Static code analysis for complex systems

Find code-level issues before execution with Visao, the static analysis component inside Midair.

Analyze source code, execution paths and project-specific rules before the software runs.

Why static code analysis matters

Some defects are cheaper to find before software is running on devices or distributed environments. Static analysis examines the source without executing it and can surface code-level issues before testing begins.

In Midair, Visao provides that pre-run layer. Its findings can stay connected to later test runs and runtime evidence instead of ending as a separate static report.

What is static code analysis?

Static code analysis examines source code without executing the program. It is used to find potential defects, unsafe behavior and violations of defined rules before runtime testing begins.

Static analysis asks what can be found from the code before execution. Testing asks what happens when the software actually runs.

Static vs dynamic code analysis goes through the difference with examples.

Challenges static analysis has to handle

Four problems that decide whether an analyzer is useful on a real system.

Issues hidden beyond compiler warnings

Code may build successfully and still contain behavior worth investigating.

Project-specific failure rules

Generic analyzers do not know every constraint that matters to a particular system.

Complex execution paths

A defect may depend on a specific path through the code rather than a simple pattern match.

Static findings isolated from later testing

A finding is less useful when it cannot be connected to the test run or runtime behavior that confirms it.

Visao

How Visao analyzes code

Visao combines several analysis techniques to reason about code before execution and produce findings tied to the actual source location and rule involved.

Model checking

Explores the states the program can reach and checks whether a property can be violated on any of them.

Abstract interpretation

Tracks the range of values a variable can hold, which narrows the search and catches some errors on its own.

SMT-based reasoning

Decides whether the conditions that lead to a fault can all hold at the same time.

Project-specific rules

Checks written for the constraints of one codebase, run beside the built-in ones.

Examples of findings

•

Unsafe memory use

For example, a buffer left without its terminator and then read past its end.

•

Integer overflow

For example, a shift that runs into the sign bit after an integer promotion.

•

Violations of project-specific rules

Whatever the team has written down as a failure condition for its own system.

A static finding does not stop at the report

Visao runs before execution. When a finding needs runtime validation, the same investigation can continue in Midair through a TS Factory test run and Delta runtime evidence.

Visao finding → Test run → Runtime evidence

Use cases

•

Embedded software and firmware

Code that eventually runs on hardware with limited observability.

•

Network and system software

Low-level or infrastructure code where behavior depends on system context.

•

Security-sensitive software

Code where unsafe behavior needs to be found before runtime investigation.

•

Complex C and C++ codebases

Large, long-lived source trees where a defect can hide on a rarely taken path.

•

Projects with domain-specific rules

Where generic analyzers do not capture every failure condition that matters.

Capabilities

Static analysis before execution

Find code-level issues without running the software.

Project-specific checks

Apply rules that reflect the actual constraints of the project.

Path-aware analysis

Investigate behavior that depends on how execution reaches a particular state.

CI/CD integration

Run analysis as part of existing development workflows.

Connected evidence in Midair

Carry relevant findings into later testing and runtime investigation.

Start your pilot

Start with your own codebase and see how Visao findings connect with testing and runtime evidence in Midair.