‹ BackHN Continuity

Thread

Cyclomatic Complexity in C#

87 points · 29 comments · gone35

  1. runningmike · · focus · HN ↗
    From a security perspective cc is highly relevant. I use it to get a solid rating of the security aspects of Python code. I use [1] which is solid and proven.

    [1] <a href="https:&#x2F;&#x2F;nocomplexity.com&#x2F;documents&#x2F;codeaudit&#x2F;complexitycheck.html#complexity-check" rel="nofollow">https:&#x2F;&#x2F;nocomplexity.com&#x2F;documents&#x2F;codeaudit&#x2F;complexitycheck...

    1. thomasmg · · focus · HN ↗
      Is there research that show if and how much a low complexity improves security?
      1. ozim · · focus · HN ↗
        Weird question to ask, that is pretty obvious.

        Worst things happen always when 2 or more systems are combined because each system might be simple on its own, yet a combination is always much more complex.

        1. bunderbunder · · focus · HN ↗
          It’s not obvious to me because cyclomatic complexity is not a straightforward proxy for the number of systems that are being combined.

          It’s also the case that some of the most common sources of vulnerabilities, such as SQL injection, introduce no additional cyclomatic complexity. Heck, buffer overflows are good for your cyclomatic complexity - those array bounds checks are all extra branches.

          1. pixl97 · · focus · HN ↗
            Buffer overflow checks are really only going to be a linear growth in CC. It&#x27;s when things move towards exponential growth or higher that it gets really easy to introduce flaws of many kinds.

            Now, it&#x27;s probably not a direct correlation. I&#x27;d think security bugs are more likely from programmers that unintentionally raise CC without really realizing it. Aka, overreaching their own knowledge when simpler structures are avaliable.

            1. bunderbunder · · focus · HN ↗
              Sure. It’s just that there’s also so much research that has found that cyclomatic complexity is theoretically ill-founded, and that it tends to underperform other ways of measuring complexity. Most notably, just counting lines of code. (Not per function, in total.)

              Here’s an oldie but goodie: <a href="https:&#x2F;&#x2F;cs.du.edu&#x2F;~snarayan&#x2F;sada&#x2F;teaching&#x2F;COMP3705&#x2F;lecture&#x2F;p1&#x2F;cycl-1.pdf" rel="nofollow">https:&#x2F;&#x2F;cs.du.edu&#x2F;~snarayan&#x2F;sada&#x2F;teaching&#x2F;COMP3705&#x2F;lecture&#x2F;p...

              I’ve personally had better success thinking of it as more of a measure of readability than of quality.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.