1 /*
2 * Copyright (c) 2025 Huawei Device Co., Ltd.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at
6 *
7 * http://www.apache.org/licenses/LICENSE-2.0
8 *
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
14 */
15
16 #include "cmdgetosaccountservicestub_fuzzer.h"
17
18 #include <string>
19 #include <vector>
20 #define private public
21 #include "account_mgr_service.h"
22 #undef private
23 #include "fuzz_data.h"
24 #include "iaccount.h"
25
26 using namespace std;
27 using namespace OHOS::AccountSA;
28
29 namespace OHOS {
30 namespace {
31 const std::u16string ACCOUNT_TOKEN = u"ohos.accountfwk.IAccount";
32 constexpr size_t MAX_RANDOM_STRING_LENGTH = 64;
33 constexpr size_t MIN_RANDOM_STRING_LENGTH = 1;
34 constexpr char16_t NULL_CHARACTER = 0;
35 constexpr char16_t ASCII_MAX = 0x007F;
36 constexpr char16_t PRINTABLE_ASCII_COUNT = 95;
37 constexpr char16_t SPACE_CHARACTER = 32;
38 const uint32_t TEST_CODE = 1000;
39
GenerateRandomU16String(FuzzData & fuzzData)40 std::u16string GenerateRandomU16String(FuzzData& fuzzData)
41 {
42 size_t length = (fuzzData.GetData<uint8_t>() % MAX_RANDOM_STRING_LENGTH) + MIN_RANDOM_STRING_LENGTH;
43 std::u16string result;
44 result.reserve(length);
45 for (size_t i = 0; i < length; ++i) {
46 char16_t ch = fuzzData.GetData<char16_t>();
47 if (ch == NULL_CHARACTER || ch > ASCII_MAX) {
48 ch = static_cast<char16_t>((ch % PRINTABLE_ASCII_COUNT) + SPACE_CHARACTER);
49 }
50 result.push_back(ch);
51 }
52 return result;
53 }
54 }
55
CmdGetOsAccountServiceStubFuzzTest(const uint8_t * data,size_t size,uint32_t code)56 bool CmdGetOsAccountServiceStubFuzzTest(const uint8_t* data, size_t size, uint32_t code)
57 {
58 if ((data == nullptr) || (size == 0)) {
59 return false;
60 }
61
62 FuzzData fuzzData(data, size);
63 MessageParcel dataTemp;
64
65 uint8_t randomByte = fuzzData.GetData<uint8_t>();
66 bool useValidToken = (randomByte & 0x01) != 0;
67 bool useRunningState = (randomByte & 0x02) != 0;
68
69 std::u16string token = useValidToken ? ACCOUNT_TOKEN : GenerateRandomU16String(fuzzData);
70 if (!dataTemp.WriteInterfaceToken(token)) {
71 return false;
72 }
73
74 std::string randomStr = fuzzData.GenerateString();
75 dataTemp.WriteString(randomStr);
76
77 int32_t randomInt = fuzzData.GetData<int32_t>();
78 dataTemp.WriteInt32(randomInt);
79
80 ServiceRunningState state = useRunningState ?
81 ServiceRunningState::STATE_RUNNING :
82 ServiceRunningState::STATE_NOT_START;
83 DelayedRefSingleton<AccountMgrService>::GetInstance().state_ = state;
84
85 MessageParcel reply;
86 MessageOption option;
87 DelayedRefSingleton<AccountMgrService>::GetInstance().OnRemoteRequest(code, dataTemp, reply, option);
88 return true;
89 }
90
SendRequestWithCode(int32_t code)91 void SendRequestWithCode(int32_t code)
92 {
93 MessageParcel dataTemp;
94 dataTemp.WriteInterfaceToken(ACCOUNT_TOKEN);
95 MessageOption option;
96 MessageParcel reply;
97 DelayedRefSingleton<AccountMgrService>::GetInstance().state_ = ServiceRunningState::STATE_RUNNING;
98 DelayedRefSingleton<AccountMgrService>::GetInstance().OnRemoteRequest(code, dataTemp, reply, option);
99 }
100 }
101
LLVMFuzzerInitialize(int * argc,char *** argv)102 extern "C" int LLVMFuzzerInitialize(int *argc, char ***argv)
103 {
104 OHOS::SendRequestWithCode(static_cast<uint32_t>(IAccountIpcCode::COMMAND_QUERY_OHOS_ACCOUNT_INFO));
105 OHOS::SendRequestWithCode(static_cast<uint32_t>(IAccountIpcCode::COMMAND_QUERY_DISTRIBUTED_VIRTUAL_DEVICE_ID));
106 OHOS::SendRequestWithCode(static_cast<uint32_t>(IAccountIpcCode::COMMAND_GET_OHOS_ACCOUNT_INFO));
107 OHOS::SendRequestWithCode(static_cast<uint32_t>(IAccountIpcCode::COMMAND_QUERY_DEVICE_ACCOUNT_ID));
108 return 0;
109 }
110
111 /* Fuzzer entry point */
LLVMFuzzerTestOneInput(const uint8_t * data,size_t size)112 extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size)
113 {
114 /* Run your code on data */
115 OHOS::CmdGetOsAccountServiceStubFuzzTest(
116 data, size, static_cast<uint32_t>(IAccountIpcCode::COMMAND_GET_OS_ACCOUNT_SERVICE));
117 OHOS::CmdGetOsAccountServiceStubFuzzTest(
118 data, size, static_cast<uint32_t>(IAccountIpcCode::COMMAND_GET_APP_ACCOUNT_SERVICE));
119 OHOS::CmdGetOsAccountServiceStubFuzzTest(
120 data, size, static_cast<uint32_t>(IAccountIpcCode::COMMAND_GET_ACCOUNT_I_A_M_SERVICE));
121 OHOS::CmdGetOsAccountServiceStubFuzzTest(
122 data, size, static_cast<uint32_t>(IAccountIpcCode::COMMAND_GET_DOMAIN_ACCOUNT_SERVICE));
123 OHOS::CmdGetOsAccountServiceStubFuzzTest(data, size, OHOS::TEST_CODE);
124 return 0;
125 }