Concept and mechanism
Static analysis investigates a program without executing its paths. It can reveal variable use before assignment, a write overwritten before any read, or an apparently unreachable branch. These signals need context: a second assignment may be deliberate, and a reported path may be infeasible under a precondition unknown to the tool. Record the justification for each suppression and prefer making the contract explicit over disabling an entire alert class. Cyclomatic complexity is a structural indicator; for a connected graph with single entry and exit, E minus N plus two calculates it. It is not a count of every possible path, particularly when loops exist.
Guided application
Dynamic analysis observes a concrete execution and can expose resource growth, invalid accesses, or time-consuming areas. For a process whose memory grows over many hours, compare allocations, releases, caching, and load before concluding that a leak exists. Restarting may reduce the symptom without fixing its cause. In native code, AddressSanitizer instruments compilation and uses a runtime library to detect classes of memory errors along exercised paths. Instrumentation has a cost and should not be confused with performance measurement of the normal binary. Retain the version, configuration, and path reproducing the problem. Combining static and dynamic analysis provides complementary evidence rather than a guarantee that defects are absent.
For a connected graph with E=9 and N=7, complexity is 4.
Common pitfalls
Warning treated as certain defect; growth treated as proven leak; instrumented binary treated as normal benchmark.
Related topics: Technical risk and operational evidence · White-box logical coverage · Performance and workload profile
Investigate signals through hypotheses and reproducible context.
Reference: LLVM Clang static analysis FAQ · CTAL-TTA v4.0 (2021)