TNFR Logo
TheoryLearnSoftwareResearch

On this page

TNFR

Resonant Fractal Nature Theory — a mathematical framework for coherent patterns on graph-coupled networks.

About
  • Project history
  • Editorial policy
  • Contact
Resources
  • GitHub
  • PyPI
  • DOI · Zenodo
Legal
  • MIT License
  • Citation
© 2026 TNFR project — MIT licensed.DOI 10.5281/zenodo.17602860
docs
grammar
PHYSICS_VERIFICATION.md
API_CONTRACTS.mdCANONICAL_OZ_SEQUENCES.mdEMPIRICAL_CONFRONTATION_EEG.mdREADME.mdSTRUCTURAL_FIELDS_TETRAD.mdSTRUCTURAL_INTERFACE_THEORY.md
theory
APPLIED_STRUCTURAL_ANALYSIS.mdCATALOG_TYPE_HYGIENE_PROGRAMME.mdDISSIPATIVE_AND_OPEN_SYSTEMS.mdEMERGENT_ONTOLOGY.mdEXTENDED_FIELDS_AND_DERIVED_QUANTITIES.mdFUNDAMENTAL_THEORY.mdGAUGE_SYMMETRY_AND_UNIFICATION.mdGLOSSARY.mdMATHEMATICAL_DYNAMICS_BASIS.mdMINIMAL_STRUCTURAL_DEGREES.mdNUCLEUS_A_PRIME_LADDER_ATLAS.mdNUCLEUS_B_EQUIVARIANCE_OBSTRUCTIONS.mdPHYSICAL_REGIME_CORRESPONDENCES.mdREADME.mdREMESH_INFINITY_DERIVATION.mdSTRUCTURAL_CONSERVATION_THEOREM.mdSTRUCTURAL_OPERATORS.mdSTRUCTURAL_STABILITY_AND_DYNAMICS.mdTNFR_BSD_RESEARCH_NOTES.mdTNFR_HODGE_RESEARCH_NOTES.mdTNFR_NAVIER_STOKES_RESEARCH_NOTES.mdTNFR_NUMBER_THEORY.mdTNFR_P_VS_NP_RESEARCH_NOTES.mdTNFR_RIEMANN_RESEARCH_NOTES.mdTNFR_VARIATIONAL_PRINCIPLE.mdTNFR_YANG_MILLS_RESEARCH_NOTES.mdTNFR.pdfUNIFIED_GRAMMAR_RULES.md
factorization-lab
analysis
analyze_patterns.pycertificate_manifest.py
benchmarks
benchmark_analysis.pybenchmark_expansion_suite.pyfull_spectrum_factorization.pypaley_gap_extended.pypaley_gap_smoke.pytest_benchmark_suite.py
demos
experiment_contexts
exp_0b1663cd19b7.jsonexp_0bf0054b7474.jsonexp_75a4c8ca616a.jsonexp_848ee0fd1857.jsonexp_f6fe00562193.jsonexp_fdf3da424e1e.json
failure_telemetry_batch.pyfeedback_integration_demo.pyintegration_demo_snapshots.dbseed_management_integration_demo.pysnapshot_integration_demo.pytrajectory_143.jsontrajectory_77.jsontrajectory_89.jsontrajectory_91.jsontrajectory_97.json
docs
FACTORING_PLAYBOOK.mdFALSE_POSITIVE_TEST_SUITE.mdOPERATOR_CERTIFICATES.mdROADMAP.mdSPECTRAL_ROUTE.md
experiment_contexts
exp_cebe1d9e7d8e.json
notebooks
spectral_history.ipynb
scripts
run_false_positive_tests.py
tests
run_false_positive_test_suite.pytest_cli.pytest_false_positive_methodology.pytest_false_positive_verifier.pytest_feedback_integration.pytest_partitioning.pytest_seed_management.pytest_self_opt_support.pytest_snapshot_system.pytest_spectral_paley.pytest_verification_robustness.py
tnfr_factorization
__init__.pyapi.pycli.pyfailure_telemetry.pyfeedback_adapter.pyfeedback_integration.pypartitioning.pyself_opt_support.pyspectral_paley.py
demo_snapshots.dbLICENSE_SNAPSHOT.mdPACKAGE_SUMMARY.mdREADME.mdseed_management.pysnapshot_system.pytest_certificate_hashing.pytest_installation.pyverification_trajectory_77.json
benchmarks
analyze_tetrad_universality.pyb0star_alpha_canonical_product_graphs.pybenchmark_optimization_tracks.pybenchmark_utils.pyboundary_vibration.pybridge_primes_riemann.pychiral_involution.pycli_utils.pycoherence_projector_sense_index.pycommutant_bridge.pycomposition_arithmetic.pyconfinement_zones_test.pyconservation_law_validation.pydirected_paley_bridge.pyemergent_arithmetic_pulse.pyemergent_atom_dynamics.pyemergent_atomic_shells.pyemergent_base_dimension.pyemergent_dimension_dynamics.pyemergent_fractal_pulse.pyemergent_fractal_simplex_dimension.pyemergent_integers_symmetry.pyemergent_musical_nfr.pyemergent_nfr_geometry.pyemergent_nfr_where.pyemergent_rationals.pyemergent_rhythm.pyemergent_screening.pyemergent_shell_cardinals.pyemergent_shell_ordering.pyemergent_simplex_dimension.pyemergent_substrate_symmetry.pyequivariance_wall.pyexternal_phase_gate_validation.pyfield_methods_battery.pygolden_residue_remesh_bridge.pyintegrated_force_regime_study.pyinverse_spectrum_to_symmetry.pyk_phi_safety_demo.pykuramoto_farey_bridge.pymissing_piece_bridge.pymultichannel_interface_benchmark.pynavier_stokes_recipe_bridge.pynodal_propagator_residue_bridge.pyns_moment_hierarchy_cascade.pyoperational_irreducibility.pypaley_bridge.pyphase_curvature_investigation.pyphase_wall.pyphi_s_confinement_investigation.pyprimes_as_consequence.pypulse_phase_coherence_budget.pyREADME.mdremesh_infinity_riemann_baseline.pyremesh_infinity_riemann_composed.pyremesh_infinity_riemann_modified_graph.pyremesh_infinity_riemann_operator.pyremesh_infinity_riemann_spectral_basis.pyremesh_infinity_riemann_spectral_robustness.pyremesh_infinity_riemann_spectral.pyresidue_phase_vs_riemann.pystructural_interface_benchmark.pytemporal_interface_benchmark.pytetrad_results_aggregate.pyu2_destabilization_irreversibility.pyuniversality_clusters.pyxi_c_fast_experiment.py
