Upgrade V8 to version 4.9.385.28
https://chromium.googlesource.com/v8/v8/+/4.9.385.28
FPIIM-449
Change-Id: I4b2e74289d4bf3667f2f3dc8aa2e541f63e26eb4
diff --git a/test/mjsunit/regress/regress-crbug-527364.js b/test/mjsunit/regress/regress-crbug-527364.js
new file mode 100644
index 0000000..914bed0
--- /dev/null
+++ b/test/mjsunit/regress/regress-crbug-527364.js
@@ -0,0 +1,26 @@
+// Copyright 2015 the V8 project authors. All rights reserved.
+// Use of this source code is governed by a BSD-style license that can be
+// found in the LICENSE file.
+
+// Flags: --stack-size=100 --allow-natives-syntax
+
+function module() {
+ "use asm";
+ var abs = Math.abs;
+ function f() {
+ return +abs();
+ }
+ return { f:f };
+}
+
+function run_close_to_stack_limit(f) {
+ try {
+ run_close_to_stack_limit(f);
+ f();
+ } catch(e) {
+ }
+}
+
+var boom = module().f;
+%OptimizeFunctionOnNextCall(boom)
+run_close_to_stack_limit(boom);