TNFR Logo
TheoryLearnSoftwareResearch

On this page

TNFR

Resonant Fractal Nature Theory — a mathematical framework for coherent patterns on graph-coupled networks.

About
  • Project history
  • Editorial policy
  • Contact
Resources
  • GitHub
  • PyPI
  • DOI · Zenodo
Legal
  • MIT License
  • Citation
© 2026 TNFR project — MIT licensed.DOI 10.5281/zenodo.17602860
docs
grammar
PHYSICS_VERIFICATION.md
API_CONTRACTS.mdCANONICAL_OZ_SEQUENCES.mdEMPIRICAL_CONFRONTATION_EEG.mdREADME.mdSTRUCTURAL_FIELDS_TETRAD.mdSTRUCTURAL_INTERFACE_THEORY.md
theory
APPLIED_STRUCTURAL_ANALYSIS.mdCATALOG_TYPE_HYGIENE_PROGRAMME.mdDISSIPATIVE_AND_OPEN_SYSTEMS.mdEMERGENT_ONTOLOGY.mdEXTENDED_FIELDS_AND_DERIVED_QUANTITIES.mdFUNDAMENTAL_THEORY.mdGAUGE_SYMMETRY_AND_UNIFICATION.mdGLOSSARY.mdMATHEMATICAL_DYNAMICS_BASIS.mdMINIMAL_STRUCTURAL_DEGREES.mdNUCLEUS_A_PRIME_LADDER_ATLAS.mdNUCLEUS_B_EQUIVARIANCE_OBSTRUCTIONS.mdPHYSICAL_REGIME_CORRESPONDENCES.mdREADME.mdREMESH_INFINITY_DERIVATION.mdSTRUCTURAL_CONSERVATION_THEOREM.mdSTRUCTURAL_OPERATORS.mdSTRUCTURAL_STABILITY_AND_DYNAMICS.mdTNFR_BSD_RESEARCH_NOTES.mdTNFR_HODGE_RESEARCH_NOTES.mdTNFR_NAVIER_STOKES_RESEARCH_NOTES.mdTNFR_NUMBER_THEORY.mdTNFR_P_VS_NP_RESEARCH_NOTES.mdTNFR_RIEMANN_RESEARCH_NOTES.mdTNFR_VARIATIONAL_PRINCIPLE.mdTNFR_YANG_MILLS_RESEARCH_NOTES.mdTNFR.pdfUNIFIED_GRAMMAR_RULES.md
factorization-lab
analysis
analyze_patterns.pycertificate_manifest.py
benchmarks
benchmark_analysis.pybenchmark_expansion_suite.pyfull_spectrum_factorization.pypaley_gap_extended.pypaley_gap_smoke.pytest_benchmark_suite.py
demos
experiment_contexts
exp_0b1663cd19b7.jsonexp_0bf0054b7474.jsonexp_75a4c8ca616a.jsonexp_848ee0fd1857.jsonexp_f6fe00562193.jsonexp_fdf3da424e1e.json
failure_telemetry_batch.pyfeedback_integration_demo.pyintegration_demo_snapshots.dbseed_management_integration_demo.pysnapshot_integration_demo.pytrajectory_143.jsontrajectory_77.jsontrajectory_89.jsontrajectory_91.jsontrajectory_97.json
docs
FACTORING_PLAYBOOK.mdFALSE_POSITIVE_TEST_SUITE.mdOPERATOR_CERTIFICATES.mdROADMAP.mdSPECTRAL_ROUTE.md
experiment_contexts
exp_cebe1d9e7d8e.json
notebooks
spectral_history.ipynb
scripts
run_false_positive_tests.py
tests
run_false_positive_test_suite.pytest_cli.pytest_false_positive_methodology.pytest_false_positive_verifier.pytest_feedback_integration.pytest_partitioning.pytest_seed_management.pytest_self_opt_support.pytest_snapshot_system.pytest_spectral_paley.pytest_verification_robustness.py
tnfr_factorization
__init__.pyapi.pycli.pyfailure_telemetry.pyfeedback_adapter.pyfeedback_integration.pypartitioning.pyself_opt_support.pyspectral_paley.py
demo_snapshots.dbLICENSE_SNAPSHOT.mdPACKAGE_SUMMARY.mdREADME.mdseed_management.pysnapshot_system.pytest_certificate_hashing.pytest_installation.pyverification_trajectory_77.json
benchmarks
