RegExpTestInline extends to quantifiers, alternation, and unicode flags
Component: JavaScriptCore DFG/FTL JIT | 83683ab
Yarr is WebKit's regex engine, and its JIT generates matching code that, for patterns with quantifiers or alternation, needs a scratch frame to track backtracking state — which branch was taken, how many times a group repeated. RegExpTestInline is the DFG/FTL optimization that inlines a regex match directly into JIT-compiled JavaScript instead of calling out to Yarr; previously it refused to inline any pattern needing that frame, because the frame was addressed relative to the frame pointer, a scheme that only works inside Yarr's own call frame.
This commit repurposes the outgoing-argument area at the bottom of the DFG/FTL frame — unused because the inlined matcher never calls anything — to hold the Yarr frame, addressed off the stack pointer instead of the frame pointer. It relies on the enclosing function's own stack check to cover the extra space rather than performing a separate one. That unlocks inlining for patterns with quantifiers, alternation, and the u/v unicode flags.
Significance
Almost all real-world regex literals use quantifiers or alternation, so this closes the gap where RegExpTestInline previously fired on only trivial patterns; benchmarks show ~1.7x speedups on .test() calls. The mechanism is worth noting independently of the numbers: JIT-generated code now writes backtracking state into a stack region whose size is covered by a stack check emitted for a different purpose, and addresses it through the stack pointer rather than the frame pointer.