Skip to main content

Module arith

Module arith 

Source
Expand description

Integer helpers that keep the 128-bit multiply helper out of a program.

u64::checked_mul and u64::saturating_mul lower to umul.with.overflow, which the sBPF instruction set has no form of, so LLVM links __multi3 (344 bytes) and calls it for every such product (about 50 CU each). The divide-guard idioms a > u64::MAX / b and (a * b) / b != a are recognized and folded back into the same helper. Splitting both operands into 32-bit halves decides overflow with 64-bit arithmetic only: the product exceeds 64 bits exactly when both high halves are nonzero, when the cross term reaches 2^32, or when the final add carries. Measured 2026-09-21 on the framework-comparison counter, where the rent product alone linked and called the helper on every init.

Traits§

LeanMul
Checked multiplication that routes 64-bit unsigned products through checked_mul_u64 and every other width through the library operator (which needs no helper below 64 bits). Used by the wire integer types, so WireU64::checked_mul and checked_mul_assign never link the helper.

Functions§

checked_mul_u64
a * b when it fits in 64 bits, None otherwise, without __multi3.
saturating_mul_u64
a * b, saturating at u64::MAX, without __multi3.