/*
 * Copyright (C) 2025 The Android Open Source Project
 *
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *      http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */

#include <sys/mman.h>
#include <unistd.h>

#include "SkRRect.h"
#include "binary_loader.h"
#include "common.h"
#include "memutils.h"
#include "src/core/SkBlurMaskFilterImpl.h"

typedef bool (*draw_rrects_into_mask_func)(const SkRRect rrect, SkMaskBuilder* mask);
static void* (*real_calloc_func)(size_t, size_t) = nullptr;
char* startPtr = nullptr;

void* calloc(size_t size, size_t flag) {
    real_calloc_func = (void* (*)(size_t, size_t))dlsym(RTLD_NEXT, "calloc");
    FAIL_CHECK(real_calloc_func);

    // Check if size is zero.
    if (size == 0) {
        // Create a guarded buffer.
        size_t pageSize = getpagesize();
        startPtr = (char*)memalign(pageSize, pageSize);
        FAIL_CHECK(startPtr);
        memset(startPtr, 0, pageSize);
        DISABLE_MEM_ACCESS(startPtr, pageSize);
        return startPtr;
    }
    return real_calloc_func(size, flag);
}

int main(int /* argc */, char* argv[]) {
    // Get the path to the shared library and offset from command-line arguments
    const char* libPath = argv[1];
    const uintptr_t functionOffset = strtoul(argv[2], nullptr, 0);

    // Get function address of 'draw_rrects_into_mask()' from loaded library
    BinaryLoader binaryLoader(libPath);
    const uintptr_t functionAddress = binaryLoader.getFunctionAddress(functionOffset);
    FAIL_CHECK(functionAddress);

    // Create function pointer to 'draw_rrects_into_mask()'
    draw_rrects_into_mask_func draw_rrects_into_mask_ptr =
            (draw_rrects_into_mask_func)functionAddress;

    // Configure params such that co-ordinate of left is greater than right.
    SkMaskBuilder mask;
    SkRect rect = SkRect::MakeLTRB(1 /*Left*/, 0 /*Top*/, 0 /*Right*/, 0 /*Bottom*/);
    SkRRect rrect = SkRRect::MakeRectXY(rect, 0 /*x-axis radius*/, 0 /*y-axis radius*/);

    // draw_rrects_into_mask() is called with parameters such that computeImageSize() returns 'size'
    // as zero. Without fix, there is no check on 'size' and zero is passed to calloc().
    uint8_t * initialImagePtr = mask.image();
    draw_rrects_into_mask_ptr(rrect, &mask);

    // With Fix, AllocImage() is not called with 'size' as zero and 'fImage' is not modified.
    if (mask.image() == initialImagePtr) {
        return EXIT_SUCCESS;
    }

    // Without Fix, calloc() is called with 'size' as zero. Calloc() is overloaded to return
    // guarded buffer for 'size' as zero. Guarded buffer is assigned to 'fImage'. Test fails if
    // 'fImage' is assigned with guarded buffer.
    if (startPtr != nullptr && (char*)mask.image() == startPtr) {
        free(startPtr);
        return EXIT_VULNERABLE;
    }
    return EXIT_FAILURE;
}
