scan: follow a word only if it could be a heap block's start - 16-aligned, in the user address space, not in the arena
The exit scan crashed two of the gate's scenarios (world, swim: SIGBUS and SIGSEGV in lp_mem_scan at 0x0e00000c65800000 and 0x04000004e461c000): a word of data with its high bits set was handed to malloc_size, and a zone faulted looking it up. A candidate must now be 16-aligned, at or above 4 GB (macOS's page zero), below 2^47, and outside the frame arena before malloc_size sees it; a block's own words are read only once malloc_size has said it is one. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
parent
5aa7c03022
commit
91f91716b5
3 changed files with 47141 additions and 47087 deletions
File diff suppressed because it is too large
Load diff
Loading…
Add table
Add a link
Reference in a new issue