I love the compromise on integer overflow. Default overflow checking in debug mode will keep most Rust programs free of overflow, and that should ensure that if hardware designers ever come to their senses and implement free hardware overflow traps, Rust code can enable them without issue.
Rust's position is reasonable, but it won't keep most programs free of overflow. Overflow and underflow bugs typically require malicious input to expose; casual testing usually doesn't encounter them.
Also, in release builds they promise an undefined value, not undefined behavior. By my reading, hardware-assisted overflow checks cannot log errors or do anything else useful under this policy. (Probably saturating arithmetic is best, since it's most likely to trigger an out-of-bounds error.)
Their saving grace is the other safety checks (e.g. bounds checking), and their assertion that "we reserve the right to make checking stricter in the future" which enables them to strengthen this policy.