TNFR Logo
TheoryLearnSoftwareResearch

On this page

TNFR

Resonant Fractal Nature Theory — a mathematical framework for coherent patterns on graph-coupled networks.

About
  • Project history
  • Editorial policy
  • Contact
Resources
  • GitHub
  • PyPI
  • DOI · Zenodo
Legal
  • MIT License
  • Citation
© 2026 TNFR project — MIT licensed.DOI 10.5281/zenodo.17602860
docs
grammar
PHYSICS_VERIFICATION.md
API_CONTRACTS.mdCANONICAL_OZ_SEQUENCES.mdEMPIRICAL_CONFRONTATION_EEG.mdREADME.mdSTRUCTURAL_FIELDS_TETRAD.mdSTRUCTURAL_INTERFACE_THEORY.md
theory
APPLIED_STRUCTURAL_ANALYSIS.mdCATALOG_TYPE_HYGIENE_PROGRAMME.mdDISSIPATIVE_AND_OPEN_SYSTEMS.mdEMERGENT_ONTOLOGY.mdEXTENDED_FIELDS_AND_DERIVED_QUANTITIES.mdFUNDAMENTAL_THEORY.mdGAUGE_SYMMETRY_AND_UNIFICATION.mdGLOSSARY.mdMATHEMATICAL_DYNAMICS_BASIS.mdMINIMAL_STRUCTURAL_DEGREES.mdNUCLEUS_A_PRIME_LADDER_ATLAS.mdNUCLEUS_B_EQUIVARIANCE_OBSTRUCTIONS.mdPHYSICAL_REGIME_CORRESPONDENCES.mdREADME.mdREMESH_INFINITY_DERIVATION.mdSTRUCTURAL_CONSERVATION_THEOREM.mdSTRUCTURAL_OPERATORS.mdSTRUCTURAL_STABILITY_AND_DYNAMICS.mdTNFR_BSD_RESEARCH_NOTES.mdTNFR_HODGE_RESEARCH_NOTES.mdTNFR_NAVIER_STOKES_RESEARCH_NOTES.mdTNFR_NUMBER_THEORY.mdTNFR_P_VS_NP_RESEARCH_NOTES.mdTNFR_RIEMANN_RESEARCH_NOTES.mdTNFR_VARIATIONAL_PRINCIPLE.mdTNFR_YANG_MILLS_RESEARCH_NOTES.mdTNFR.pdfUNIFIED_GRAMMAR_RULES.md
factorization-lab
analysis
analyze_patterns.pycertificate_manifest.py
benchmarks
benchmark_analysis.pybenchmark_expansion_suite.pyfull_spectrum_factorization.pypaley_gap_extended.pypaley_gap_smoke.pytest_benchmark_suite.py
demos
experiment_contexts
exp_0b1663cd19b7.jsonexp_0bf0054b7474.jsonexp_75a4c8ca616a.jsonexp_848ee0fd1857.jsonexp_f6fe00562193.jsonexp_fdf3da424e1e.json
failure_telemetry_batch.pyfeedback_integration_demo.pyintegration_demo_snapshots.dbseed_management_integration_demo.pysnapshot_integration_demo.pytrajectory_143.jsontrajectory_77.jsontrajectory_89.jsontrajectory_91.jsontrajectory_97.json
docs
FACTORING_PLAYBOOK.mdFALSE_POSITIVE_TEST_SUITE.mdOPERATOR_CERTIFICATES.mdROADMAP.mdSPECTRAL_ROUTE.md
experiment_contexts
exp_cebe1d9e7d8e.json
notebooks
spectral_history.ipynb
scripts
run_false_positive_tests.py
tests
run_false_positive_test_suite.pytest_cli.pytest_false_positive_methodology.pytest_false_positive_verifier.pytest_feedback_integration.pytest_partitioning.pytest_seed_management.pytest_self_opt_support.pytest_snapshot_system.pytest_spectral_paley.pytest_verification_robustness.py
tnfr_factorization
__init__.pyapi.pycli.pyfailure_telemetry.pyfeedback_adapter.pyfeedback_integration.pypartitioning.pyself_opt_support.pyspectral_paley.py
demo_snapshots.dbLICENSE_SNAPSHOT.mdPACKAGE_SUMMARY.mdREADME.mdseed_management.pysnapshot_system.pytest_certificate_hashing.pytest_installation.pyverification_trajectory_77.json
benchmarks
analyze_tetrad_universality.pyb0star_alpha_canonical_product_graphs.pybenchmark_optimization_tracks.pybenchmark_utils.pyboundary_vibration.pybridge_primes_riemann.pychiral_involution.pycli_utils.pycoherence_projector_sense_index.pycommutant_bridge.pycomposition_arithmetic.pyconfinement_zones_test.pyconservation_law_validation.pydirected_paley_bridge.pyemergent_arithmetic_pulse.pyemergent_atom_dynamics.pyemergent_atomic_shells.pyemergent_base_dimension.pyemergent_dimension_dynamics.pyemergent_fractal_pulse.pyemergent_fractal_simplex_dimension.pyemergent_integers_symmetry.pyemergent_musical_nfr.pyemergent_nfr_geometry.pyemergent_nfr_where.pyemergent_rationals.pyemergent_rhythm.pyemergent_screening.pyemergent_shell_cardinals.pyemergent_shell_ordering.pyemergent_simplex_dimension.pyemergent_substrate_symmetry.pyequivariance_wall.pyexternal_phase_gate_validation.pyfield_methods_battery.pygolden_residue_remesh_bridge.pyintegrated_force_regime_study.pyinverse_spectrum_to_symmetry.pyk_phi_safety_demo.pykuramoto_farey_bridge.pymissing_piece_bridge.pymultichannel_interface_benchmark.pynavier_stokes_recipe_bridge.pynodal_propagator_residue_bridge.pyns_moment_hierarchy_cascade.pyoperational_irreducibility.pypaley_bridge.pyphase_curvature_investigation.pyphase_wall.pyphi_s_confinement_investigation.pyprimes_as_consequence.pypulse_phase_coherence_budget.pyREADME.mdremesh_infinity_riemann_baseline.pyremesh_infinity_riemann_composed.pyremesh_infinity_riemann_modified_graph.pyremesh_infinity_riemann_operator.pyremesh_infinity_riemann_spectral_basis.pyremesh_infinity_riemann_spectral_robustness.pyremesh_infinity_riemann_spectral.pyresidue_phase_vs_riemann.pystructural_interface_benchmark.pytemporal_interface_benchmark.pytetrad_results_aggregate.pyu2_destabilization_irreversibility.pyuniversality_clusters.pyxi_c_fast_experiment.py
primality-test
benchmarks
comprehensive_benchmark.py
docs
ADVANCED_INTEGRATION.mdmathematical_foundation.mdperformance_analysis.md
examples
advanced_examples.pybasic_usage.py
tnfr_primality
__init__.py__main__.pyadvanced_cli.pyadvanced_core.pycli.pyconstants.pycore.pyoptimized.py
MANIFEST.inPACKAGE_SUMMARY.mdREADME.mdRELEASE_NOTES_v1.0.mdsetup.pytest_installation.py
tests
core_physics
__init__.pytest_conservation_laws.pytest_delta_nfr_computation_paths.pytest_delta_nfr.pytest_dispersion_coherence_sign_invariance.pytest_emergent_constants_guard.pytest_lyapunov_operators.pytest_nodal_equation.pytest_structural_triad.py
data
replay_manifests
sample_run
_manifest_summary.json_manifest.json_partition_files.txt.gz
self_opt_validation
seed_alpha
paley.json
seed_beta
integration.json
seed_gamma
unknown.json
self_optimization
