* Copyright (c) 2025 Huawei Device Co., Ltd.
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
#include "cmcreatesession_fuzzer.h"
#include "cert_manager_auth_list_mgr.h"
#include "cert_manager_auth_mgr.h"
#include "cert_manager_session_mgr.h"
#include "cm_fuzz_test_common.h"
#include "cm_test_common.h"
#include "cert_manager_double_list.h"
namespace {
const uint32_t UINT32_COUNT = 4;
const uint32_t CM_BLOB_COUNT = 2;
}
using namespace CmFuzzTest;
namespace OHOS {
static bool CreateCmSessionNodeInfo(struct CmSessionNodeInfo &info, uint8_t *myData,
uint32_t &remainSize, uint32_t &offset)
{
uint32_t userId;
if (!GetUintFromBuffer(myData, &remainSize, &offset, &userId)) {
return false;
}
uint32_t uid;
if (!GetUintFromBuffer(myData, &remainSize, &offset, &uid)) {
return false;
}
struct CmBlob uri = {0, nullptr};
if (!GetCmBlobFromBuffer(myData, &remainSize, &offset, &uri)) {
return false;
}
info.userId = userId;
info.uid = uid;
info.uri = uri;
return true;
}
bool DoSomethingInterestingWithMyAPI(const uint8_t* data, size_t size)
{
uint32_t minSize = sizeof(struct CmBlob) * CM_BLOB_COUNT +sizeof(uint32_t) * UINT32_COUNT;
uint8_t *myData = nullptr;
if (!CopyMyData(data, size, minSize, &myData)) {
return false;
}
uint32_t remainSize = static_cast<uint32_t>(size);
uint32_t offset = 0;
struct CmBlob handle = {0, nullptr};
if (!GetCmBlobFromBuffer(myData, &remainSize, &offset, &handle)) {
CmFree(myData);
return false;
}
CmSessionNodeInfo info;
if (!CreateCmSessionNodeInfo(info, myData, remainSize, offset)) {
CmFree(myData);
return false;
}
bool abortable = true;
CmSessionDeleteType deleteType = DELETE_SESSION_BY_USERID;
struct DoubleList listNode;
(void)memset_s(&listNode, sizeof(DoubleList), 0, sizeof(DoubleList));
struct DoubleList listHead;
(void)memset_s(&listHead, sizeof(DoubleList), 0, sizeof(DoubleList));
CertmanagerTest::MockHapToken mockHap;
(void)CmCreateSession(&info, &handle, abortable);
(void)CmDeleteSession(&handle);
(void)CmDeleteSessionByNodeInfo(deleteType, &info);
(void)CmInitList(&listNode);
(void)CmAddNodeAfterListHead(&listHead, &listNode);
CmFree(myData);
return true;
}
}
extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size)
{
OHOS::DoSomethingInterestingWithMyAPI(data, size);
return 0;
}