Files
Kmake/deps/v8/test/mjsunit/maglev/regress-324459570.js

28 lines
618 B
JavaScript
Raw Normal View History

2026-05-26 23:36:42 -07:00
// Copyright 2024 the V8 project authors. All rights reserved.
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.
//
// Flags: --allow-natives-syntax --maglev
const a = [1, 2, 3]
function foo(i) {
return a[i];
}
// Setting a negative index does not violate the NoElements protector.
Array.prototype[-1] = "Uh!";
%PrepareFunctionForOptimization(foo);
foo(0);
foo(5);
%OptimizeMaglevOnNextCall(foo);
foo(0);
foo(7); // It is able to read out of bounds.
assertTrue(isOptimized(foo));
foo(-1); // Deopt, since index is negative.
assertTrue(!isOptimized(foo));