test_run
partitioned
test_run
test_run_p0.jsontest_run_p1.json
_manifest_summary.json_manifest.json
engines
test_pattern_discovery_manifest.pytest_self_optimization_engine.py
mathematics
__init__.pytest_autodiff.pytest_backends.pytest_dissipative_dynamics.pytest_epi.pytest_factory_patterns.pytest_metrics.pytest_navier_stokes_refounded.pytest_number_theory_canonical.pytest_operators.pytest_residue_networks.pytest_riemann_nodal_pulse.pytest_riemann_pulse_coherence.pytest_spaces.pytest_transforms.pytest_validator.py
operators
test_canonical_operators_modern.pytest_grammar_canon.pytest_grammar_canonical_consistency.pytest_grammar_dynamics.pytest_operator_contracts.pytest_operator_strategies.py
parallel
test_fractal_partition_manifest.py
physics
test_conservation_gauge_unification.pytest_dissipative_conservation.pytest_emergent_chemistry.pytest_field_cache_invalidation.pytest_gauge.pytest_phase_transition.pytest_signatures.pytest_spectral_conservation.pytest_structural_diffusion.pytest_structural_integrity.pytest_symplectic_substrate.pytest_tetrad_bounds.pytest_variational.pytest_yang_mills_closure.pytest_yang_mills_derivability.pytest_yang_mills_scaling.pytest_yang_mills_structural_gap.pytest_yang_mills_u6_sweep.py
scripts
test_run_self_opt_validation.pytest_run_self_optimization.py
sdk
__init__.pytest_simple_advanced.py
__init__.pyconftest.pyREADME.mdtest_breast_cancer_phase_gate_demo.pytest_classical_mechanics.pytest_distributed_fft.pytest_external_phase_gate_validation.pytest_factorization_entrypoint.pytest_multichannel_interface.pytest_nodal_optimizer.pytest_phase_gate_api.pytest_replay_register_manifest.pytest_signal_confrontation.pytest_structural_interface_api.pytest_structural_interface_baselines.pytest_structural_interface_benchmark.pytest_temporal_interface.pytest_vectorized_coherence_length_regression.pytest_wine_quality_phase_gate_demo.pyutils.py
examples
01_foundations
01_hello_world.py02_musical_resonance.py03_network_formation.py04_operator_sequences.py05_coherence_evolution.py06_network_topologies.py07_phase_transitions.py08_emergent_phenomena.py09_visualization_suite.py10_simplified_sdk_showcase.py
02_physics_regimes
11_classical_limit_comparison.py115_operator_contract_audit.py12_classical_mechanics_demo.py13_quantum_mechanics_demo.py14_uncertainty_and_interference.py15_train_crossing_demo.py17_conservation_law_demo.py26_gauge_structure_demo.py27_variational_principle_demo.py28_dissipative_systems_demo.py29_lyapunov_stability_demo.py30_self_optimization_demo.py31_mathematical_constants_basis.py33_complex_field_unification.py34_conservation_protocol_suite.py35_tetrad_irreducibility.py36_grammar_violation_detector.py37_operator_tetrad_synergy.py38_grammar_energy_landscape.py39_nodal_equation_decomposition.py
03_riemann_zeta
157_nodal_pulse_phase_attack.py41_von_mangoldt_zeta_demo.py42_riemann_zeros_as_resonances.py43_prime_ladder_hamiltonian_demo.py44_weil_explicit_formula_demo.py45_li_keiper_demo.py46_weil_tnfr_positivity_demo.py47_alpha_sweep_demo.py48_admissible_family_sweep_demo.py49_nodeaware_gauge_sweep_demo.py50_uniform_coercivity_demo.py51_adaptive_coercivity_demo.py52_paley_gap_coercivity_demo.py53_lyapunov_spectral_positivity_demo.py54_hilbert_polya_demo.py55_structural_zero_density_demo.py56_spectral_emergence_demo.py57_admissible_rescaling_demo.py58_oscillatory_correction_demo.py
04_riemann_L_twisted
59_dirichlet_l_function_demo.py60_dirichlet_l_continuation_demo.py61_dirichlet_l_hamiltonian_demo.py62_dirichlet_weil_explicit_formula_demo.py63_dirichlet_li_keiper_demo.py64_twisted_weil_positivity_demo.py65_twisted_alpha_sweep_demo.py66_twisted_admissible_family_sweep_demo.py67_twisted_nodeaware_gauge_sweep_demo.py68_twisted_hermite_family_demo.py69_twisted_coercivity_uniform_demo.py70_twisted_paley_gap_coercivity_demo.py71_twisted_lyapunov_spectral_demo.py72_twisted_hilbert_polya_demo.py73_twisted_structural_zero_density_demo.py74_twisted_spectral_emergence_demo.py75_twisted_admissible_rescaling_demo.py76_twisted_oscillatory_correction_demo.py
05_type_hygiene
77_remesh_infinity_residue_split_demo.py78_nuf_type_signature_demo.py79_epi_type_signature_demo.py80_phi_type_signature_demo.py81_dnfr_type_signature_demo.py82_remesh_window_type_signature_demo.py83_delta_phi_max_type_signature_demo.py84_coupling_weights_type_signature_demo.py85_tetrad_closure_signature_demo.py86_currents_closure_signature_demo.py87_aggregates_closure_signature_demo.py88_urules_consistency_signature_demo.py89_operator_catalog_discipline_signature_demo.py
06_navier_stokes
158_navier_stokes_two_face_refounded.py
07_number_theory
100_prime_families_orbits.py101_numbers_as_coupled_network.py102_nodal_flow_primes_equilibria.py116_nuf_emergent_prime_visibility.py146_primality_grammatical_inertness.py147_numbers_as_free_monoid_words.py148_capacity_arm_carries_von_mangoldt.py149_p14_is_the_capacity_arm_operator.py153_structural_frequency_rank_cyclotomy.py40_arithmetic_number_theory.py94_generative_number_construction.py95_primes_from_spectral_waves.py96_spectral_vibration_of_coherence.py97_goldbach_additive_multiplicative.pyemergent_chemistry_particles_demo.py
08_emergent_geometry