primality-test
benchmarks
comprehensive_benchmark.py
docs
ADVANCED_INTEGRATION.mdmathematical_foundation.mdperformance_analysis.md
examples
advanced_examples.pybasic_usage.py
tnfr_primality
__init__.py__main__.pyadvanced_cli.pyadvanced_core.pycli.pyconstants.pycore.pyoptimized.py
MANIFEST.inPACKAGE_SUMMARY.mdREADME.mdRELEASE_NOTES_v1.0.mdsetup.pytest_installation.py
tests
core_physics
__init__.pytest_conservation_laws.pytest_delta_nfr_computation_paths.pytest_delta_nfr.pytest_dispersion_coherence_sign_invariance.pytest_emergent_constants_guard.pytest_lyapunov_operators.pytest_nodal_equation.pytest_structural_triad.py
data
replay_manifests
sample_run
_manifest_summary.json_manifest.json_partition_files.txt.gz
self_opt_validation
seed_alpha
paley.json
seed_beta
integration.json
seed_gamma
unknown.json
self_optimization
test_run
partitioned
test_run
test_run_p0.jsontest_run_p1.json
_manifest_summary.json_manifest.json
engines
test_pattern_discovery_manifest.pytest_self_optimization_engine.py
mathematics
__init__.pytest_autodiff.pytest_backends.pytest_dissipative_dynamics.pytest_epi.pytest_factory_patterns.pytest_metrics.pytest_navier_stokes_refounded.pytest_number_theory_canonical.pytest_operators.pytest_residue_networks.pytest_riemann_nodal_pulse.pytest_riemann_pulse_coherence.pytest_spaces.pytest_transforms.pytest_validator.py
operators
test_canonical_operators_modern.pytest_grammar_canon.pytest_grammar_canonical_consistency.pytest_grammar_dynamics.pytest_operator_contracts.pytest_operator_strategies.py
parallel
test_fractal_partition_manifest.py
physics
test_conservation_gauge_unification.pytest_dissipative_conservation.pytest_emergent_chemistry.pytest_field_cache_invalidation.pytest_gauge.pytest_phase_transition.pytest_signatures.pytest_spectral_conservation.pytest_structural_diffusion.pytest_structural_integrity.pytest_symplectic_substrate.pytest_tetrad_bounds.pytest_variational.pytest_yang_mills_closure.pytest_yang_mills_derivability.pytest_yang_mills_scaling.pytest_yang_mills_structural_gap.pytest_yang_mills_u6_sweep.py
scripts
test_run_self_opt_validation.pytest_run_self_optimization.py
sdk
__init__.pytest_simple_advanced.py
__init__.pyconftest.pyREADME.mdtest_breast_cancer_phase_gate_demo.pytest_classical_mechanics.pytest_distributed_fft.pytest_external_phase_gate_validation.pytest_factorization_entrypoint.pytest_multichannel_interface.pytest_nodal_optimizer.pytest_phase_gate_api.pytest_replay_register_manifest.pytest_signal_confrontation.pytest_structural_interface_api.pytest_structural_interface_baselines.pytest_structural_interface_benchmark.pytest_temporal_interface.pytest_vectorized_coherence_length_regression.pytest_wine_quality_phase_gate_demo.pyutils.py
examples
01_foundations
01_hello_world.py02_musical_resonance.py03_network_formation.py04_operator_sequences.py05_coherence_evolution.py06_network_topologies.py07_phase_transitions.py08_emergent_phenomena.py09_visualization_suite.py10_simplified_sdk_showcase.py
02_physics_regimes
11_classical_limit_comparison.py115_operator_contract_audit.py12_classical_mechanics_demo.py13_quantum_mechanics_demo.py14_uncertainty_and_interference.py15_train_crossing_demo.py17_conservation_law_demo.py26_gauge_structure_demo.py27_variational_principle_demo.py28_dissipative_systems_demo.py29_lyapunov_stability_demo.py30_self_optimization_demo.py31_mathematical_constants_basis.py33_complex_field_unification.py34_conservation_protocol_suite.py35_tetrad_irreducibility.py36_grammar_violation_detector.py37_operator_tetrad_synergy.py38_grammar_energy_landscape.py39_nodal_equation_decomposition.py
03_riemann_zeta
157_nodal_pulse_phase_attack.py41_von_mangoldt_zeta_demo.py42_riemann_zeros_as_resonances.py43_prime_ladder_hamiltonian_demo.py44_weil_explicit_formula_demo.py45_li_keiper_demo.py46_weil_tnfr_positivity_demo.py47_alpha_sweep_demo.py48_admissible_family_sweep_demo.py49_nodeaware_gauge_sweep_demo.py50_uniform_coercivity_demo.py51_adaptive_coercivity_demo.py52_paley_gap_coercivity_demo.py53_lyapunov_spectral_positivity_demo.py54_hilbert_polya_demo.py55_structural_zero_density_demo.py56_spectral_emergence_demo.py57_admissible_rescaling_demo.py58_oscillatory_correction_demo.py
