1 | /* |
2 | * Copyright (C) 2014, 2016 Apple Inc. All rights reserved. |
3 | * |
4 | * Redistribution and use in source and binary forms, with or without |
5 | * modification, are permitted provided that the following conditions |
6 | * are met: |
7 | * 1. Redistributions of source code must retain the above copyright |
8 | * notice, this list of conditions and the following disclaimer. |
9 | * 2. Redistributions in binary form must reproduce the above copyright |
10 | * notice, this list of conditions and the following disclaimer in the |
11 | * documentation and/or other materials provided with the distribution. |
12 | * |
13 | * THIS SOFTWARE IS PROVIDED BY APPLE INC. ``AS IS'' AND ANY |
14 | * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE |
15 | * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR |
16 | * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL APPLE INC. OR |
17 | * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, |
18 | * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, |
19 | * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR |
20 | * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY |
21 | * OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
22 | * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE |
23 | * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
24 | */ |
25 | |
26 | #include "config.h" |
27 | #include "ExceptionFuzz.h" |
28 | |
29 | #include "Error.h" |
30 | #include "JSCInlines.h" |
31 | #include "TestRunnerUtils.h" |
32 | |
33 | namespace JSC { |
34 | |
35 | static unsigned s_numberOfExceptionFuzzChecks; |
36 | unsigned numberOfExceptionFuzzChecks() { return s_numberOfExceptionFuzzChecks; } |
37 | |
38 | // Call this only if you know that exception fuzzing is enabled. |
39 | void doExceptionFuzzing(JSGlobalObject* globalObject, ThrowScope& scope, const char* where, const void* returnPC) |
40 | { |
41 | VM& vm = scope.vm(); |
42 | ASSERT(Options::useExceptionFuzz()); |
43 | |
44 | DeferGCForAWhile deferGC(vm.heap); |
45 | |
46 | s_numberOfExceptionFuzzChecks++; |
47 | |
48 | unsigned fireTarget = Options::fireExceptionFuzzAt(); |
49 | if (fireTarget == s_numberOfExceptionFuzzChecks) { |
50 | printf("JSC EXCEPTION FUZZ: Throwing fuzz exception with call frame %p, seen in %s and return address %p.\n" , globalObject, where, returnPC); |
51 | fflush(stdout); |
52 | |
53 | // The ThrowScope also checks for unchecked simulated exceptions before throwing a |
54 | // new exception. This ensures that we don't quietly overwrite a pending exception |
55 | // (which should never happen with the only exception being to rethrow the same |
56 | // exception). However, ExceptionFuzz works by intentionally throwing its own exception |
57 | // even when one may already exist. This is ok for ExceptionFuzz testing, but we need |
58 | // to placate the exception check verifier here. |
59 | EXCEPTION_ASSERT(scope.exception() || !scope.exception()); |
60 | |
61 | throwException(globalObject, scope, createError(globalObject, "Exception Fuzz"_s )); |
62 | } |
63 | } |
64 | |
65 | } // namespace JSC |
66 | |
67 | |
68 | |