103_emergent_substrate_meets_riemann.py106_per_node_polarization_geometry.py107_orthogonal_structure_emergent_geometry.py108_emergent_field_generating_structure.py112_structure_predicts_coherence_flow.py113_overdamped_projection_bridge.py114_substrate_conserved_quantities.py117_emergent_geometry_residue_graph.py118_emergent_vs_classical_operator.py119_phase_sector_directed_residue.py120_symmetry_wall_substrate_vs_spectrum.py121_canonical_symmetry_break_negative.py122_factorization_phase_sector.py123_symmetry_sector_decomposition.py124_emergent_metric_fractal_consistency.py125_node_is_the_emergent_substrate.py126_two_layers_base_fiber.py127_base_is_emergent_not_imposed.py128_base_substrate_coemergence.py129_spectral_gap_base_fiber_clock.py130_operators_break_substrate_charges.py131_coemergent_loop_convergence.py132_geometric_phase_holonomy.py133_psi_topological_defects.py134_spectral_dimension_heat_kernel.py135_arrow_of_time_h_theorem.py136_heat_kernel_coefficients.py137_synchronization_transition.py138_structure_frequency_synchronization.py139_grammar_formal_language.py140_grammar_automaton.py141_grammar_rule_decomposition.py142_grammar_operator_quotient.py143_glyphic_function_sublanguage.py144_branching_combinator.py145_syntactic_monoid_starfree.py150_emergent_grammatical_pattern_parry.py151_grammar_in_emergent_geometry.py152_operator_contract_tetrahedron.py154_conductor_annotated_qr_spectrum.py155_ontological_position_of_numbers.py156_emergence_directness_law.py98_emergent_symplectic_substrate.py99_structural_diffusion.pyunified_fields_showcase.py
09_millennium
109_p_vs_np_coherence_synthesis.py110_bsd_rank_structural_pressure.py111_hodge_discrete_and_honest_gap.py
10_applications
159_empirical_confrontation_pipeline.py90_phase_gate_monitor_demo.py91_breast_cancer_phase_gate_demo.py92_wine_quality_phase_gate_demo.py93_structural_interface_demo.pypytorch_cuda_demo.py
README.md
scripts
replay
__init__.pyregister_manifest.py
__init__.pyREADME.mdrebuild_failure_manifest.pyrun_reproducible_benchmarks.pyrun_self_opt_validation.pyrun_self_optimization.pytnfr_is_prime.pyvalidate_conservation_law.pyverify_internal_references.py
src
core
__init__.pyevaluation.py
tnfr
backends
__init__.pyjax_backend.pynumpy_backend.pyoptimized_numpy.pyREADME.mdtorch_backend.py
cli
__init__.py__init__.pyiarguments.pyarguments.pyiexecution.pyexecution.pyiinteractive_validator.pyREADME.mdutils.pyutils.pyi
compat
__init__.pydataclass.pyjsonschema_stub.pymatplotlib_stub.pynumpy_stub.pyREADME.md
config
__init__.py__init__.pyiconstants.pyconstants.pyidefaults_core.pydefaults_init.pydefaults_metric.pydefaults.pyfeature_flags.pyfeature_flags.pyiglyph_constants.pyoperator_names.pyoperator_names.pyiphysics_derivation.pyprecision_modes.pypresets.pypresets.pyiREADME.mdsecurity.pythresholds.pytnfr_config.py
constants
__init__.py__init__.pyialiases.pyaliases.pyicanonical.pymetric.pymetric.pyioperational.py
core
__init__.pycontainer.pydefault_implementations.pyexceptions.pyinterfaces.pyREADME.md
dynamics
__init__.py__init__.pyiadaptation.pyadaptation.pyiadaptive_sequences.pyadaptive_sequences.pyiadelic.pyadvanced_cache_optimizer.pyadvanced_fft_arithmetic.pyaliases.pyaliases.pyibifurcation.pycache_aware_fft_engine.pycanonical.pycanonical.pyicomputational_hub.pycoordination.pycoordination.pyidistributed_fft.pydnfr.pydnfr.pyidynamic_limits.pyemergent_centralization.pyemergent_integration_engine.pyfeedback.pyfeedback.pyifft_backend.pyfft_cache_coordinator.pyfft_dispatchers.pyfft_engine.pyfft_workers.pyfused_dnfr.pyhomeostasis.pyhomeostasis.pyiintegrators.pyintegrators.pyilearning.pylearning.pyimetabolism.pymulti_modal_cache.pynbody_tnfr.pynbody.pynodal_optimizer.pyoptimization_orchestrator.pypropagation.pyREADME.mdruntime.pyruntime.pyisampling.pysampling.pyiselectors.pyselectors.pyiself_optimizing_engine.pyspectral_structural_fusion.pystructural_cache.pystructural_clip.pysymplectic.pyunified_backend.pyunified_mathematical_cache_orchestrator.py
engines
computation
__init__.pyfft_engine.pyunified_fft_engine.pyunified_gpu_system.py
constants
__init__.pycanonical.pyoperational.py
integration
__init__.pyemergent_integration.py
pattern_discovery
__init__.pymathematical_patterns.pymulti_modal_cache.py
self_optimization
__init__.pyengine.py
__init__.pyREADME.md
errors
__init__.pycontextual.py
factorization
__init__.py
flatten
README.md
gamma
README.md
glyph_history
README.md
glyph_runtime
README.md
immutable
README.md
initialization
README.md
io
README.md
math
__init__.pyfields_symbolic.pygrammar_validators.pyoptimizer.pyREADME.mdsymbolic.py
mathematics
__init__.pybackend.pybackend.pyidynamics.pydynamics.pyiepi.pyepi.pyigenerators.pygenerators.pyiliouville.pymetrics.pymetrics.pyinumber_theory.pyoperators_factory.pyoperators_factory.pyioperators.pyoperators.pyioptimized_primality.pyprojection.pyprojection.pyiREADME.mdruntime.pyruntime.pyispaces.pyspaces.pyispectral.pytransforms.pytransforms.pyiunified_cache.pyunified_numerical.pyzeta.py
metrics
__init__.py__init__.pyibuffer_cache.pybuffer_cache.pyicache_utils.pycoherence.pycoherence.pyicommon.pycommon.pyicore.pycore.pyidiagnosis.pydiagnosis.pyiemergence.pyexport.pyexport.pyiglyph_timing.pyglyph_timing.pyilearning_metrics.pylearning_metrics.pyilocal_coherence.pyphase_coherence.pyphase_compatibility.pyREADME.mdreporting.pyreporting.pyisense_index.pysense_index.pyitelemetry.pytetrad.pytrig_cache.pytrig_cache.pyitrig.pytrig.pyi
multiscale
__init__.pyhierarchical.pyREADME.md
navier_stokes
__init__.pyconservative_face.pyoperator.py
node
README.md
observers
README.md
operators
network_analysis
__init__.pysource_detection.py
postconditions
__init__.pymutation.py
preconditions
__init__.pycoherence.pydissonance.pyemission.pymutation.pyreception.pyresonance.py
strategies
