diff --git a/runtime/flan_rt.c b/runtime/flan_rt.c index dd58fcd6..19686241 100644 --- a/runtime/flan_rt.c +++ b/runtime/flan_rt.c @@ -1502,7 +1502,9 @@ flan_allocator *flan_arena_new(int64_t cap) { /* What an allocator's procedure becomes once [flan_arena_destroy] has handed * its arena back. Every request traps, because there is nothing left to serve * it from and answering NULL would read as exhaustion — which a retry handler - * that raises the budget would then retry for ever. */ + * that raises the budget would then retry for ever. Flan code does not reach + * it: a stale Allocator value traps in flan_alloc_use and a stale container on + * its epoch first. It is the backstop for a caller holding the bare record. */ static void *flan_destroyed_proc(flan_allocator *a, int32_t mode, void *p, int64_t old_size, int64_t size, int64_t align) { (void)a; (void)mode; (void)p; (void)old_size; (void)size; (void)align;