HIGH_BIT_RESULT_POINTER

oobresptr.wat (91 bytes) — warp_run returns packed (resPtr = 0x8000_0000, resLen = 4): a result pointer with bit 31 set. Signed-int narrowing would wrap it negative and read host memory below the linear-memory base — a sandbox-escape OOB read.