__init__.pydefaults.pygpu_strategies.pystrategy.py
__init__.py__init__.pyialgebra.pycanonical_patterns.pycascade.pycoherence.pycontraction.pycoupling.pycycle_detection.pydefinitions_base.pydefinitions.pydefinitions.pyidissonance.pyemission.pyexpansion.pygrammar_application.pygrammar_canon.pygrammar_context.pygrammar_core.pygrammar_dynamics.pygrammar_error_factory.pygrammar_memoization.pygrammar_patterns.pygrammar_telemetry.pygrammar_types.pygrammar_u6.pygrammar_validate.pygrammar.pygrammar.pyihamiltonian.pyhealth_analyzer.pyintrospection.pyjitter.pyjitter.pyilifecycle.pymetabolism.pymetrics_basic.pymetrics_core.pymetrics_network.pymetrics_structural.pymetrics_u6.pymetrics.pymutation.pynodal_equation.pyoperator_contracts.pypattern_detection.pypatterns.pyREADME.mdreception.pyrecursivity.pyregistry.pyregistry.pyiremesh.pyremesh.pyiresonance.pyself_organization.pysilence.pystructural_units.pytransition.py
parallel
__init__.pyauto_scaler.pydistributed.pyengine.pymonitoring.pypartitioner.pyREADME.md
performance
guardrails.py
physics
__init__.py_helpers.pycalibration.pycanonical.pycell.pyclassical_mechanics.pyconservation_gauge_unification.pyconservation.pydissipative_conservation.pyemergent_chemistry.pyemergent_particles.pyextended.pyfields.pygauge.pyintegrity.pyinteractions.pylife.pylyapunov.pypatterns.pyphase_transition.pyquantum_mechanics.pyREADME.mdsignatures.pyspectral_conservation.pyspectral_metrics.pystructural_diffusion.pysymplectic_substrate.pytelemetry.pyunified.pyvariational.pyvectorized_ops.py
primality
__init__.py
recipes
__init__.pycookbook.pyREADME.md
riemann
__init__.pyadmissible_family_sweep.pyadmissible_rescaling.pyaggregates_closure_signature.pyalpha_sweep.pyanalytic_continuation_dirichlet.pyanalytic_continuation.pycoercivity_uniform.pycoupling_weights_type_signature.pycurrents_closure_signature.pydelta_phi_max_type_signature.pydirichlet_l.pydnfr_type_signature.pyepi_type_signature.pyhilbert_polya.pyli_keiper.pylyapunov_spectral_positivity.pynodal_pulse.pynodeaware_gauge_sweep.pynuf_type_signature.pyoperator_catalog_discipline_signature.pyoperator.pyoscillatory_correction.pypaley_gap_coercivity.pyphi_type_signature.pyprime_ladder_hamiltonian.pypulse_coherence.pyremesh_infinity_residue_split.pyremesh_window_type_signature.pyspectral_emergence.pystructural_zero_density.pytelemetry.pytetrad_closure_signature.pytwisted_admissible_family_sweep.pytwisted_admissible_rescaling.pytwisted_alpha_sweep.pytwisted_coercivity_uniform.pytwisted_hermite_family.pytwisted_hilbert_polya.pytwisted_li_keiper.pytwisted_lyapunov_spectral_positivity.pytwisted_nodeaware_gauge_sweep.pytwisted_oscillatory_correction.pytwisted_paley_gap_coercivity.pytwisted_prime_ladder_hamiltonian.pytwisted_spectral_emergence.pytwisted_structural_zero_density.pytwisted_weil_explicit_formula.pytwisted_weil_positivity.pyurules_consistency_signature.pyvon_mangoldt.pyweil_explicit_formula.pyweil_positivity.py
schemas
__init__.pygrammar.jsonREADME.md
sdk
__init__.py__init__.pyiadaptive_system.pyadaptive_system.pyibuilders.pybuilders.pyifluent.pyfluent.pyiREADME.mdself_opt.pysimple.pytemplates.pytemplates.pyiutils.py
security
__init__.pycrypto.pydatabase.pyREADME.mdsubprocess.pyvalidation.py
sequencing
__init__.pypatterns.pyREADME.md
services
__init__.pyorchestrator.pyREADME.md
sparse
__init__.pyREADME.mdrepresentations.py
structural
README.md
telemetry
__init__.pycache_metrics.pycache_metrics.pyiconstants.pynu_f.pynu_f.pyiREADME.mdunified_telemetry_system.pyverbosity.pyverbosity.pyi
tools
__init__.pydomain_templates.pyREADME.mdsequence_generator.pytnfr_is_prime_cli_optimized.pytnfr_is_prime_cli.py
topology
__init__.pyasymmetry.pyREADME.md
utils
cache_layers.pycache.pycache.pyicallbacks.pycallbacks.pyichunks.pychunks.pyidata.pydata.pyifast_diameter.pygraph.pygraph.pyiinit.pyinit.pyiio.pyio.pyinumeric.pynumeric.pyiREADME.mdtopology.pyunified_cache.py
validation
__init__.py__init__.pyiaggregator.pybase.pycompatibility.pycompatibility.pyiconfig.pygraph.pygraph.pyihealth.pyinput_validation.pyinterface_baselines.pyinvariants.pymultichannel_interface.pyphase_gate.pyREADME.mdrules.pyrules.pyiruntime.pyruntime.pyisequence_validator.pysignal_confrontation.pysoft_filters.pysoft_filters.pyispectral.pyspectral.pyistructural_interface.pytemporal_interface.pyunified_validation_system.pyvalidator.pywindow.pywindow.pyi
visualization
__init__.pycascade_viz.pyhierarchy.pyREADME.mdsequence_plotter.py
yang_mills
__init__.pyclosure.pyderivability.pyscaling.pystructural_gap.pyu6_sweep.py
__init__.py__init__.pyi_compat.py_version.py_version.pyialias.pyalias.pyibackend_config.pycache.pycache.pyiexecution.pyexecution.pyiflatten.pyflatten.pyigamma.pygamma.pyiglyph_history.pyglyph_history.pyiglyph_runtime.pyglyph_runtime.pyiimmutable.pyimmutable.pyiinitialization.pyinitialization.pyiio.pyio.pyilocking.pylocking.pyinode.pynode.pyiobservers.pyobservers.pyiontosim.pyontosim.pyipy.typedrng.pyrng.pyisecure_config.pyselector.pyselector.pyisense.pysense.pyistructural.pystructural.pyitokens.pytokens.pyitrace.pytrace.pyitypes.pytypes.pyiunits.pyunits.pyi
tetrad_evaluator.py
.pre-commit-config.yaml.semgrep.yaml.zenodo.jsonARCHITECTURE.mdbandit.yamlCHANGELOG.mdCITATION.cffCONTRIBUTING.mdEMERGENT_CANON_AUDIT.mdEMERGENT_DERIVATION_PLAN.mdLICENSE.mdMakefileMANIFEST.inpyproject.tomlpyrightconfig.jsonPYTORCH_CUDA_INTEGRATION.mdREADME.mdSECURITY.mdTESTING.mdTNFR_Website_Content_Brief.md
FILE: src/tnfr/config/security.py

