summaryrefslogtreecommitdiffstats
path: root/js/src/jit-test/tests/bug1782558-veclen.js
diff options
context:
space:
mode:
authorDaniel Baumann <daniel.baumann@progress-linux.org>2024-04-07 19:33:14 +0000
committerDaniel Baumann <daniel.baumann@progress-linux.org>2024-04-07 19:33:14 +0000
commit36d22d82aa202bb199967e9512281e9a53db42c9 (patch)
tree105e8c98ddea1c1e4784a60a5a6410fa416be2de /js/src/jit-test/tests/bug1782558-veclen.js
parentInitial commit. (diff)
downloadfirefox-esr-upstream.tar.xz
firefox-esr-upstream.zip
Adding upstream version 115.7.0esr.upstream/115.7.0esrupstream
Signed-off-by: Daniel Baumann <daniel.baumann@progress-linux.org>
Diffstat (limited to '')
-rw-r--r--js/src/jit-test/tests/bug1782558-veclen.js14
1 files changed, 14 insertions, 0 deletions
diff --git a/js/src/jit-test/tests/bug1782558-veclen.js b/js/src/jit-test/tests/bug1782558-veclen.js
new file mode 100644
index 0000000000..a8f1a48ea9
--- /dev/null
+++ b/js/src/jit-test/tests/bug1782558-veclen.js
@@ -0,0 +1,14 @@
+// |jit-test| skip-if: getBuildConfiguration()["pointer-byte-size"] > 4 || getBuildConfiguration()["android"]
+
+// On 64-bit, this will allocate 2G temporary strings for keys while
+// stringifying the Array, which takes a rather long time and doesn't have the
+// potential of the problematic overflowing anyway.
+
+try {
+ let x = [];
+ x.length = Math.pow(2, 32) - 1;
+ x + 1;
+ assertEq(true, false, "overflow expected");
+} catch (e) {
+ assertEq((e + "").includes("InternalError: allocation size overflow"), true);
+}