> Defining overflow as wrapping, for example, would be bad for security because it means we couldn't check it with UBSan.
You could always write “WrapAroundSan”.
You could always write “WrapAroundSan”.
This is effectively what Rust does (replace "SIGILL" by "panic").
That also means it's possible to write overflow checks easily, and ones that the compiler won't optimise out. Before compilers became UB-crazy, you could write such checks in the most straightforward way, and get exactly what you expected. I'd consider that a far bigger advantage for security than arguing for the existence of a tool whose sole reason for existence seems to be due to the presence of UB in the first place.