Thought: switch the default on overflow checking and provide RFC 560's scoped attribute for checked arithmetic

I'm sorry, you're correct. I was referring to nikomatsakis' original proposal that proposed an undefined value. In any event, the RFC still declares reliance on wrapping a program error.