• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /*
2  * Copyright (c) 2023 Huawei Device Co., Ltd.
3  * Licensed under the Apache License, Version 2.0 (the "License");
4  * you may not use this file except in compliance with the License.
5  * You may obtain a copy of the License at
6  *
7  *     http://www.apache.org/licenses/LICENSE-2.0
8  *
9  * Unless required by applicable law or agreed to in writing, software
10  * distributed under the License is distributed on an "AS IS" BASIS,
11  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12  * See the License for the specific language governing permissions and
13  * limitations under the License.
14  */
15 
16 #include "sensoronremoterequest_fuzzer.h"
17 
18 #include <cstddef>
19 #include <cstdint>
20 
21 #include "accesstoken_kit.h"
22 #include "message_parcel.h"
23 #include "nativetoken_kit.h"
24 #include "securec.h"
25 #include "token_setproc.h"
26 
27 #include "sensor.h"
28 #include "sensor_service.h"
29 
30 namespace OHOS {
31 namespace Sensors {
32 using namespace Security::AccessToken;
33 using Security::AccessToken::AccessTokenID;
34 namespace {
35 constexpr size_t U32_AT_SIZE = 4;
36 constexpr uint32_t IPC_CODE_COUNT = 13;
37 auto g_service = SensorDelayedSpSingleton<SensorService>::GetInstance();
38 const std::u16string SENSOR_INTERFACE_TOKEN = u"OHOS.Sensors.ISensorService";
39 } // namespace
40 
SetUpTestCase()41 void SetUpTestCase()
42 {
43     const char **perms = new (std::nothrow) const char *[2];
44     if (perms == nullptr) {
45         return;
46     }
47     perms[0] = "ohos.permission.ACCELEROMETER";
48     perms[1] = "ohos.permission.MANAGE_SENSOR";
49     TokenInfoParams infoInstance = {
50         .dcapsNum = 0,
51         .permsNum = 2,
52         .aclsNum = 0,
53         .dcaps = nullptr,
54         .perms = perms,
55         .acls = nullptr,
56         .processName = "SensorOnRemoteRequestFuzzTest",
57         .aplStr = "system_core",
58     };
59     uint64_t tokenId = GetAccessTokenId(&infoInstance);
60     SetSelfTokenID(tokenId);
61     AccessTokenKit::ReloadNativeTokenInfo();
62     delete[] perms;
63 }
64 
GetU32Data(const uint8_t * data)65 uint32_t GetU32Data(const uint8_t *data)
66 {
67     // convert fuzz input data to an integer
68     return ((data[0] << 24) | (data[1] << 16) | (data[2] << 8) | data[3]) % IPC_CODE_COUNT;
69 }
70 
OnRemoteRequestFuzzTest(const uint8_t * data,size_t size)71 bool OnRemoteRequestFuzzTest(const uint8_t *data, size_t size)
72 {
73     SetUpTestCase();
74     uint32_t code = GetU32Data(data);
75     MessageParcel datas;
76     datas.WriteInterfaceToken(SENSOR_INTERFACE_TOKEN);
77     datas.WriteBuffer(data + U32_AT_SIZE, size - U32_AT_SIZE);
78     datas.RewindRead(0);
79     MessageParcel reply;
80     MessageOption option;
81     g_service->OnRemoteRequest(code, datas, reply, option);
82     return true;
83 }
84 } // namespace Sensors
85 } // namespace OHOS
86 
LLVMFuzzerTestOneInput(const uint8_t * data,size_t size)87 extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size)
88 {
89     /* Run your code on data */
90     if (data == nullptr) {
91         return 0;
92     }
93 
94     /* Validate the length of size */
95     if (size < OHOS::Sensors::U32_AT_SIZE) {
96         return 0;
97     }
98 
99     OHOS::Sensors::OnRemoteRequestFuzzTest(data, size);
100     return 0;
101 }
102