analyze_tetrad_universality.pyb0star_alpha_canonical_product_graphs.pybenchmark_optimization_tracks.pybenchmark_utils.pyboundary_vibration.pybridge_primes_riemann.pychiral_involution.pycli_utils.pycoherence_projector_sense_index.pycommutant_bridge.pycomposition_arithmetic.pyconfinement_zones_test.pyconservation_law_validation.pydirected_paley_bridge.pyemergent_arithmetic_pulse.pyemergent_atom_dynamics.pyemergent_atomic_shells.pyemergent_base_dimension.pyemergent_dimension_dynamics.pyemergent_fractal_pulse.pyemergent_fractal_simplex_dimension.pyemergent_integers_symmetry.pyemergent_musical_nfr.pyemergent_nfr_geometry.pyemergent_nfr_where.pyemergent_rationals.pyemergent_rhythm.pyemergent_screening.pyemergent_shell_cardinals.pyemergent_shell_ordering.pyemergent_simplex_dimension.pyemergent_substrate_symmetry.pyequivariance_wall.pyexternal_phase_gate_validation.pyfield_methods_battery.pygolden_residue_remesh_bridge.pyintegrated_force_regime_study.pyinverse_spectrum_to_symmetry.pyk_phi_safety_demo.pykuramoto_farey_bridge.pymissing_piece_bridge.pymultichannel_interface_benchmark.pynavier_stokes_recipe_bridge.pynodal_propagator_residue_bridge.pyns_moment_hierarchy_cascade.pyoperational_irreducibility.pypaley_bridge.pyphase_curvature_investigation.pyphase_wall.pyphi_s_confinement_investigation.pyprimes_as_consequence.pypulse_phase_coherence_budget.pyREADME.mdremesh_infinity_riemann_baseline.pyremesh_infinity_riemann_composed.pyremesh_infinity_riemann_modified_graph.pyremesh_infinity_riemann_operator.pyremesh_infinity_riemann_spectral_basis.pyremesh_infinity_riemann_spectral_robustness.pyremesh_infinity_riemann_spectral.pyresidue_phase_vs_riemann.pystructural_interface_benchmark.pytemporal_interface_benchmark.pytetrad_results_aggregate.pyu2_destabilization_irreversibility.pyuniversality_clusters.pyxi_c_fast_experiment.py
primality-test
benchmarks
comprehensive_benchmark.py
docs
ADVANCED_INTEGRATION.mdmathematical_foundation.mdperformance_analysis.md
examples
advanced_examples.pybasic_usage.py
tnfr_primality
__init__.py__main__.pyadvanced_cli.pyadvanced_core.pycli.pyconstants.pycore.pyoptimized.py
MANIFEST.inPACKAGE_SUMMARY.mdREADME.mdRELEASE_NOTES_v1.0.mdsetup.pytest_installation.py
tests
core_physics
__init__.pytest_conservation_laws.pytest_delta_nfr_computation_paths.pytest_delta_nfr.pytest_dispersion_coherence_sign_invariance.pytest_emergent_constants_guard.pytest_lyapunov_operators.pytest_nodal_equation.pytest_structural_triad.py
data
replay_manifests
sample_run
_manifest_summary.json_manifest.json_partition_files.txt.gz
self_opt_validation
seed_alpha
paley.json
seed_beta
integration.json
seed_gamma
unknown.json
self_optimization
test_run
partitioned
test_run
test_run_p0.jsontest_run_p1.json
_manifest_summary.json_manifest.json
engines
test_pattern_discovery_manifest.pytest_self_optimization_engine.py
mathematics
__init__.pytest_autodiff.pytest_backends.pytest_dissipative_dynamics.pytest_epi.pytest_factory_patterns.pytest_metrics.pytest_navier_stokes_refounded.pytest_number_theory_canonical.pytest_operators.pytest_residue_networks.pytest_riemann_nodal_pulse.pytest_riemann_pulse_coherence.pytest_spaces.pytest_transforms.pytest_validator.py
operators
test_canonical_operators_modern.pytest_grammar_canon.pytest_grammar_canonical_consistency.pytest_grammar_dynamics.pytest_operator_contracts.pytest_operator_strategies.py
parallel
test_fractal_partition_manifest.py
physics
test_conservation_gauge_unification.pytest_dissipative_conservation.pytest_emergent_chemistry.pytest_field_cache_invalidation.pytest_gauge.pytest_phase_transition.pytest_signatures.pytest_spectral_conservation.pytest_structural_diffusion.pytest_structural_integrity.pytest_symplectic_substrate.pytest_tetrad_bounds.pytest_variational.pytest_yang_mills_closure.pytest_yang_mills_derivability.pytest_yang_mills_scaling.pytest_yang_mills_structural_gap.pytest_yang_mills_u6_sweep.py
