v8/test/mjsunit/regress/regress-crbug-627828.js
mstarzinger a2f1519f68 [turbofan] Fix deopt point for [[ToName]] lazy bailout.
This fixes the deoptimization information for the lazy bailout point
after a [[ToName]] operation inserted for object literals and class
literals. The result value was erroneously ignored.

R=jarin@chromium.org
TEST=mjsunit/regress/regress-crbug-627828
BUG=chromium:627828

Review-Url: https://codereview.chromium.org/2149493003
Cr-Commit-Position: refs/heads/master@{#37719}
2016-07-13 15:18:10 +00:00

41 lines
933 B
JavaScript

// Copyright 2016 the V8 project authors. All rights reserved.
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.
// Flags: --allow-natives-syntax
(function TestDeoptFromCopmputedNameInObjectLiteral() {
function f() {
var o = {
toString: function() {
%DeoptimizeFunction(f);
return "x";
}
};
return { [o]() { return 23 } };
}
assertEquals(23, f().x());
assertEquals(23, f().x());
%OptimizeFunctionOnNextCall(f);
assertEquals(23, f().x());
})();
(function TestDeoptFromCopmputedNameInClassLiteral() {
function g() {
var o = {
toString: function() {
%DeoptimizeFunction(g);
return "y";
}
};
class C {
[o]() { return 42 };
}
return new C();
}
assertEquals(42, g().y());
assertEquals(42, g().y());
%OptimizeFunctionOnNextCall(g);
assertEquals(42, g().y());
})();