04_riemann_L_twisted
59_dirichlet_l_function_demo.py60_dirichlet_l_continuation_demo.py61_dirichlet_l_hamiltonian_demo.py62_dirichlet_weil_explicit_formula_demo.py63_dirichlet_li_keiper_demo.py64_twisted_weil_positivity_demo.py65_twisted_alpha_sweep_demo.py66_twisted_admissible_family_sweep_demo.py67_twisted_nodeaware_gauge_sweep_demo.py68_twisted_hermite_family_demo.py69_twisted_coercivity_uniform_demo.py70_twisted_paley_gap_coercivity_demo.py71_twisted_lyapunov_spectral_demo.py72_twisted_hilbert_polya_demo.py73_twisted_structural_zero_density_demo.py74_twisted_spectral_emergence_demo.py75_twisted_admissible_rescaling_demo.py76_twisted_oscillatory_correction_demo.py
05_type_hygiene
77_remesh_infinity_residue_split_demo.py78_nuf_type_signature_demo.py79_epi_type_signature_demo.py80_phi_type_signature_demo.py81_dnfr_type_signature_demo.py82_remesh_window_type_signature_demo.py83_delta_phi_max_type_signature_demo.py84_coupling_weights_type_signature_demo.py85_tetrad_closure_signature_demo.py86_currents_closure_signature_demo.py87_aggregates_closure_signature_demo.py88_urules_consistency_signature_demo.py89_operator_catalog_discipline_signature_demo.py
06_navier_stokes
158_navier_stokes_two_face_refounded.py
07_number_theory
100_prime_families_orbits.py101_numbers_as_coupled_network.py102_nodal_flow_primes_equilibria.py116_nuf_emergent_prime_visibility.py146_primality_grammatical_inertness.py147_numbers_as_free_monoid_words.py148_capacity_arm_carries_von_mangoldt.py149_p14_is_the_capacity_arm_operator.py153_structural_frequency_rank_cyclotomy.py40_arithmetic_number_theory.py94_generative_number_construction.py95_primes_from_spectral_waves.py96_spectral_vibration_of_coherence.py97_goldbach_additive_multiplicative.pyemergent_chemistry_particles_demo.py
08_emergent_geometry
103_emergent_substrate_meets_riemann.py106_per_node_polarization_geometry.py107_orthogonal_structure_emergent_geometry.py108_emergent_field_generating_structure.py112_structure_predicts_coherence_flow.py113_overdamped_projection_bridge.py114_substrate_conserved_quantities.py117_emergent_geometry_residue_graph.py118_emergent_vs_classical_operator.py119_phase_sector_directed_residue.py120_symmetry_wall_substrate_vs_spectrum.py121_canonical_symmetry_break_negative.py122_factorization_phase_sector.py123_symmetry_sector_decomposition.py124_emergent_metric_fractal_consistency.py125_node_is_the_emergent_substrate.py126_two_layers_base_fiber.py127_base_is_emergent_not_imposed.py128_base_substrate_coemergence.py129_spectral_gap_base_fiber_clock.py130_operators_break_substrate_charges.py131_coemergent_loop_convergence.py132_geometric_phase_holonomy.py133_psi_topological_defects.py134_spectral_dimension_heat_kernel.py135_arrow_of_time_h_theorem.py136_heat_kernel_coefficients.py137_synchronization_transition.py138_structure_frequency_synchronization.py139_grammar_formal_language.py140_grammar_automaton.py141_grammar_rule_decomposition.py142_grammar_operator_quotient.py143_glyphic_function_sublanguage.py144_branching_combinator.py145_syntactic_monoid_starfree.py150_emergent_grammatical_pattern_parry.py151_grammar_in_emergent_geometry.py152_operator_contract_tetrahedron.py154_conductor_annotated_qr_spectrum.py155_ontological_position_of_numbers.py156_emergence_directness_law.py98_emergent_symplectic_substrate.py99_structural_diffusion.pyunified_fields_showcase.py
09_millennium
109_p_vs_np_coherence_synthesis.py110_bsd_rank_structural_pressure.py111_hodge_discrete_and_honest_gap.py
10_applications
159_empirical_confrontation_pipeline.py90_phase_gate_monitor_demo.py91_breast_cancer_phase_gate_demo.py92_wine_quality_phase_gate_demo.py93_structural_interface_demo.pypytorch_cuda_demo.py
README.md
scripts
replay
__init__.pyregister_manifest.py
__init__.pyREADME.mdrebuild_failure_manifest.pyrun_reproducible_benchmarks.pyrun_self_opt_validation.pyrun_self_optimization.pytnfr_is_prime.pyvalidate_conservation_law.pyverify_internal_references.py
src
core
__init__.pyevaluation.py
tnfr
backends
__init__.pyjax_backend.pynumpy_backend.pyoptimized_numpy.pyREADME.mdtorch_backend.py
cli
__init__.py__init__.pyiarguments.pyarguments.pyiexecution.pyexecution.pyiinteractive_validator.pyREADME.mdutils.pyutils.pyi
compat
