1 /*
2  * Copyright (c) 2022 Huawei Device Co., Ltd.
3  * Licensed under the Apache License, Version 2.0 (the "License");
4  * you may not use this file except in compliance with the License.
5  * You may obtain a copy of the License at
6  *
7  *     http://www.apache.org/licenses/LICENSE-2.0
8  *
9  * Unless required by applicable law or agreed to in writing, software
10  * distributed under the License is distributed on an "AS IS" BASIS,
11  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12  * See the License for the specific language governing permissions and
13  * limitations under the License.
14  */
15 
16 #include "getsimeons_fuzzer.h"
17 
18 #include <cstddef>
19 #include <cstdint>
20 #include <thread>
21 
22 #define private public
23 #include "addcoreservicetoken_fuzzer.h"
24 #include "core_service.h"
25 #include "core_service_stub.h"
26 #include "napi_util.h"
27 #include "system_ability_definition.h"
28 #include "tel_event_handler.h"
29 #include "unistd.h"
30 
31 using namespace OHOS::Telephony;
32 namespace OHOS {
33 static bool g_isInited = false;
34 constexpr int32_t SLOT_NUM = 2;
35 constexpr int32_t CHOICE_NUM = 2;
36 
IsServiceInited()37 bool IsServiceInited()
38 {
39     if (!g_isInited) {
40         DelayedSingleton<CoreService>::GetInstance()->OnStart();
41         if (DelayedSingleton<CoreService>::GetInstance()->GetServiceRunningState() ==
42             static_cast<int32_t>(ServiceRunningState::STATE_RUNNING)) {
43             g_isInited = true;
44         }
45     }
46     return g_isInited;
47 }
48 
IsNrSupported(const uint8_t * data,size_t size)49 void IsNrSupported(const uint8_t *data, size_t size)
50 {
51     if (!IsServiceInited()) {
52         return;
53     }
54 
55     int32_t slotId = static_cast<int32_t>(*data % SLOT_NUM);
56     MessageParcel dataMessageParcel;
57     dataMessageParcel.WriteInt32(slotId);
58     dataMessageParcel.WriteBuffer(data, size);
59     dataMessageParcel.RewindRead(0);
60     MessageParcel reply;
61     DelayedSingleton<CoreService>::GetInstance()->OnIsNrSupported(dataMessageParcel, reply);
62 }
63 
GetPsRadioTech(const uint8_t * data,size_t size)64 void GetPsRadioTech(const uint8_t *data, size_t size)
65 {
66     if (!IsServiceInited()) {
67         return;
68     }
69 
70     int32_t slotId = static_cast<int32_t>(*data % SLOT_NUM);
71     MessageParcel dataMessageParcel;
72     dataMessageParcel.WriteInt32(slotId);
73     dataMessageParcel.WriteBuffer(data, size);
74     dataMessageParcel.RewindRead(0);
75     MessageParcel reply;
76     DelayedSingleton<CoreService>::GetInstance()->OnGetPsRadioTech(dataMessageParcel, reply);
77 }
78 
GetCsRadioTech(const uint8_t * data,size_t size)79 void GetCsRadioTech(const uint8_t *data, size_t size)
80 {
81     if (!IsServiceInited()) {
82         return;
83     }
84 
85     int32_t slotId = static_cast<int32_t>(*data % SLOT_NUM);
86     MessageParcel dataMessageParcel;
87     dataMessageParcel.WriteInt32(slotId);
88     dataMessageParcel.WriteBuffer(data, size);
89     dataMessageParcel.RewindRead(0);
90     MessageParcel reply;
91     DelayedSingleton<CoreService>::GetInstance()->OnGetCsRadioTech(dataMessageParcel, reply);
92 }
93 
GetNrOptionMode(const uint8_t * data,size_t size)94 void GetNrOptionMode(const uint8_t *data, size_t size)
95 {
96     if (!IsServiceInited()) {
97         return;
98     }
99 
100     int32_t slotId = static_cast<int32_t>(*data % SLOT_NUM);
101     MessageParcel dataMessageParcel;
102     dataMessageParcel.WriteInt32(slotId);
103     dataMessageParcel.WriteBuffer(data, size);
