Cyclomatic Complexity in C#

(blog.ndepend.com)

17 points | by gone35 2 days ago

3 comments

  • bunderbunder 42 minutes ago
    Overall cyclomatic complexity is a useful metric, but it does have one shortcoming when used with modern languages: it was invented before polymorphism really became a thing.

    That means that it really only counts explicit branching. So, for example, in an OO language like C#, calling a virtual method doesn’t increment cyclomatic complexity even though the method invocation could go down many code paths. Potentially thousands if you’re dealing with a common interface like IEnumerable. If you’re working on a library then the number of potential code paths in this kind of situation is unbounded.

    As an aside, it’s interesting to think how it might apply to a language like Smalltalk that doesn’t even have if or switch statements.

    OO isn’t the only monkey wrench, either. Higher-order functions also introduce forms of branching that cyclomatic complexity doesn’t measure.

    Again that doesn’t make it a useless metric. Just don’t think that a cyclomatic complexity limit in your codebase is some sort of maintainability panacea. Some of the least comprehensible functions I’ve deciphered had quite low cyclomatic complexities.

  • woggy 1 hour ago
    Anyone using tools like ndepend or others to help guide agents in refactors?

    Personally I have a some tools that build dependency graphs (C# and Python) and store the results in a local database. Agents seem quite good at poking at this and coming up with refactor ideas. Graph analysis tools are useful here, simple application will detect cyclical dependencies, but I encourage the agents to use more complex tools like clustering to poke at the data.

    • cryptolobster 40 minutes ago
      I've been feeding agents dependency graphs plus CC and coverage data from a local store, and it works well for spotting cyclical deps and high-CC hotspots
  • runningmike 1 hour ago
    From a security perspective cc is highly relevant. I use it to get a solid rating of the security aspects of Python code. I use [1] which is solid and proven.

    [1] https://nocomplexity.com/documents/codeaudit/complexitycheck...

    • thomasmg 1 hour ago
      Is there research that show if and how much a low complexity improves security?
      • ozim 44 minutes ago
        Weird question to ask, that is pretty obvious.

        Worst things happen always when 2 or more systems are combined because each system might be simple on its own, yet a combination is always much more complex.

        • bunderbunder 37 minutes ago
          It’s not obvious to me because cyclomatic complexity is not a straightforward proxy for the number of systems that are being combined.

          It’s also the case that some of the most common sources of vulnerabilities, such as SQL injection, introduce no additional cyclomatic complexity. Heck, buffer overflows are good for your cyclomatic complexity - those array bounds checks are all extra branches.

          • pixl97 25 minutes ago
            Buffer overflow checks are really only going to be a linear growth in CC. It's when things move towards exponential growth or higher that it gets really easy to introduce flaws of many kinds.

            Now, it's probably not a direct correlation. I'd think security bugs are more likely from programmers that unintentionally raise CC without really realizing it. Aka, overreaching their own knowledge when simpler structures are avaliable.

            • bunderbunder 11 minutes ago
              Sure. It’s just that there’s also so much research that has found that cyclomatic complexity is theoretically ill-founded, and that it tends to underperform other ways of measuring complexity. Most notably, just counting lines of code. (Not per function, in total.)

              Here’s an oldie but goodie: https://cs.du.edu/~snarayan/sada/teaching/COMP3705/lecture/p...

              I’ve personally had better success thinking of it as more of a measure of readability than of quality.