o inherits a custom toString from proto, so o.hasOwnProperty("toString") is false because that method is not an own property. Yet string coercion walks the prototype chain to find toString and invokes it, producing "P". Inherited methods are fully usable even though hasOwnProperty reports them as not owned.