Summary
Stan Math's macOS default includes tbbmalloc_proxy alongside tbb and tbbmalloc. In a Julia process loading a BridgeStan 2.9.0 model, we traced a SIGSEGV to the bundled TBB allocator's ownership probe of a system-allocated buffer. Building models with TBB_LIBRARIES=tbb stopped the observed recurring crashes.
Crash evidence
Julia 1.10.11, macOS 26.6.2 arm64, BridgeStan 2.9.0, bundled TBB 2020.3:
- Stack: Julia GC frees an array buffer → macOS
find_zone_and_free → __TBB_malloc_safer_msize + 80 in libtbbmalloc.dylib.
- Faulting instruction:
ldurh w8, [x19, #-4].
x0 = x19 = 0x451c00000: the start of a 2848K system MALLOC_LARGE region.
- Fault address
0x451bffffc falls in the unmapped 16K gap immediately before that region.
- The proxy and allocator libraries were loaded. No Stan model code was on the faulting stack.
The TBB 2020.3 macOS proxy registers a process-wide malloc zone, whose size() callback calls __TBB_malloc_safer_msize(ptr, NULL). TBB's isLargeObject<unknownMem> reads a would-be header below a foreign pointer after its range/alignment checks. safer_dereference guards access violations under MSVC only; the same unguarded probe remains in current oneTBB.
Scope
BridgeStan inherits these makefiles. CmdStan includes them too and links TBB_TARGETS into model executables, so the default allocator configuration also reaches macOS CmdStan models. We have not demonstrated a CmdStan crash. Its separate process avoids replacing the calling Python/R/Julia application's allocator, but does not establish safety of the sampling executable itself.
The observed crash is a native allocator failure, not evidence of incorrect Stan model calculations. This report is based on the crash report and source inspection; no standalone reproducer has been run. Related signatures are tracked in Pigeons.jl#266 and oneTBB#210.
Suggested mitigation
Please consider making allocator-proxy replacement opt-in, at least for shared-library consumers, and documenting this macOS failure mode. TBB_LIBRARIES=tbb preserves TBB threading while omitting allocator replacement; STAN_THREADS is independent. Existing models must be rebuilt, and a fresh process must not load an older proxy-linked model. We have not benchmarked the performance tradeoff, and are not asserting all Stan interfaces or CmdStan workloads crash.
Summary
Stan Math's macOS default includes
tbbmalloc_proxyalongsidetbbandtbbmalloc. In a Julia process loading a BridgeStan 2.9.0 model, we traced a SIGSEGV to the bundled TBB allocator's ownership probe of a system-allocated buffer. Building models withTBB_LIBRARIES=tbbstopped the observed recurring crashes.Crash evidence
Julia 1.10.11, macOS 26.6.2 arm64, BridgeStan 2.9.0, bundled TBB 2020.3:
find_zone_and_free→__TBB_malloc_safer_msize + 80inlibtbbmalloc.dylib.ldurh w8, [x19, #-4].x0 = x19 = 0x451c00000: the start of a 2848K systemMALLOC_LARGEregion.0x451bffffcfalls in the unmapped 16K gap immediately before that region.The TBB 2020.3 macOS proxy registers a process-wide malloc zone, whose
size()callback calls__TBB_malloc_safer_msize(ptr, NULL). TBB'sisLargeObject<unknownMem>reads a would-be header below a foreign pointer after its range/alignment checks.safer_dereferenceguards access violations under MSVC only; the same unguarded probe remains in current oneTBB.Scope
BridgeStan inherits these makefiles. CmdStan includes them too and links
TBB_TARGETSinto model executables, so the default allocator configuration also reaches macOS CmdStan models. We have not demonstrated a CmdStan crash. Its separate process avoids replacing the calling Python/R/Julia application's allocator, but does not establish safety of the sampling executable itself.The observed crash is a native allocator failure, not evidence of incorrect Stan model calculations. This report is based on the crash report and source inspection; no standalone reproducer has been run. Related signatures are tracked in Pigeons.jl#266 and oneTBB#210.
Suggested mitigation
Please consider making allocator-proxy replacement opt-in, at least for shared-library consumers, and documenting this macOS failure mode.
TBB_LIBRARIES=tbbpreserves TBB threading while omitting allocator replacement;STAN_THREADSis independent. Existing models must be rebuilt, and a fresh process must not load an older proxy-linked model. We have not benchmarked the performance tradeoff, and are not asserting all Stan interfaces or CmdStan workloads crash.