v8/tools/clusterfuzz/js_fuzzer/test_data/mutate_objects.js
Michael Achenbach 320d98709f Open source js-fuzzer
This is a JavaScript fuzzer originally authored by Oliver Chang. It
is a mutation based fuzzer using Babel code transformations. For more
information see the included README.md.

The original code was altered:
- Add new V8 copyright headers.
- Make the test expectation generator aware of the headers.
- Fix file endings for presubmit checks.
- Fix `npm test` on fresh checkout with a new fake DB.
- Make test skipping work with new v8/tools location.
- OWNERS file.
- New title section in README.md.

No-Try: true
Bug: chromium:1109770
Change-Id: Ie71752c0a37491a50500c49060a3c526716ef933
Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/2320330
Commit-Queue: Michael Achenbach <machenbach@chromium.org>
Reviewed-by: Maya Lekova <mslekova@chromium.org>
Cr-Commit-Position: refs/heads/master@{#69164}
2020-07-31 11:34:39 +00:00

42 lines
1.0 KiB
JavaScript

// Copyright 2020 the V8 project authors. All rights reserved.
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.
// Empty objects are not manipulated.
a = {};
a = {};
a = {};
a = {};
a = {};
a = {};
// Small objects only get some mutations.
a = {1: 0};
a = {a: 0};
a = {"s": 0};
a = {1: 0};
a = {a: 0};
a = {"s": 0};
// Larger objects get all mutations.
a = {1: "a", 2: "b", 3: "c"};
a = {1: "a", 2: "b", 3: "c"};
a = {1: "a", 2: "b", 3: "c"};
a = {1: "a", 2: "b", 3: "c"};
a = {1: "a", 2: "b", 3: "c"};
a = {1: "a", 2: "b", 3: "c"};
a = {1: "a", 2: "b", 3: "c"};
a = {1: "a", 2: "b", 3: "c"};
a = {1: "a", 2: "b", 3: "c"};
a = {1: "a", 2: "b", 3: "c"};
// Getters and setters are ignored.
a = {get bar() { return 0 }, 1: 0, set bar(t) {}};
a = {get bar() { return 0 }, 1: 0, set bar(t) {}};
a = {get bar() { return 0 }, 1: 0, set bar(t) {}};
// Recursive.
a = {1: {4: "4", 5: "5", 6: "6"}, 2: {3: "3"}};
a = {1: {4: "4", 5: "5", 6: "6"}, 2: {3: "3"}};
a = {1: {4: "4", 5: "5", 6: "6"}, 2: {3: "3"}};