security.py

Secure configuration management for the TNFR engine.

This module provides utilities for loading configuration from environment variables with validation and secure defaults. It ensures that sensitive credentials are never hardcoded in source code.

Security Principles:

  • Never hardcode secrets, API keys, or passwords
  • Load sensitive values from environment variables
  • Provide secure defaults for development
  • Validate configuration before use
  • Support multiple configuration sources (environment, .env files)
  • Sanitize credentials in logs to prevent exposure
  • Secure memory management for secrets
  • Credential rotation and TTL support

Source Code

python
"""Secure configuration management for the TNFR engine.

This module provides utilities for loading configuration from environment
variables with validation and secure defaults. It ensures that sensitive
credentials are never hardcoded in source code.

Security Principles:
- Never hardcode secrets, API keys, or passwords
- Load sensitive values from environment variables
- Provide secure defaults for development
- Validate configuration before use
- Support multiple configuration sources (environment, .env files)
- Sanitize credentials in logs to prevent exposure
- Secure memory management for secrets
- Credential rotation and TTL support
"""

from __future__ import annotations

import os
import secrets
import time
import warnings
from datetime import datetime, timedelta, timezone
from typing import Any, Callable
from urllib.parse import urlparse, urlunparse


class ConfigurationError(Exception):
    """Raised when configuration is invalid or missing required values."""


class SecurityAuditWarning(UserWarning):
    """Warning for security audit findings that don't stop execution."""


def get_env_variable(
    name: str,
    default: str | None = None,
    required: bool = False,
    secret: bool = False,
) -> str | None:
    """Get an environment variable with validation.

    Parameters
    ----------
    name : str
        The name of the environment variable to retrieve.
    default : str, optional
        Default value if the environment variable is not set.
    required : bool, default=False
        If True, raise ConfigurationError if the variable is not set.
    secret : bool, default=False
        If True, this is a sensitive value (password, token, etc.).
        Warnings will be issued if using defaults for secrets.

    Returns
    -------
    str or None
        The value of the environment variable, or the default value.

    Raises
    ------
    ConfigurationError
        If required=True and the variable is not set.

    Examples
    --------
    >>> # Get optional configuration with default
    >>> log_level = get_env_variable("TNFR_LOG_LEVEL", default="INFO")

    >>> # Get required secret (will raise if not set)
    >>> api_token = get_env_variable(
    ...     "GITHUB_TOKEN",
    ...     required=True,
    ...     secret=True
    ... )

    >>> # Get optional secret (will warn if using default)
    >>> redis_password = get_env_variable(
    ...     "REDIS_PASSWORD",
    ...     default="",
    ...     secret=True
    ... )
    """
    value = os.environ.get(name)

    if value is None:
        if required:
            raise ConfigurationError(
                f"Required environment variable '{name}' is not set. "
                f"Please set it in your environment or .env file."
            )
        if secret and default is not None:
            warnings.warn(
                f"Using default value for secret '{name}'. "
                f"set the environment variable for production use.",
                stacklevel=2,
            )
        return default

    return value


def load_pypi_credentials() -> dict[str, str | None]:
    """Load PyPI publishing credentials from environment.

    Returns
    -------
    dict
        Dictionary containing username, password, and repository settings.

    Notes
    -----
    This function reads from multiple environment variables to support
    different tools (twine, poetry, etc.):

    - PYPI_USERNAME or TWINE_USERNAME
    - PYPI_PASSWORD, PYPI_API_TOKEN, or TWINE_PASSWORD
    - PYPI_REPOSITORY (defaults to 'pypi')

    Best Practice
    -------------
    Use API tokens instead of passwords:
    - PYPI_USERNAME=__token__
    - PYPI_PASSWORD=pypi-XXXXXXXXXXXXXXXXXXXX...

    Note: Example uses 'XXX' pattern to avoid triggering security scanners.
    Actual PyPI tokens follow format: pypi-AgEIcHlwaS5vcmcC...

    See Also
    --------
    https://pypi.org/help/#apitoken : PyPI API token documentation
    """
    username = os.environ.get("PYPI_USERNAME") or os.environ.get("TWINE_USERNAME")
    password = (
        os.environ.get("PYPI_PASSWORD")
        or os.environ.get("PYPI_API_TOKEN")
        or os.environ.get("TWINE_PASSWORD")
    )
    repository = os.environ.get("PYPI_REPOSITORY", "pypi")

    return {
        "username": username,
        "password": password,
        "repository": repository,
    }


def load_github_credentials() -> dict[str, str | None]:
    """Load GitHub API credentials from environment.

    Returns
    -------
    dict
        Dictionary containing token and repository information.

    Notes
    -----
    This function reads GITHUB_TOKEN and GITHUB_REPOSITORY environment
    variables commonly set in GitHub Actions and other CI environments.

