Integer Overflow & Numeric Bugs
In debug builds, overflow panics in +, -, *. In release, two's complement wrapping unless you use checked_*, saturating_*, or wrapping_* explicitly.
Search across all documentation pages
In debug builds, overflow panics in +, -, *. In release, two's complement wrapping unless you use checked_*, saturating_*, or wrapping_* explicitly.
let total = a.checked_add(b).ok_or(Error::Overflow)?;
let cents: i64 = amount.parse().context("amount")?;// User-influenced math
fn price_total(unit_cents: u32, qty: u32) -> Result<u32, Error> {
unit_cents.checked_mul(qty).ok_or(Error::Overflow)
}
// Float money anti-pattern
// Use integer cents or rust_decimal for currencyDebug vs release:
cargo test # may panic on overflow in debug
cargo build --release # wraps silently on + - *Use overflow-checks profile or explicit checked ops in prod paths.
usize indexing: validate length before allocate. Division by zero still panics in release. Float: NaN comparisons need is_nan.
u64 as u32. Fix: try_from.checked_add on durations.| Alternative | Use When | Don't Use When |
|---|---|---|
saturating_add | caps scores | financial totals need error |
wrapping_add | hash/crypto | business logic |
BigInt crate | unbounded | hot path simple ints |
overflow-checks = true in profile or use checked ops.
arithmetic_side_effects and cast lints.
String deserialize for u64 in JSON when >2^53.
Explicit Int64 for ids; watch cast in expressions.
Use unbiased range crates; avoid % bias.
i64 millis; check add with chrono checked APIs.
Same rules; explicit wrapping intrinsics if intended.
#[should_panic] debug only; checked returns Err in prod code.
Use fixed-width ops; no accidental wrap.
grep as and bare + on user integers in hot paths.
Stack versions: This page was written for Rust 1.97.0 (edition 2024), Tokio 1.x, Axum 0.8, serde 1.0, sqlx 0.8, clap 4, and Polars 0.46+.
Reviewed by Chris St. John·Last updated Jul 16, 2026