__init__.pydataclass.pyjsonschema_stub.pymatplotlib_stub.pynumpy_stub.pyREADME.md
config
__init__.py__init__.pyiconstants.pyconstants.pyidefaults_core.pydefaults_init.pydefaults_metric.pydefaults.pyfeature_flags.pyfeature_flags.pyiglyph_constants.pyoperator_names.pyoperator_names.pyiphysics_derivation.pyprecision_modes.pypresets.pypresets.pyiREADME.mdsecurity.pythresholds.pytnfr_config.py
constants
__init__.py__init__.pyialiases.pyaliases.pyicanonical.pymetric.pymetric.pyioperational.py
core
__init__.pycontainer.pydefault_implementations.pyexceptions.pyinterfaces.pyREADME.md
dynamics
__init__.py__init__.pyiadaptation.pyadaptation.pyiadaptive_sequences.pyadaptive_sequences.pyiadelic.pyadvanced_cache_optimizer.pyadvanced_fft_arithmetic.pyaliases.pyaliases.pyibifurcation.pycache_aware_fft_engine.pycanonical.pycanonical.pyicomputational_hub.pycoordination.pycoordination.pyidistributed_fft.pydnfr.pydnfr.pyidynamic_limits.pyemergent_centralization.pyemergent_integration_engine.pyfeedback.pyfeedback.pyifft_backend.pyfft_cache_coordinator.pyfft_dispatchers.pyfft_engine.pyfft_workers.pyfused_dnfr.pyhomeostasis.pyhomeostasis.pyiintegrators.pyintegrators.pyilearning.pylearning.pyimetabolism.pymulti_modal_cache.pynbody_tnfr.pynbody.pynodal_optimizer.pyoptimization_orchestrator.pypropagation.pyREADME.mdruntime.pyruntime.pyisampling.pysampling.pyiselectors.pyselectors.pyiself_optimizing_engine.pyspectral_structural_fusion.pystructural_cache.pystructural_clip.pysymplectic.pyunified_backend.pyunified_mathematical_cache_orchestrator.py
engines
computation
__init__.pyfft_engine.pyunified_fft_engine.pyunified_gpu_system.py
constants
__init__.pycanonical.pyoperational.py
integration
__init__.pyemergent_integration.py
pattern_discovery
__init__.pymathematical_patterns.pymulti_modal_cache.py
self_optimization
__init__.pyengine.py
__init__.pyREADME.md
errors
__init__.pycontextual.py
factorization
__init__.py
flatten
README.md
gamma
README.md
glyph_history
README.md
glyph_runtime
README.md
immutable
README.md
initialization
README.md
io
README.md
math
__init__.pyfields_symbolic.pygrammar_validators.pyoptimizer.pyREADME.mdsymbolic.py
mathematics
__init__.pybackend.pybackend.pyidynamics.pydynamics.pyiepi.pyepi.pyigenerators.pygenerators.pyiliouville.pymetrics.pymetrics.pyinumber_theory.pyoperators_factory.pyoperators_factory.pyioperators.pyoperators.pyioptimized_primality.pyprojection.pyprojection.pyiREADME.mdruntime.pyruntime.pyispaces.pyspaces.pyispectral.pytransforms.pytransforms.pyiunified_cache.pyunified_numerical.pyzeta.py
metrics
__init__.py__init__.pyibuffer_cache.pybuffer_cache.pyicache_utils.pycoherence.pycoherence.pyicommon.pycommon.pyicore.pycore.pyidiagnosis.pydiagnosis.pyiemergence.pyexport.pyexport.pyiglyph_timing.pyglyph_timing.pyilearning_metrics.pylearning_metrics.pyilocal_coherence.pyphase_coherence.pyphase_compatibility.pyREADME.mdreporting.pyreporting.pyisense_index.pysense_index.pyitelemetry.pytetrad.pytrig_cache.pytrig_cache.pyitrig.pytrig.pyi
multiscale
__init__.pyhierarchical.pyREADME.md
navier_stokes
__init__.pyconservative_face.pyoperator.py
node
README.md
observers
README.md
operators
network_analysis
__init__.pysource_detection.py
postconditions
__init__.pymutation.py
preconditions
__init__.pycoherence.pydissonance.pyemission.pymutation.pyreception.pyresonance.py
strategies
__init__.pydefaults.pygpu_strategies.pystrategy.py
__init__.py__init__.pyialgebra.pycanonical_patterns.pycascade.pycoherence.pycontraction.pycoupling.pycycle_detection.pydefinitions_base.pydefinitions.pydefinitions.pyidissonance.pyemission.pyexpansion.pygrammar_application.pygrammar_canon.pygrammar_context.pygrammar_core.pygrammar_dynamics.pygrammar_error_factory.pygrammar_memoization.pygrammar_patterns.pygrammar_telemetry.pygrammar_types.pygrammar_u6.pygrammar_validate.pygrammar.pygrammar.pyihamiltonian.pyhealth_analyzer.pyintrospection.pyjitter.pyjitter.pyilifecycle.pymetabolism.pymetrics_basic.pymetrics_core.pymetrics_network.pymetrics_structural.pymetrics_u6.pymetrics.pymutation.pynodal_equation.pyoperator_contracts.pypattern_detection.pypatterns.pyREADME.mdreception.pyrecursivity.pyregistry.pyregistry.pyiremesh.pyremesh.pyiresonance.pyself_organization.pysilence.pystructural_units.pytransition.py
parallel
__init__.pyauto_scaler.pydistributed.pyengine.pymonitoring.pypartitioner.pyREADME.md
performance
guardrails.py
physics
