Protocol
Share Calculation
Formula, integer arithmetic constraints, and strict overflow protection.
Financial calculations in SplitPay must never panic or silently overflow. All mathematical operations use Rust's checked methods.
Checked Integer Arithmetic
Every multiplication, division, addition, and subtraction in the contract is checked:
checked_mul()prevents multiplication overflow when multiplying large payments by BPS.checked_div()handles integer division by 10,000.checked_add()andchecked_sub()prevent underflow and overflow.
Overflow & Truncation Protection
Any arithmetic failure results in Error::ArithmeticOverflow (17), aborting the transaction before any token transfer can occur.
Mathematical Invariant Formula
sum(distributions) == gross_payment_amount
Guaranteed for all integer amounts > 0 and all valid 10,000 BPS pool splits.