scan: follow a word only if it could be a heap block's start - 16-aligned, in the user address space, not in the arena

The exit scan crashed two of the gate's scenarios (world, swim: SIGBUS and SIGSEGV in lp_mem_scan at
0x0e00000c65800000 and 0x04000004e461c000): a word of data with its high bits set was handed to
malloc_size, and a zone faulted looking it up. A candidate must now be 16-aligned, at or above 4 GB
(macOS's page zero), below 2^47, and outside the frame arena before malloc_size sees it; a block's
own words are read only once malloc_size has said it is one.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Orkun ÇAKILKAYA 2026-09-28 18:21:37 +03:00
parent 5aa7c03022
commit 91f91716b5
3 changed files with 47141 additions and 47087 deletions

File diff suppressed because it is too large Load diff