__init__.py_helpers.pycalibration.pycanonical.pycell.pyclassical_mechanics.pyconservation_gauge_unification.pyconservation.pydissipative_conservation.pyemergent_chemistry.pyemergent_particles.pyextended.pyfields.pygauge.pyintegrity.pyinteractions.pylife.pylyapunov.pypatterns.pyphase_transition.pyquantum_mechanics.pyREADME.mdsignatures.pyspectral_conservation.pyspectral_metrics.pystructural_diffusion.pysymplectic_substrate.pytelemetry.pyunified.pyvariational.pyvectorized_ops.py
primality
__init__.py
recipes
__init__.pycookbook.pyREADME.md
riemann
__init__.pyadmissible_family_sweep.pyadmissible_rescaling.pyaggregates_closure_signature.pyalpha_sweep.pyanalytic_continuation_dirichlet.pyanalytic_continuation.pycoercivity_uniform.pycoupling_weights_type_signature.pycurrents_closure_signature.pydelta_phi_max_type_signature.pydirichlet_l.pydnfr_type_signature.pyepi_type_signature.pyhilbert_polya.pyli_keiper.pylyapunov_spectral_positivity.pynodal_pulse.pynodeaware_gauge_sweep.pynuf_type_signature.pyoperator_catalog_discipline_signature.pyoperator.pyoscillatory_correction.pypaley_gap_coercivity.pyphi_type_signature.pyprime_ladder_hamiltonian.pypulse_coherence.pyremesh_infinity_residue_split.pyremesh_window_type_signature.pyspectral_emergence.pystructural_zero_density.pytelemetry.pytetrad_closure_signature.pytwisted_admissible_family_sweep.pytwisted_admissible_rescaling.pytwisted_alpha_sweep.pytwisted_coercivity_uniform.pytwisted_hermite_family.pytwisted_hilbert_polya.pytwisted_li_keiper.pytwisted_lyapunov_spectral_positivity.pytwisted_nodeaware_gauge_sweep.pytwisted_oscillatory_correction.pytwisted_paley_gap_coercivity.pytwisted_prime_ladder_hamiltonian.pytwisted_spectral_emergence.pytwisted_structural_zero_density.pytwisted_weil_explicit_formula.pytwisted_weil_positivity.pyurules_consistency_signature.pyvon_mangoldt.pyweil_explicit_formula.pyweil_positivity.py
schemas
__init__.pygrammar.jsonREADME.md
sdk
__init__.py__init__.pyiadaptive_system.pyadaptive_system.pyibuilders.pybuilders.pyifluent.pyfluent.pyiREADME.mdself_opt.pysimple.pytemplates.pytemplates.pyiutils.py
security
__init__.pycrypto.pydatabase.pyREADME.mdsubprocess.pyvalidation.py
sequencing
__init__.pypatterns.pyREADME.md
services
__init__.pyorchestrator.pyREADME.md
sparse
__init__.pyREADME.mdrepresentations.py
structural
README.md
telemetry
__init__.pycache_metrics.pycache_metrics.pyiconstants.pynu_f.pynu_f.pyiREADME.mdunified_telemetry_system.pyverbosity.pyverbosity.pyi
tools
__init__.pydomain_templates.pyREADME.mdsequence_generator.pytnfr_is_prime_cli_optimized.pytnfr_is_prime_cli.py
topology
__init__.pyasymmetry.pyREADME.md
utils
cache_layers.pycache.pycache.pyicallbacks.pycallbacks.pyichunks.pychunks.pyidata.pydata.pyifast_diameter.pygraph.pygraph.pyiinit.pyinit.pyiio.pyio.pyinumeric.pynumeric.pyiREADME.mdtopology.pyunified_cache.py
validation
__init__.py__init__.pyiaggregator.pybase.pycompatibility.pycompatibility.pyiconfig.pygraph.pygraph.pyihealth.pyinput_validation.pyinterface_baselines.pyinvariants.pymultichannel_interface.pyphase_gate.pyREADME.mdrules.pyrules.pyiruntime.pyruntime.pyisequence_validator.pysignal_confrontation.pysoft_filters.pysoft_filters.pyispectral.pyspectral.pyistructural_interface.pytemporal_interface.pyunified_validation_system.pyvalidator.pywindow.pywindow.pyi
visualization
__init__.pycascade_viz.pyhierarchy.pyREADME.mdsequence_plotter.py
yang_mills
__init__.pyclosure.pyderivability.pyscaling.pystructural_gap.pyu6_sweep.py
__init__.py__init__.pyi_compat.py_version.py_version.pyialias.pyalias.pyibackend_config.pycache.pycache.pyiexecution.pyexecution.pyiflatten.pyflatten.pyigamma.pygamma.pyiglyph_history.pyglyph_history.pyiglyph_runtime.pyglyph_runtime.pyiimmutable.pyimmutable.pyiinitialization.pyinitialization.pyiio.pyio.pyilocking.pylocking.pyinode.pynode.pyiobservers.pyobservers.pyiontosim.pyontosim.pyipy.typedrng.pyrng.pyisecure_config.pyselector.pyselector.pyisense.pysense.pyistructural.pystructural.pyitokens.pytokens.pyitrace.pytrace.pyitypes.pytypes.pyiunits.pyunits.pyi
tetrad_evaluator.py
.pre-commit-config.yaml.semgrep.yaml.zenodo.jsonARCHITECTURE.mdbandit.yamlCHANGELOG.mdCITATION.cffCONTRIBUTING.mdEMERGENT_CANON_AUDIT.mdEMERGENT_DERIVATION_PLAN.mdLICENSE.mdMakefileMANIFEST.inpyproject.tomlpyrightconfig.jsonPYTORCH_CUDA_INTEGRATION.mdREADME.mdSECURITY.mdTESTING.mdTNFR_Website_Content_Brief.md
FILE: SECURITY.md

