1/*
2 * Copyright (c) 2022 Huawei Device Co., Ltd.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at
6 *
7 *     http://www.apache.org/licenses/LICENSE-2.0
8 *
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
14 */
15
16#include "snapshotserializehugeobject_fuzzer.h"
17
18#include "ecmascript/log_wrapper.h"
19#include "ecmascript/object_factory.h"
20#include "ecmascript/snapshot/mem/snapshot.h"
21
22using namespace panda;
23using namespace panda::ecmascript;
24
25namespace OHOS {
26    void SnapshotSerializeHugeObjectFuzzTest(const uint8_t* data, size_t size)
27    {
28        RuntimeOption option;
29        option.SetLogLevel(RuntimeOption::LOG_LEVEL::ERROR);
30        EcmaVM *vm = JSNApi::CreateJSVM(option);
31        {
32            JsiFastNativeScope scope(vm);
33            if (size <= 0) {
34                return;
35            }
36            auto factory = vm->GetFactory();
37            const uint32_t hugeSize = 256 * 1024;
38            JSHandle<TaggedArray> array = factory->NewTaggedArray(hugeSize + *data); // new huge object tagged array
39            if (*data > 0) {
40                JSHandle<TaggedArray> array1 = factory->NewTaggedArray(hugeSize + *data);
41                array->Set(vm->GetAssociatedJSThread(), 0, array1.GetTaggedValue());
42            }
43            const CString fileName = "snapshot";
44            Snapshot snapshotSerialize(vm);
45            // serialize
46            snapshotSerialize.Serialize(*array, nullptr, fileName);
47            // deserialize
48            Snapshot snapshotDeserialize(vm);
49            snapshotDeserialize.Deserialize(SnapshotType::VM_ROOT, fileName);
50            // remove snapshot file if exist
51            std::remove(fileName.c_str());
52        }
53        JSNApi::DestroyJSVM(vm);
54    }
55}
56
57// Fuzzer entry point.
58extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size)
59{
60    // Run your code on data.
61    OHOS::SnapshotSerializeHugeObjectFuzzTest(data, size);
62    return 0;
63}