    Best Practice
    -------------
    Use fine-grained personal access tokens with minimal scopes:
    - For security scans: read:security_events
    - For releases: contents:write, packages:write

    See Also
    --------
    https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/creating-a-personal-access-token
    """
    token = os.environ.get("GITHUB_TOKEN")
    repository = os.environ.get("GITHUB_REPOSITORY")

    return {
        "token": token,
        "repository": repository,
    }


def load_redis_config(validate_url: bool = True) -> dict[str, Any]:
    """Load Redis connection configuration from environment.

    Parameters
    ----------
    validate_url : bool, default=True
        Whether to validate the constructed Redis URL.

    Returns
    -------
    dict
        Dictionary containing Redis connection parameters.

    Notes
    -----
    Supports standard Redis configuration variables:

    - REDIS_HOST (default: 'localhost')
    - REDIS_PORT (default: 6379)
    - REDIS_PASSWORD (optional)
    - REDIS_DB (default: 0)
    - REDIS_USE_TLS (default: False)
    - REDIS_URL (alternative: full URL, overrides individual params)

    Security
    --------
    Always use authentication (REDIS_PASSWORD) in production.
    Enable TLS (REDIS_USE_TLS=true) for network connections.
    URLs with credentials are validated and sanitized for logging.

    See Also
    --------
    tnfr.utils.RedisCacheLayer : Redis cache implementation
    SecureCredentialValidator : URL validation and sanitization
    """
    # Check if full URL is provided
    redis_url = get_env_variable("REDIS_URL", default=None)

    if redis_url:
        # Validate URL if requested
        if validate_url:
            SecureCredentialValidator.validate_redis_url(redis_url)

        # Parse URL to extract components
        parsed = urlparse(redis_url)

        return {
            "host": parsed.hostname or "localhost",
            "port": parsed.port or 6379,
            "password": parsed.password,
            "db": int(parsed.path.lstrip("/") or "0") if parsed.path else 0,
            "ssl": parsed.scheme == "rediss",
            "url": redis_url,
        }

    # Load from individual variables
    host = get_env_variable("REDIS_HOST", default="localhost")
    port_str = get_env_variable("REDIS_PORT", default="6379")
    password = get_env_variable("REDIS_PASSWORD", default=None, secret=True)
    db_str = get_env_variable("REDIS_DB", default="0")
    use_tls_str = get_env_variable("REDIS_USE_TLS", default="false")

    try:
        port = int(port_str)
    except ValueError:
        raise ConfigurationError(f"REDIS_PORT must be an integer, got: {port_str}")

    # Validate port range
    if not (1 <= port <= 65535):
        raise ConfigurationError(f"REDIS_PORT must be between 1 and 65535, got: {port}")

    try:
        db = int(db_str)
    except ValueError:
        raise ConfigurationError(f"REDIS_DB must be an integer, got: {db_str}")

    use_tls = use_tls_str.lower() in ("true", "1", "yes", "on")

    # Construct URL for validation
    if validate_url:
        scheme = "rediss" if use_tls else "redis"
        if password:
            url = f"{scheme}://:{password}@{host}:{port}/{db}"
        else:
            url = f"{scheme}://{host}:{port}/{db}"
        SecureCredentialValidator.validate_redis_url(url)

    return {
        "host": host,
        "port": port,
        "password": password,
        "db": db,
        "ssl": use_tls,
    }


def get_cache_secret() -> bytes | None:
    """Get the cache signing secret from environment.

    Returns
    -------
    bytes or None
        The cache secret as bytes, or None if not configured.

    Notes
    -----
    Reads from TNFR_CACHE_SECRET environment variable. The secret should
    be a hex-encoded string (recommended length: 64 characters / 32 bytes).

    Security
    --------
    Use a cryptographically strong random secret:

    >>> import secrets
    >>> secret = secrets.token_hex(32)  # 64-character hex string
    >>> # set TNFR_CACHE_SECRET=<secret> in your environment

    See Also
    --------
    tnfr.utils.ShelveCacheLayer : Shelf cache with signature support
    tnfr.utils.RedisCacheLayer : Redis cache with signature support
    """
    secret_hex = get_env_variable("TNFR_CACHE_SECRET", secret=True)
    if secret_hex is None:
        return None

    try:
        return bytes.fromhex(secret_hex)
    except ValueError as exc:
        raise ConfigurationError(
            f"TNFR_CACHE_SECRET must be a hex-encoded string: {exc}"
        )


def validate_no_hardcoded_secrets(value: str) -> bool:
    """Validate that a string doesn't look like a hardcoded secret.

    Parameters
    ----------
    value : str
        The string to validate.

    Returns
    -------
    bool
        True if the value passes validation.

    Raises
    ------
    ValueError
        If the value appears to be a hardcoded secret.

    Notes
    -----
    This is a heuristic check for common secret patterns:

    - Long alphanumeric strings (potential tokens)
    - Known secret prefixes (ghp_, pypi-, sk-, etc.)
    - Base64-encoded strings

    For production environments, consider using more sophisticated
    tools like `detect-secrets` which employ entropy analysis for
    better accuracy.

    Examples
    --------
    >>> validate_no_hardcoded_secrets("my-password")
    True

    >>> validate_no_hardcoded_secrets("ghp_abcd1234...")
    Traceback (most recent call last):
        ...
    ValueError: Value appears to be a hardcoded GitHub token
    """
    # Check for known secret prefixes
    secret_prefixes = [
        ("ghp_", "GitHub token"),
        ("gho_", "GitHub OAuth token"),
        ("ghu_", "GitHub user token"),
        ("ghs_", "GitHub server token"),
        ("ghr_", "GitHub refresh token"),
        ("pypi-", "PyPI token"),
        ("sk-", "OpenAI API key"),
        ("xoxb-", "Slack bot token"),
        ("xoxp-", "Slack user token"),
    ]

    for prefix, name in secret_prefixes:
        if value.startswith(prefix):
            raise ValueError(f"Value appears to be a hardcoded {name}")

    # Check for suspiciously long alphanumeric strings
    # Note: This is a simple heuristic. For production use, consider
    # entropy-based analysis (e.g., using detect-secrets library)
    if len(value) > 32 and value.replace("-", "").replace("_", "").isalnum():
        # Allow environment variable names (typically uppercase)
        if not value.isupper():
            warnings.warn(
                f"Value looks like it might be a hardcoded secret: {value[:10]}...",
                stacklevel=2,
            )

    return True


class SecureCredentialValidator:
    """Robust credential and configuration validator.