SECURITY.md

Security Policy

Supported Versions

We release patches for security vulnerabilities in the following versions:

VersionSupported
1.x.x:white_check_mark:
< 1.0:x:

Reporting a Vulnerability

The TNFR Python Engine team takes security vulnerabilities seriously. We appreciate your efforts to responsibly disclose your findings and will make every effort to acknowledge your contributions.

How to Report a Security Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, please report them via one of the following methods:

  1. GitHub Security Advisories: Use the Security Advisory feature (preferred)
  2. Email: Contact the maintainers directly (check repository for current contact)

Please include the following information in your report:

  • Type of vulnerability
  • Full paths of source file(s) related to the manifestation of the vulnerability
  • The location of the affected source code (tag/branch/commit or direct URL)
  • Step-by-step instructions to reproduce the vulnerability
  • Proof-of-concept or exploit code (if possible)
  • Impact of the vulnerability, including how an attacker might exploit it

Response Timeline

  • Initial Response: Within 48 hours of report submission
  • Status Update: Within 7 days with assessment and potential timeline
  • Resolution: Varies by severity; critical issues prioritized

Disclosure Policy

  • Security vulnerabilities will be coordinated with reporters before public disclosure
  • We aim to patch critical vulnerabilities within 30 days
  • Public disclosure will occur after patch is released and users have time to update

Security Best Practices for Users

SQL Injection Prevention

TNFR provides proactive SQL injection prevention utilities:

The TNFR engine currently uses in-memory NetworkX graphs and file-based persistence (JSON, YAML, Pickle). While no SQL databases are currently used, the codebase includes comprehensive SQL injection prevention utilities for future database functionality.

Security Utilities Available:

python
from tnfr.security import (
    SecureQueryBuilder,
    validate_identifier,
    sanitize_string_input,
    validate_nodal_input,
)

# Always use parameterized queries
builder = SecureQueryBuilder()
query, params = builder.select("nfr_nodes", ["id", "nu_f", "phase"])\
    .where("nu_f > ?", 0.5)\
    .order_by("nu_f", "DESC")\
    .build()

# Validate all identifiers (table/column names)
table_name = validate_identifier("nfr_nodes")
column_name = validate_identifier("nu_f")

# Sanitize string inputs
user_input = sanitize_string_input(user_provided_data, max_length=1000)

# Validate TNFR structural data before persistence
node_data = validate_nodal_input({
    "nu_f": 0.75,
    "phase": 1.57,
    "coherence": 0.85,
})

Security Principles:

  1. Parameterized Queries: Always use placeholders (?, :name) for values
  2. Identifier Validation: Validate table/column names against whitelist pattern
  3. No String Concatenation: Never build queries with f-strings or + operators
  4. Input Sanitization: Validate and sanitize all user inputs
  5. TNFR Structural Validation: Ensure structural frequency, phase, and coherence values are valid

Example of Safe vs Unsafe Patterns:

python
# ❌ UNSAFE: Never do this!
# query = f"SELECT * FROM nfr_nodes WHERE id = {user_input}"

# ✓ SAFE: Use parameterized queries
builder = SecureQueryBuilder()
query, params = builder.select("nfr_nodes")\
    .where("id = ?", user_input)\
    .build()
# Execute: cursor.execute(query, params)

Secret and Credential Management

TNFR follows strict security practices to prevent hardcoded secrets:

  1. No Hardcoded Secrets: All API keys, passwords, tokens, and credentials are loaded from environment variables
  2. Environment Variables: Use .env files for local development (never commit these!)
  3. Configuration Template: Copy .env.example to .env and fill in your credentials
  4. Secure Defaults: Development defaults are safe and non-functional placeholders

Environment Configuration:

bash
# Copy the example configuration
cp .env.example .env

# Edit .env with your actual credentials
# This file is gitignored and will not be committed

Using Configuration Utilities:

python
from tnfr.secure_config import (
    load_pypi_credentials,
    load_github_credentials,
    load_redis_config,
    get_cache_secret,
)

# Load credentials from environment
pypi_creds = load_pypi_credentials()
github_creds = load_github_credentials()
redis_config = load_redis_config()

# Get cache signing secret
cache_secret = get_cache_secret()

Security Best Practices:

  • Use API tokens instead of passwords (e.g., PyPI tokens, GitHub tokens)
  • Rotate credentials regularly
  • Use different credentials for development, staging, and production
  • Store production secrets in secure secret management systems (AWS Secrets Manager, HashiCorp Vault, etc.)
  • Grant minimal necessary permissions to all tokens
  • Revoke tokens immediately if compromised

Automated Security Testing:

TNFR includes automated tests that scan for hardcoded secrets:

  • GitHub token detection
  • PyPI token detection
  • Suspicious long strings that might be secrets
  • Verification of .env in .gitignore

Pickle Serialization Warning

The TNFR engine uses Python's pickle module for caching complex TNFR structures (NetworkX graphs, EPIs, coherence states). Pickle can execute arbitrary code during deserialization.

