• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /*
2  * Copyright (c) 2025 Huawei Device Co., Ltd.
3  * Licensed under the Apache License, Version 2.0 (the "License");
4  * you may not use this file except in compliance with the License.
5  * You may obtain a copy of the License at
6  *
7  *     http://www.apache.org/licenses/LICENSE-2.0
8  *
9  * Unless required by applicable law or agreed to in writing, software
10  * distributed under the License is distributed on an "AS IS" BASIS,
11  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12  * See the License for the specific language governing permissions and
13  * limitations under the License.
14  */
15 
16 #include "cmdgetosaccountservicestub_fuzzer.h"
17 
18 #include <string>
19 #include <vector>
20 #define private public
21 #include "account_mgr_service.h"
22 #undef private
23 #include "fuzz_data.h"
24 #include "iaccount.h"
25 
26 using namespace std;
27 using namespace OHOS::AccountSA;
28 
29 namespace OHOS {
30 namespace {
31 const std::u16string ACCOUNT_TOKEN = u"ohos.accountfwk.IAccount";
32 constexpr size_t MAX_RANDOM_STRING_LENGTH = 64;
33 constexpr size_t MIN_RANDOM_STRING_LENGTH = 1;
34 constexpr char16_t NULL_CHARACTER = 0;
35 constexpr char16_t ASCII_MAX = 0x007F;
36 constexpr char16_t PRINTABLE_ASCII_COUNT = 95;
37 constexpr char16_t SPACE_CHARACTER = 32;
38 const uint32_t TEST_CODE = 1000;
39 
GenerateRandomU16String(FuzzData & fuzzData)40 std::u16string GenerateRandomU16String(FuzzData& fuzzData)
41 {
42     size_t length = (fuzzData.GetData<uint8_t>() % MAX_RANDOM_STRING_LENGTH) + MIN_RANDOM_STRING_LENGTH;
43     std::u16string result;
44     result.reserve(length);
45     for (size_t i = 0; i < length; ++i) {
46         char16_t ch = fuzzData.GetData<char16_t>();
47         if (ch == NULL_CHARACTER || ch > ASCII_MAX) {
48             ch = static_cast<char16_t>((ch % PRINTABLE_ASCII_COUNT) + SPACE_CHARACTER);
49         }
50         result.push_back(ch);
51     }
52     return result;
53 }
54 }
55 
CmdGetOsAccountServiceStubFuzzTest(const uint8_t * data,size_t size,uint32_t code)56 bool CmdGetOsAccountServiceStubFuzzTest(const uint8_t* data, size_t size, uint32_t code)
57 {
58     if ((data == nullptr) || (size == 0)) {
59         return false;
60     }
61 
62     FuzzData fuzzData(data, size);
63     MessageParcel dataTemp;
64 
65     uint8_t randomByte = fuzzData.GetData<uint8_t>();
66     bool useValidToken = (randomByte & 0x01) != 0;
67     bool useRunningState = (randomByte & 0x02) != 0;
68 
69     std::u16string token = useValidToken ? ACCOUNT_TOKEN : GenerateRandomU16String(fuzzData);
70     if (!dataTemp.WriteInterfaceToken(token)) {
71         return false;
72     }
73 
74     std::string randomStr = fuzzData.GenerateString();
75     dataTemp.WriteString(randomStr);
76 
77     int32_t randomInt = fuzzData.GetData<int32_t>();
78     dataTemp.WriteInt32(randomInt);
79 
80     ServiceRunningState state = useRunningState ?
81                                ServiceRunningState::STATE_RUNNING :
82                                ServiceRunningState::STATE_NOT_START;
83     DelayedRefSingleton<AccountMgrService>::GetInstance().state_ = state;
84 
85     MessageParcel reply;
86     MessageOption option;
87     DelayedRefSingleton<AccountMgrService>::GetInstance().OnRemoteRequest(code, dataTemp, reply, option);
88     return true;
89 }
90 
SendRequestWithCode(int32_t code)91 void SendRequestWithCode(int32_t code)
92 {
93     MessageParcel dataTemp;
94     dataTemp.WriteInterfaceToken(ACCOUNT_TOKEN);
95     MessageOption option;
96     MessageParcel reply;
97     DelayedRefSingleton<AccountMgrService>::GetInstance().state_ = ServiceRunningState::STATE_RUNNING;
98     DelayedRefSingleton<AccountMgrService>::GetInstance().OnRemoteRequest(code, dataTemp, reply, option);
99 }
100 }
101 
LLVMFuzzerInitialize(int * argc,char *** argv)102 extern "C" int LLVMFuzzerInitialize(int *argc, char ***argv)
103 {
104     OHOS::SendRequestWithCode(static_cast<uint32_t>(IAccountIpcCode::COMMAND_QUERY_OHOS_ACCOUNT_INFO));
105     OHOS::SendRequestWithCode(static_cast<uint32_t>(IAccountIpcCode::COMMAND_QUERY_DISTRIBUTED_VIRTUAL_DEVICE_ID));
106     OHOS::SendRequestWithCode(static_cast<uint32_t>(IAccountIpcCode::COMMAND_GET_OHOS_ACCOUNT_INFO));
107     OHOS::SendRequestWithCode(static_cast<uint32_t>(IAccountIpcCode::COMMAND_QUERY_DEVICE_ACCOUNT_ID));
108     return 0;
109 }
110 
111 /* Fuzzer entry point */
LLVMFuzzerTestOneInput(const uint8_t * data,size_t size)112 extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size)
113 {
114     /* Run your code on data */
115     OHOS::CmdGetOsAccountServiceStubFuzzTest(
116         data, size, static_cast<uint32_t>(IAccountIpcCode::COMMAND_GET_OS_ACCOUNT_SERVICE));
117     OHOS::CmdGetOsAccountServiceStubFuzzTest(
118         data, size, static_cast<uint32_t>(IAccountIpcCode::COMMAND_GET_APP_ACCOUNT_SERVICE));
119     OHOS::CmdGetOsAccountServiceStubFuzzTest(
120         data, size, static_cast<uint32_t>(IAccountIpcCode::COMMAND_GET_ACCOUNT_I_A_M_SERVICE));
121     OHOS::CmdGetOsAccountServiceStubFuzzTest(
122         data, size, static_cast<uint32_t>(IAccountIpcCode::COMMAND_GET_DOMAIN_ACCOUNT_SERVICE));
123     OHOS::CmdGetOsAccountServiceStubFuzzTest(data, size, OHOS::TEST_CODE);
124     return 0;
125 }