You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Fix VM move forwarding bug with if-expression result registers
Move forwarding was incorrectly forwarding through phi-like merge
points where a register has multiple definitions from different
branches of an if-expression. This caused DCE to eliminate the
then-branch body, producing wrong results.
Example: `if v0 > 0 { 0 - 100 } else { v0 }` returned the else
branch value regardless of the condition.
Fix: skip forwarding when the source register (move_src) has multiple
definitions, since the Move acts as a merge point that must be
preserved so all control flow paths reach the destination.
Found by differential fuzzing (JIT vs VM).
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>