Important Security Considerations:

  1. ShelveCacheLayer: Only load shelf files from trusted sources
  2. RedisCacheLayer:
    • Use Redis authentication (AUTH command or ACL)
    • Implement network access controls
    • Use TLS for Redis connections
    • Never cache untrusted user input

Security Warnings:

Starting from version 1.x, TNFR will emit SecurityWarning when cache layers are created without signature validation. To suppress these warnings in trusted environments, set:

bash
export TNFR_ALLOW_UNSIGNED_PICKLE=1

Secure Cache Configuration (Recommended)

TNFR provides convenient helper functions to create secure cache layers with HMAC signature validation. This is the recommended approach for production deployments.

Quick Start with Secure Caches

python
from tnfr.utils import create_secure_shelve_layer, create_secure_redis_layer

# Set your cache secret via environment variable (recommended)
# export TNFR_CACHE_SECRET="your-secure-random-secret-key"

# Create secure cache layers (reads secret from environment)
shelf_layer = create_secure_shelve_layer("coherence.db")
redis_layer = create_secure_redis_layer()

# Store and retrieve TNFR structures safely
shelf_layer.store("nfr_state", {"epi": [1.5, 2.3], "theta": [0.1, 0.2]})
restored = shelf_layer.load("nfr_state")

Environment Variables

  • TNFR_CACHE_SECRET: Secret key for HMAC signature validation (required for secure layers)
  • TNFR_ALLOW_UNSIGNED_PICKLE: Set to 1 to suppress security warnings for unsigned pickle usage

Manual HMAC Configuration

For more control, you can use the HMAC helper functions:

python
from tnfr.utils import (
    create_hmac_signer,
    create_hmac_validator,
    ShelveCacheLayer,
    RedisCacheLayer,
)

# Create HMAC signer and validator
secret = b"your-secure-secret-key"
signer = create_hmac_signer(secret)
validator = create_hmac_validator(secret)

# Create cache layers with signature validation
shelf_layer = ShelveCacheLayer(
    "cache.db",
    signer=signer,
    validator=validator,
    require_signature=True,
)

redis_layer = RedisCacheLayer(
    namespace="tnfr:cache",
    signer=signer,
    validator=validator,
    require_signature=True,
)

Hardened Cache Signatures

ShelveCacheLayer and RedisCacheLayer support payload signing to detect tampering in environments where cache files or Redis instances are not fully trusted.

  • Configure a shared secret HMAC (or any signing/verification callable pair) using the signer and validator parameters.
  • Enable require_signature=True to activate hardened mode. In hardened mode the cache deletes unsigned or invalid entries and raises a :class:tnfr.utils.SecurityError.
  • New in 1.x: Warnings are emitted when creating cache layers without signatures. Use the secure helper functions for best practices.

Example with custom signing:

python
import hashlib
import hmac

from tnfr.utils import RedisCacheLayer, SecurityError, ShelveCacheLayer

SECRET = b"tnfr-shared-secret"

def signer(payload: bytes) -> bytes:
    return hmac.new(SECRET, payload, hashlib.sha256).digest()

def validator(payload: bytes, signature: bytes) -> bool:
    expected = hmac.new(SECRET, payload, hashlib.sha256).digest()
    return hmac.compare_digest(expected, signature)

shelf_layer = ShelveCacheLayer(
    "cache.db",
    signer=signer,
    validator=validator,
    require_signature=True,
)

redis_layer = RedisCacheLayer(
    namespace="tnfr:cache",
    signer=signer,
    validator=validator,
    require_signature=True,
)

try:
    shelf_layer.store("alpha", {"value": 1})
    data = shelf_layer.load("alpha")
except SecurityError:
    # Hardened mode rejected tampered payload
    ...

Tamper Detection:

When hardened mode is active, any tampered cache entry is automatically purged and causes an immediate SecurityError, preventing poisoned payloads from propagating through TNFR simulations.

Migration Guide

If you're using ShelveCacheLayer or RedisCacheLayer without signatures:

  1. For trusted, local-only caches (development):

    bash
    export TNFR_ALLOW_UNSIGNED_PICKLE=1
  2. For production deployments (recommended):

    python
    # Before
    layer = ShelveCacheLayer("cache.db")
    
    # After (secure)
    from tnfr.utils import create_secure_shelve_layer
    layer = create_secure_shelve_layer("cache.db")
  3. Set environment variable in production:

    bash
    export TNFR_CACHE_SECRET="$(openssl rand -hex 32)"

Dependency Management

All project dependencies are continuously monitored for security vulnerabilities using automated tools and processes.

pip-audit: Automated Dependency Vulnerability Scanning

What is pip-audit?

pip-audit is a tool that scans Python dependencies for known security vulnerabilities by checking them against the Python Packaging Advisory Database (PyPA).

