Melanie's v2-0002 in the VM clear thread [1] is the same change as candidate (a), and it fixes this report too. On master the attached test fails without it and passes with it. The same change also passes on 17, 18 and 19.
This does not need a switchover. With full_page_writes = off, a plain standby restart hits it if the restartpoint is before a DELETE or UPDATE that cleared VM bits and a later VACUUM truncated the VM. So it would be good to get v2-0002 in before the next minor release.
I asked Fable to create a test for me.
The attached clears VM bits by delete, HOT update and cross-page update, and fails if any one of the three reads still uses RBM_NORMAL.
Candidate (b) would also work, but once the read no longer uses RBM_NORMAL, no invalid page is logged for the VM, so it is not needed.
Until the fix ships, ignore_invalid_pages = on lets the standby start. It can be turned off after the next restartpoint.