node/deps/v8/test/mjsunit/array-buffer-view-tracking-regress.js
Michaël Zasso f1e0b83e7b
deps: update V8 to 14.6.202.33
PR-URL: https://github.com/nodejs/node/pull/61898
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Chengzhong Wu <legendecas@gmail.com>
2026-04-24 18:01:28 +02:00

24 lines
679 B
JavaScript

// Copyright 2026 the V8 project authors. All rights reserved.
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.
// Flags: --allow-natives-syntax --track-array-buffer-views
// Update map with detach transition and properties
(() => {
let ab = new ArrayBuffer();
let ta = new Int32Array(ab);
ta[undefined] = undefined;
%ArrayBufferDetach(ab);
let ta2 = new Int32Array();
ta2[undefined] = undefined;
Object.defineProperty(ta2, undefined, {value: {}});
})();
// Update detached map
(function () {
let ab = new ArrayBuffer();
let ta = new Int32Array(ab);
%ArrayBufferDetach(ab);
ta.__proto__ = {};
})();