Automated Scanning Schedule:

  • On every push to main/master branches
  • On every pull request to main/master branches
  • Weekly scheduled scan (every Monday at 5 AM UTC)

How to Run pip-audit Locally:

bash
# Install pip-audit
pip install pip-audit

# Install project dependencies
pip install -e .[all]

# Scan installed packages in your environment
pip-audit

# Or scan a specific site-packages directory
SITE_PACKAGES=$(python -c "import sysconfig; print(sysconfig.get_path('purelib'))")
pip-audit --path "$SITE_PACKAGES"

Understanding pip-audit Results:

When vulnerabilities are found, pip-audit reports:

  • Package name and version: The vulnerable dependency
  • Vulnerability ID: GHSA-, PYSEC-, or CVE identifier
  • Fix versions: The version(s) that resolve the vulnerability
  • Severity: Critical, High, Medium, or Low (when available)

Security Update Process:

When pip-audit detects vulnerabilities in the CI/CD pipeline:

  1. Automatic Detection: The pip-audit workflow runs and uploads a JSON report as an artifact
  2. Review: Maintainers review the pip-audit-report artifact from the workflow run
  3. Assessment: Evaluate if the vulnerability affects TNFR's use case:
    • Check if the vulnerable code path is actually used by TNFR
    • Assess the severity and exploitability in TNFR's context
    • Review available fixes and their compatibility
  4. Resolution Options:
    • Update dependency: Update to the fixed version in pyproject.toml
    • Pin to safe version: If latest version causes breaking changes, pin to nearest safe version
    • Document exception: If the vulnerability doesn't affect TNFR, document why in a security review
    • Find alternatives: Consider replacing the dependency if no safe version exists
  5. Testing: Run full test suite to ensure the update doesn't break functionality
  6. Document: Update changelog with security fix information

Example Workflow for Fixing a Vulnerability:

bash
# 1. Review the pip-audit report (download from GitHub Actions artifacts)
cat pip-audit.json

# 2. Update the vulnerable dependency in pyproject.toml
# For example, if networkx 2.6 is vulnerable and 3.0 fixes it:
# Change: "networkx>=2.6,<3.0"
# To:     "networkx>=3.0,<4.0"

# 3. Update your local environment
pip install -e .[all]

# 4. Run pip-audit again to verify the fix
pip-audit

# 5. Run the test suite
pytest

# 6. Commit and create a pull request
git add pyproject.toml
git commit -m "fix: update networkx to resolve GHSA-xxxx-xxxx-xxxx"
git push origin fix/update-networkx

Why pip-audit is NOT in pre-commit hooks:

While pip-audit is valuable for CI/CD, it is not included in pre-commit hooks because:

  • It requires network access to query the PyPA advisory database
  • It can be slow (5-30 seconds depending on network and number of packages)
  • It would slow down developer workflow for every commit
  • The automated CI/CD scanning catches issues before merge

Dependabot:

Automated Dependabot version updates (the .github/dependabot.yml configuration that opened dependabot/* branches) have been removed to avoid automated branch/PR noise. Dependabot security updates and alerts are disabled at the repository settings level. Dependency vulnerability coverage is provided by the pip-audit CI workflow described above, which scans installed packages against the PyPA advisory database on every push/PR to main, on a weekly schedule, and on manual dispatch.

Static Analysis

The repository relies on a single automated vulnerability scanner plus notification-only repository safeguards:

  • pip-audit: Dependency vulnerability scanner (CI workflow; never creates branches or pull requests)
  • Secret scanning + push protection: Enabled at the repository settings level (notification-only; prevents committing credentials)

The previous CodeQL and Bandit/Semgrep (SAST) CI workflows were removed to eliminate redundant automated scanning. bandit.yaml and tools/bandit_to_sarif.py remain available for optional manual local audits (bandit -r src -c bandit.yaml).

Security Features

TNFR Structural Integrity

TNFR maintains structural fidelity through canonical invariants that prevent:

  1. Uncontrolled mutations: EPI changes only through structural operators
  2. Non-deterministic behavior: Reproducible simulations with seed control
  3. Phase violations: Explicit phase verification for all couplings
  4. Frequency failures: Validation of structural frequency (νf) in Hz_str

These invariants ensure predictable, auditable behavior across all TNFR operations.

Domain Neutrality

The TNFR engine is domain-neutral by design, supporting:

  • Multiple backend choices (NumPy, JAX, PyTorch)
  • Configurable determinism for reproducibility
  • Transparent structural logging for audit trails

Known Security Considerations

Documented Pickle Usage

The following components use pickle serialization with documented security warnings:

  1. src/tnfr/utils/cache.py:

    • ShelveCacheLayer: Persistent file-based caching
    • RedisCacheLayer: Distributed Redis-based caching
  2. src/tnfr/dynamics/dnfr.py:

    • Pickle serialization check for parallel processing compatibility

All pickle usage includes:

  • Comprehensive security warnings in docstrings
  • Clear documentation of trust requirements
  • # nosec annotations where risk is accepted and documented

Excluded Security Checks

The following Bandit checks are intentionally excluded in bandit.yaml:

  • B610: Django QuerySet.extra - Not applicable (TNFR uses internal callables only)
  • B324: SHA1 usage - Non-cryptographic use (topology fingerprints for logging/caching)

Security Update Policy

  1. Critical vulnerabilities: Patched within 48-72 hours
  2. High severity: Patched within 1 week
  3. Medium/Low severity: Patched in next minor release
  4. Dependency updates: Reviewed and applied manually (surfaced by the pip-audit CI workflow)

Attribution

We believe in responsible disclosure and will credit security researchers who report vulnerabilities (unless they prefer to remain anonymous).

Questions?

If you have questions about this security policy, please open a GitHub Discussion or contact the maintainers.


Last Updated: November 2025 Policy Version: 1.0