    Validates credentials and configuration with strict security criteria
    following TNFR principles of structural coherence and stability.
    """

    ALLOWED_SCHEMES = frozenset(["redis", "rediss"])  # Only secure schemes
    MAX_URL_LENGTH = 512  # Prevent DoS attacks
    MIN_SECRET_LENGTH = 8  # Minimum secret strength

    @staticmethod
    def validate_redis_url(url: str) -> bool:
        """Validate Redis URL with strict security criteria.

        Parameters
        ----------
        url : str
            Redis URL to validate.

        Returns
        -------
        bool
            True if URL is valid.

        Raises
        ------
        ValueError
            If URL fails validation checks.

        Examples
        --------
        >>> SecureCredentialValidator.validate_redis_url("redis://localhost:6379/0")
        True

        >>> SecureCredentialValidator.validate_redis_url("http://evil.com")
        Traceback (most recent call last):
            ...
        ValueError: Unsupported scheme: http
        """
        if not url or not isinstance(url, str):
            raise ValueError("Redis URL must be a non-empty string")

        if len(url) > SecureCredentialValidator.MAX_URL_LENGTH:
            raise ValueError(
                f"Redis URL exceeds maximum length of {SecureCredentialValidator.MAX_URL_LENGTH}"
            )

        try:
            parsed = urlparse(url)
        except Exception as exc:
            raise ValueError(f"Invalid URL format: {exc}")

        if parsed.scheme not in SecureCredentialValidator.ALLOWED_SCHEMES:
            raise ValueError(
                f"Unsupported scheme: {parsed.scheme}. "
                f"Allowed: {', '.join(SecureCredentialValidator.ALLOWED_SCHEMES)}"
            )

        if not parsed.hostname:
            raise ValueError("Redis URL must include a hostname")

        # Validate port if specified
        if parsed.port is not None:
            if not (1 <= parsed.port <= 65535):
                raise ValueError(f"Invalid port number: {parsed.port}")

        return True

    @staticmethod
    def sanitize_for_logging(url: str) -> str:
        """Sanitize URL for safe logging (hide credentials).

        Parameters
        ----------
        url : str
            URL that may contain credentials.

        Returns
        -------
        str
            Sanitized URL with credentials masked.

        Examples
        --------
        >>> SecureCredentialValidator.sanitize_for_logging(
        ...     "redis://user:secret@host:6379/0"
        ... )
        'redis://user:***@host:6379/0'
        """
        if not url:
            return url

        try:
            parsed = urlparse(url)

            # Check if parsing actually succeeded
            if not parsed.scheme and not parsed.netloc:
                # This is not a valid URL
                return "<invalid-url>"
        except Exception:
            # If parsing fails, return a safe placeholder
            return "<invalid-url>"

        # Mask password if present
        if parsed.password:
            # Replace password with ***
            netloc = parsed.netloc
            if "@" in netloc:
                userinfo, hostinfo = netloc.rsplit("@", 1)
                if ":" in userinfo:
                    username, _ = userinfo.split(":", 1)
                    netloc = f"{username}:***@{hostinfo}"
                else:
                    netloc = f"***@{hostinfo}"

            sanitized = parsed._replace(netloc=netloc)
            return urlunparse(sanitized)

        return url

    @staticmethod
    def validate_secret_strength(secret: str | bytes, min_length: int = 8) -> bool:
        """Validate that a secret meets minimum strength requirements.

        Parameters
        ----------
        secret : str or bytes
            The secret to validate.
        min_length : int, default=8
            Minimum required length.

        Returns
        -------
        bool
            True if secret is strong enough.

        Raises
        ------
        ValueError
            If secret is too weak.
        """
        if isinstance(secret, bytes):
            length = len(secret)
            secret_str = secret.decode("utf-8", errors="ignore")
        else:
            length = len(secret)
            secret_str = secret

        # Check for common weak passwords first (before length check)
        # This provides more specific error messages
        weak_passwords = ["password", "123456", "admin", "secret", "test", "changeme"]
        if secret_str.lower() in weak_passwords:
            raise ValueError("Secret matches a known weak password")

        # Then check length
        if length < min_length:
            raise ValueError(f"Secret too short: {length} < {min_length} (minimum)")

        return True


class SecureSecretManager:
    """Secure secret management with automatic memory cleanup.

    Manages secrets in memory with secure cleanup to prevent exposure
    through memory dumps. Implements structural coherence principles
    by ensuring secrets maintain integrity throughout their lifecycle.
    """

    def __init__(self) -> None:
        """Initialize secure secret manager."""
        self._secrets: dict[str, bytearray] = {}
        self._access_log: list[tuple[str, float]] = []

    def store_secret(self, key: str, secret: bytes | str) -> None:
        """Store a secret securely.

        Parameters
        ----------
        key : str
            Identifier for the secret.
        secret : bytes or str
            The secret value to store.
        """
        if isinstance(secret, str):
            secret_bytes = secret.encode("utf-8")
        else:
            secret_bytes = secret

        # Store as mutable bytearray for secure clearing
        self._secrets[key] = bytearray(secret_bytes)

    def get_secret(self, key: str) -> bytes:
        """Get a secret with access tracking.

        Parameters
        ----------
        key : str
            Secret identifier.

        Returns
        -------
        bytes
            Copy of the secret (not direct reference).
        """
        self._access_log.append((key, time.time()))
        secret_array = self._secrets.get(key)
        if secret_array is None:
            return b""
        # Return copy to prevent external mutation
        return bytes(secret_array)

    def clear_secret(self, key: str) -> None:
        """Clear a secret from memory securely.

        Parameters
        ----------
        key : str
            Secret identifier to clear.
        """
        if key in self._secrets:
            # Overwrite with random bytes before deletion
            secret_array = self._secrets[key]
            for i in range(len(secret_array)):
                secret_array[i] = secrets.randbits(8) & 0xFF
            del self._secrets[key]

    def clear_all(self) -> None:
        """Clear all secrets from memory."""
        for key in list(self._secrets.keys()):
            self.clear_secret(key)

    def get_access_log(self) -> list[tuple[str, float]]:
        """Get access log for auditing.

        Returns
        -------
        list of tuples
            list of (key, timestamp) tuples.
        """
        return self._access_log.copy()

    def __del__(self) -> None:
        """Cleanup on destruction."""
        self.clear_all()


class CredentialRotationManager:
    """Manages credential rotation with TTL support.

    Implements structural reorganization principle by managing
    credential lifecycle and triggering rotation when coherence
    (validity period) decreases.
    """

    def __init__(
        self,
        rotation_interval: timedelta = timedelta(hours=24),
        warning_threshold: timedelta = timedelta(hours=2),
    ) -> None:
        """Initialize rotation manager.

