diff --git a/bundle.json b/bundle.json index 5a45d46..e30bbde 100644 --- a/bundle.json +++ b/bundle.json @@ -131,7 +131,8 @@ ], "test": [ "//base/miscservices/inputmethod/unitest:InputMethodControllerTest", - "//base/miscservices/inputmethod/unitest:InputMethodAbilityTest" + "//base/miscservices/inputmethod/unitest:InputMethodAbilityTest", + "//base/miscservices/inputmethod/test/fuzztest:fuzztest" ] } } diff --git a/test/fuzztest/BUILD.gn b/test/fuzztest/BUILD.gn new file mode 100644 index 0000000..0e73327 --- /dev/null +++ b/test/fuzztest/BUILD.gn @@ -0,0 +1,20 @@ +# Copyright (c) 2022 Huawei Device Co., Ltd. +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +import("//base/miscservices/inputmethod/inputmethod.gni") + +group("fuzztest") { + testonly = true + + deps = [ "inputclientstub_fuzzer:fuzztest" ] +} diff --git a/test/fuzztest/inputclientstub_fuzzer/BUILD.gn b/test/fuzztest/inputclientstub_fuzzer/BUILD.gn new file mode 100644 index 0000000..a700632 --- /dev/null +++ b/test/fuzztest/inputclientstub_fuzzer/BUILD.gn @@ -0,0 +1,68 @@ +# Copyright (c) 2021 Huawei Device Co., Ltd. +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +import("//base/miscservices/inputmethod/inputmethod.gni") + +#####################hydra-fuzz################### +import("//build/config/features.gni") +import("//build/ohos.gni") +import("//build/test.gni") + +##############################fuzztest########################################## +ohos_fuzztest("InputClientStubFuzzTest") { + module_out_path = "miscservices/inputmethod" + + fuzz_config_file = + "//base/miscservices/inputmethod/test/fuzztest/inputclientstub_fuzzer" + + include_dirs = [ + "//base/miscservices/inputmethod/frameworks/inputmethod_controller/include", + "//base/miscservices/inputmethod/frameworks/inputmethod_ability/include", + "//base/miscservices/inputmethod/services/include", + "//base/hiviewdfx/hilog/interfaces/native/innerkits/include", + "//foundation/communication/ipc/interfaces/innerkits/ipc_core/include", + "//utils/native/base/include", + ] + + cflags = [ + "-g", + "-O0", + "-Wno-unused-variable", + "-fno-omit-frame-pointer", + ] + + sources = [ "inputclientstub_fuzzer.cpp" ] + + deps = [ + "//base/miscservices/inputmethod/frameworks/inputmethod_controller:inputmethod_client", + "//base/miscservices/inputmethod/services:inputmethod_service", + "//foundation/communication/ipc/interfaces/innerkits/ipc_core:ipc_core", + "//foundation/communication/ipc/interfaces/innerkits/ipc_single:ipc_single", + "//foundation/distributedschedule/safwk/interfaces/innerkits/safwk:system_ability_fwk", + "//foundation/distributedschedule/samgr/interfaces/innerkits/samgr_proxy:samgr_proxy", + "//utils/native/base:utils", + ] + + external_deps = [ "hiviewdfx_hilog_native:libhilog" ] +} + +############################################################################### +group("fuzztest") { + testonly = true + deps = [] + deps += [ + # deps file + ":InputClientStubFuzzTest", + ] +} +############################################################################### diff --git a/test/fuzztest/inputclientstub_fuzzer/corpus/init b/test/fuzztest/inputclientstub_fuzzer/corpus/init new file mode 100644 index 0000000..bc977bd --- /dev/null +++ b/test/fuzztest/inputclientstub_fuzzer/corpus/init @@ -0,0 +1,14 @@ +# Copyright (c) 2022 Huawei Device Co., Ltd. +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +FUZZ \ No newline at end of file diff --git a/test/fuzztest/inputclientstub_fuzzer/inputclientstub_fuzzer.cpp b/test/fuzztest/inputclientstub_fuzzer/inputclientstub_fuzzer.cpp new file mode 100644 index 0000000..5fad1f8 --- /dev/null +++ b/test/fuzztest/inputclientstub_fuzzer/inputclientstub_fuzzer.cpp @@ -0,0 +1,70 @@ +/* + * Copyright (c) 2021 Huawei Device Co., Ltd. + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + + +#include "inputclientstub_fuzzer.h" + +#include +#include + +#include "input_client_stub.h" +#include "global.h" + +#include "message_parcel.h" + +using namespace OHOS::MiscServices; +namespace OHOS { + constexpr size_t THRESHOLD = 10; + constexpr int32_t OFFSET = 4; + const std::u16string INPUTCLIENTSTUB_INTERFACE_TOKEN = u"ohos.miscservices.InputClientStub"; + + uint32_t ConvertToUint32(const uint8_t *ptr) + { + if (ptr == nullptr) { + return 0; + } + uint32_t bigVar = (ptr[0] << 24) | (ptr[1] << 16) | (ptr[2] << 8) | (ptr[3]); + return bigVar; + } + bool FuzzInputClientStub(const uint8_t* rawData, size_t size) + { + uint32_t code = ConvertToUint32(rawData); + rawData = rawData + OFFSET; + size = size - OFFSET; + + MessageParcel data; + data.WriteInterfaceToken(INPUTCLIENTSTUB_INTERFACE_TOKEN); + data.WriteBuffer(rawData, size); + data.RewindRead(0); + MessageParcel reply; + MessageOption option; + + sptr mClient = new InputClientStub; + mClient->OnRemoteRequest(code, data, reply, option); + + return true; + } +} +/* Fuzzer entry point */ +extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) +{ + if (size < OHOS::THRESHOLD) { + return -1; + } + /* Run your code on data */ + OHOS::FuzzInputClientStub(data, size); + return 0; +} + diff --git a/test/fuzztest/inputclientstub_fuzzer/inputclientstub_fuzzer.h b/test/fuzztest/inputclientstub_fuzzer/inputclientstub_fuzzer.h new file mode 100644 index 0000000..4acd32e --- /dev/null +++ b/test/fuzztest/inputclientstub_fuzzer/inputclientstub_fuzzer.h @@ -0,0 +1,21 @@ +/* + * Copyright (c) 2021 Huawei Device Co., Ltd. + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +#ifndef TEST_FUZZTEST_INPUTCLIENTSTUB_FUZZER_INPUTCLIENTSTUB_FUZZER_H +#define TEST_FUZZTEST_INPUTCLIENTSTUB_FUZZER_INPUTCLIENTSTUB_FUZZER_H + +#define FUZZ_PROJECT_NAME "inputclientstub_fuzzer" + +#endif // TEST_FUZZTEST_INPUTCLIENTSTUB_FUZZER_INPUTCLIENTSTUB_FUZZER_H diff --git a/test/fuzztest/inputclientstub_fuzzer/project.xml b/test/fuzztest/inputclientstub_fuzzer/project.xml new file mode 100644 index 0000000..85e7ef2 --- /dev/null +++ b/test/fuzztest/inputclientstub_fuzzer/project.xml @@ -0,0 +1,25 @@ + + + + + + 1000 + + 300 + + 4096 + +