104     dataMessageParcel.RewindRead(0);
105     MessageParcel reply;
106     DelayedSingleton<CoreService>::GetInstance()->OnGetNrOptionMode(dataMessageParcel, reply);
107 }
108 
GetSimEons(const uint8_t * data,size_t size)109 void GetSimEons(const uint8_t *data, size_t size)
110 {
111     if (!IsServiceInited()) {
112         return;
113     }
114 
115     int32_t slotId = static_cast<int32_t>(*data % SLOT_NUM);
116     bool longNameRequired = static_cast<int32_t>(*data % CHOICE_NUM);
117     std::string plmn(reinterpret_cast<const char *>(data), size);
118     MessageParcel dataMessageParcel;
119     dataMessageParcel.WriteInt32(slotId);
120     dataMessageParcel.WriteString(plmn);
121     dataMessageParcel.WriteInt32(size);
122     dataMessageParcel.WriteBool(longNameRequired);
123     dataMessageParcel.RewindRead(0);
124     MessageParcel reply;
125     DelayedSingleton<CoreService>::GetInstance()->OnGetSimEons(dataMessageParcel, reply);
126 }
127 
GetIsoCountryCodeForNetwork(const uint8_t * data,size_t size)128 void GetIsoCountryCodeForNetwork(const uint8_t *data, size_t size)
129 {
130     if (!IsServiceInited()) {
131         return;
132     }
133 
134     int32_t slotId = static_cast<int32_t>(*data % SLOT_NUM);
135     MessageParcel dataMessageParcel;
136     dataMessageParcel.WriteInt32(slotId);
137     dataMessageParcel.WriteBuffer(data, size);
138     dataMessageParcel.RewindRead(0);
139     MessageParcel reply;
140     DelayedSingleton<CoreService>::GetInstance()->OnGetIsoCountryCodeForNetwork(dataMessageParcel, reply);
141 }
142 
GetSignalInfoList(const uint8_t * data,size_t size)143 void GetSignalInfoList(const uint8_t *data, size_t size)
144 {
145     if (!IsServiceInited()) {
146         return;
147     }
148 
149     int32_t slotId = static_cast<int32_t>(*data % SLOT_NUM);
150     MessageParcel dataMessageParcel;
151     dataMessageParcel.WriteInt32(slotId);
152     dataMessageParcel.WriteBuffer(data, size);
153     dataMessageParcel.RewindRead(0);
154     MessageParcel reply;
155     DelayedSingleton<CoreService>::GetInstance()->OnGetSignalInfoList(dataMessageParcel, reply);
156 }
157 
DoSomethingInterestingWithMyAPI(const uint8_t * data,size_t size)158 void DoSomethingInterestingWithMyAPI(const uint8_t *data, size_t size)
159 {
160     if (data == nullptr || size == 0) {
161         return;
162     }
163 
164     IsNrSupported(data, size);
165     GetPsRadioTech(data, size);
166     GetCsRadioTech(data, size);
167     GetNrOptionMode(data, size);
168     GetSimEons(data, size);
169     GetIsoCountryCodeForNetwork(data, size);
170     GetSignalInfoList(data, size);
171     auto telRilManager = DelayedSingleton<CoreService>::GetInstance()->telRilManager_;
172     if (telRilManager == nullptr || telRilManager->handler_ == nullptr) {
173         return;
174     }
175     telRilManager->handler_->ClearFfrt(false);
176     telRilManager->handler_->queue_ = nullptr;
177     return;
178 }
179 } // namespace OHOS
180 
181 /* Fuzzer entry point */
LLVMFuzzerInitialize(int * argc,char *** argv)182 extern "C" int LLVMFuzzerInitialize(int *argc, char ***argv)
183 {
184     OHOS::AddCoreServiceTokenFuzzer token;
185     return 0;
186 }
187 
188 /* Fuzzer entry point */
LLVMFuzzerTestOneInput(const uint8_t * data,size_t size)189 extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size)
190 {
191     /* Run your code on data */
192     OHOS::DoSomethingInterestingWithMyAPI(data, size);
193     OHOS::DelayedSingleton<CoreService>::DestroyInstance();
194     return 0;
195 }
196