size)186 void JSValueRefIsLightWeightSetFuzzTest([[maybe_unused]] const uint8_t *data, size_t size)
187 {
188     RuntimeOption option;
189     option.SetLogLevel(RuntimeOption::LOG_LEVEL::ERROR);
190     EcmaVM *vm = JSNApi::CreateJSVM(option);
191     {
192         JsiFastNativeScope scope(vm);
193         if (size <= 0) {
194             LOG_ECMA(ERROR) << "Parameter out of range..";
195             return;
196         }
197         auto thread = vm->GetAssociatedJSThread();
198         JSHandle<JSAPILightWeightSet> mapHandle = ConstructobjectLightWeightSet(thread);
199         JSHandle<JSTaggedValue> jshashmap = JSHandle<JSTaggedValue>::Cast(mapHandle);
200         Local<JSValueRef> tag = JSNApiHelper::ToLocal<JSValueRef>(jshashmap);
201         tag->IsLightWeightSet(vm);
202     }
203     JSNApi::DestroyJSVM(vm);
204 }
205 }
206 
207 // Fuzzer entry point.
LLVMFuzzerTestOneInput(const uint8_t *data, size_t size)208 extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size)
209 {
210     // Run your code on data.
211     OHOS::JSValueRefIsLightWeightMapFuzzTest(data, size);
212     OHOS::JSValueRefIsLightWeightSetFuzzTest(data, size);
213     return 0;
214 }