        Parameters
        ----------
        rotation_interval : timedelta, default=24 hours
            How often credentials should be rotated.
        warning_threshold : timedelta, default=2 hours
            When to warn about upcoming expiration.
        """
        self.rotation_interval = rotation_interval
        self.warning_threshold = warning_threshold
        self._last_rotation: dict[str, datetime] = {}
        self._rotation_callbacks: dict[str, Callable[[], None]] = {}

    def register_credential(
        self,
        credential_key: str,
        rotation_callback: Callable[[], None] | None = None,
    ) -> None:
        """Register a credential for rotation tracking.

        Parameters
        ----------
        credential_key : str
            Identifier for the credential.
        rotation_callback : callable, optional
            Function to call when rotation is needed.
        """
        self._last_rotation[credential_key] = datetime.now(timezone.utc)
        if rotation_callback is not None:
            self._rotation_callbacks[credential_key] = rotation_callback

    def needs_rotation(self, credential_key: str) -> bool:
        """Check if credential needs rotation.

        Parameters
        ----------
        credential_key : str
            Credential identifier.

        Returns
        -------
        bool
            True if rotation is needed.
        """
        last = self._last_rotation.get(credential_key)
        if last is None:
            return True
        age = datetime.now(timezone.utc) - last
        return age >= self.rotation_interval

    def needs_warning(self, credential_key: str) -> bool:
        """Check if credential is nearing expiration.

        Parameters
        ----------
        credential_key : str
            Credential identifier.

        Returns
        -------
        bool
            True if warning should be issued.
        """
        last = self._last_rotation.get(credential_key)
        if last is None:
            return True
        age = datetime.now(timezone.utc) - last
        time_until_rotation = self.rotation_interval - age
        return time_until_rotation <= self.warning_threshold

    def rotate_if_needed(self, credential_key: str) -> bool:
        """Rotate credential if needed.

        Parameters
        ----------
        credential_key : str
            Credential identifier.

        Returns
        -------
        bool
            True if rotation was performed.
        """
        if self.needs_rotation(credential_key):
            callback = self._rotation_callbacks.get(credential_key)
            if callback is not None:
                callback()
            self._last_rotation[credential_key] = datetime.now(timezone.utc)
            return True
        return False

    def get_credential_age(self, credential_key: str) -> timedelta | None:
        """Get age of credential.

        Parameters
        ----------
        credential_key : str
            Credential identifier.

        Returns
        -------
        timedelta or None
            Age of credential, or None if not registered.
        """
        last = self._last_rotation.get(credential_key)
        if last is None:
            return None
        return datetime.now(timezone.utc) - last


class SecurityAuditor:
    """Security auditor for configuration and environment.

    Implements diagnostic nodal analysis to identify security
    coherence issues and dissonances in configuration.
    """

    SENSITIVE_PATTERNS = frozenset(
        [
            "password",
            "secret",
            "key",
            "token",
            "credential",
            "api_key",
            "apikey",
            "auth",
            "private",
        ]
    )

    WEAK_VALUES = frozenset(
        [
            "password",
            "123456",
            "admin",
            "secret",
            "test",
            "changeme",
            "default",
            "root",
            "toor",
        ]
    )

    def audit_environment_variables(self) -> list[str]:
        """Audit environment variables for security issues.

        Returns
        -------
        list of str
            list of security issues found.
        """
        issues = []

        for var_name in os.environ:
            var_name_lower = var_name.lower()
            var_value = os.environ[var_name]

            # Check if this is a sensitive variable
            is_sensitive = any(
                pattern in var_name_lower for pattern in self.SENSITIVE_PATTERNS
            )

            if is_sensitive:
                # Check for weak values
                if var_value.lower() in self.WEAK_VALUES:
                    issues.append(
                        f"Weak/default value in sensitive variable: {var_name}"
                    )

                # Check for too short secrets
                if len(var_value) < 8:
                    issues.append(
                        f"Secret too short ({len(var_value)} chars) in: {var_name}"
                    )

                # Check if secret looks like a placeholder
                if var_value in ["your-secret", "your-token", "changeme", "..."]:
                    issues.append(f"Placeholder value detected in: {var_name}")

        return issues

    def check_redis_config_security(self) -> list[str]:
        """Check Redis configuration for security issues.

        Returns
        -------
        list of str
            list of security issues found.
        """
        issues = []

        # Check if password is set
        redis_password = os.environ.get("REDIS_PASSWORD")
        if not redis_password:
            issues.append("REDIS_PASSWORD not set - authentication disabled")

        # Check if TLS is enabled
        redis_use_tls = os.environ.get("REDIS_USE_TLS", "false").lower()
        if redis_use_tls not in ("true", "1", "yes", "on"):
            issues.append("REDIS_USE_TLS not enabled - unencrypted connection")

        return issues

    def check_cache_secret_security(self) -> list[str]:
        """Check cache secret configuration.

        Returns
        -------
        list of str
            list of security issues found.
        """
        issues = []

        cache_secret = os.environ.get("TNFR_CACHE_SECRET")
        if not cache_secret:
            issues.append("TNFR_CACHE_SECRET not set - unsigned cache data")
        else:
            # Check if secret is strong enough
            try:
                secret_bytes = bytes.fromhex(cache_secret)
                if len(secret_bytes) < 16:
                    issues.append(
                        f"TNFR_CACHE_SECRET too short: {len(secret_bytes)} bytes "
                        "(recommend 32+ bytes)"
                    )
            except ValueError:
                issues.append("TNFR_CACHE_SECRET is not valid hex")

        return issues

    def run_full_audit(self) -> dict[str, list[str]]:
        """Run complete security audit.

        Returns
        -------
        dict
            Dictionary mapping audit category to list of issues.
        """
        return {
            "environment_variables": self.audit_environment_variables(),
            "redis_config": self.check_redis_config_security(),
            "cache_secret": self.check_cache_secret_security(),
        }


# Global instances for convenience
_global_secret_manager: SecureSecretManager | None = None
_global_rotation_manager: CredentialRotationManager | None = None


def get_secret_manager() -> SecureSecretManager:
    """Get global secret manager instance.

    Returns
    -------
    SecureSecretManager
        Global secret manager instance.
    """
    global _global_secret_manager
    if _global_secret_manager is None:
        _global_secret_manager = SecureSecretManager()
    return _global_secret_manager


def get_rotation_manager() -> CredentialRotationManager:
    """Get global rotation manager instance.

    Returns
    -------
    CredentialRotationManager
        Global rotation manager instance.
    """
    global _global_rotation_manager
    if _global_rotation_manager is None:
        _global_rotation_manager = CredentialRotationManager()
    return _global_rotation_manager