WalletDescriptor stores an exclusive range end in int32_t. Importing
[2147483647, 2147483647] produces an end of 2^31, which narrows to a negative
value and aborts the node during keypool top-up. An import without a range can
hit the same issue with an oversized -keypool.
Check the exclusive end before constructing the wallet descriptor, covering
both explicit and default ranges. The bound stays wallet-specific: scanning
RPCs still accept INT32_MAX as an inclusive endpoint.
Also calculate the keypool top-up endpoint in int64_t before checking its
bound, and reject reversed ranges before computing high - low in
CheckDescriptorRangeBounds. These fix the overflows reached by
keypoolrefill INT32_MAX after advancing a descriptor, and by [INT64_MAX, 0],
respectively. Regression tests cover all three fixes.
I tested on macOS arm64 with Clang 22 and UBSan passed: 34 targeted unit cases and the importdescriptors, keypool, deriveaddresses (RPC and CLI), scantxoutset, and scanblocks functional tests.