scripts
test_run_self_opt_validation.pytest_run_self_optimization.py
sdk
__init__.pytest_simple_advanced.py
__init__.pyconftest.pyREADME.mdtest_breast_cancer_phase_gate_demo.pytest_classical_mechanics.pytest_distributed_fft.pytest_external_phase_gate_validation.pytest_factorization_entrypoint.pytest_multichannel_interface.pytest_nodal_optimizer.pytest_phase_gate_api.pytest_replay_register_manifest.pytest_signal_confrontation.pytest_structural_interface_api.pytest_structural_interface_baselines.pytest_structural_interface_benchmark.pytest_temporal_interface.pytest_vectorized_coherence_length_regression.pytest_wine_quality_phase_gate_demo.pyutils.py
examples
01_foundations
01_hello_world.py02_musical_resonance.py03_network_formation.py04_operator_sequences.py05_coherence_evolution.py06_network_topologies.py07_phase_transitions.py08_emergent_phenomena.py09_visualization_suite.py10_simplified_sdk_showcase.py
02_physics_regimes
11_classical_limit_comparison.py115_operator_contract_audit.py12_classical_mechanics_demo.py13_quantum_mechanics_demo.py14_uncertainty_and_interference.py15_train_crossing_demo.py17_conservation_law_demo.py26_gauge_structure_demo.py27_variational_principle_demo.py28_dissipative_systems_demo.py29_lyapunov_stability_demo.py30_self_optimization_demo.py31_mathematical_constants_basis.py33_complex_field_unification.py34_conservation_protocol_suite.py35_tetrad_irreducibility.py36_grammar_violation_detector.py37_operator_tetrad_synergy.py38_grammar_energy_landscape.py39_nodal_equation_decomposition.py
03_riemann_zeta
157_nodal_pulse_phase_attack.py41_von_mangoldt_zeta_demo.py42_riemann_zeros_as_resonances.py43_prime_ladder_hamiltonian_demo.py44_weil_explicit_formula_demo.py45_li_keiper_demo.py46_weil_tnfr_positivity_demo.py47_alpha_sweep_demo.py48_admissible_family_sweep_demo.py49_nodeaware_gauge_sweep_demo.py50_uniform_coercivity_demo.py51_adaptive_coercivity_demo.py52_paley_gap_coercivity_demo.py53_lyapunov_spectral_positivity_demo.py54_hilbert_polya_demo.py55_structural_zero_density_demo.py56_spectral_emergence_demo.py57_admissible_rescaling_demo.py58_oscillatory_correction_demo.py
04_riemann_L_twisted
59_dirichlet_l_function_demo.py60_dirichlet_l_continuation_demo.py61_dirichlet_l_hamiltonian_demo.py62_dirichlet_weil_explicit_formula_demo.py63_dirichlet_li_keiper_demo.py64_twisted_weil_positivity_demo.py65_twisted_alpha_sweep_demo.py66_twisted_admissible_family_sweep_demo.py67_twisted_nodeaware_gauge_sweep_demo.py68_twisted_hermite_family_demo.py69_twisted_coercivity_uniform_demo.py70_twisted_paley_gap_coercivity_demo.py71_twisted_lyapunov_spectral_demo.py72_twisted_hilbert_polya_demo.py73_twisted_structural_zero_density_demo.py74_twisted_spectral_emergence_demo.py75_twisted_admissible_rescaling_demo.py76_twisted_oscillatory_correction_demo.py
05_type_hygiene
77_remesh_infinity_residue_split_demo.py78_nuf_type_signature_demo.py79_epi_type_signature_demo.py80_phi_type_signature_demo.py81_dnfr_type_signature_demo.py82_remesh_window_type_signature_demo.py83_delta_phi_max_type_signature_demo.py84_coupling_weights_type_signature_demo.py85_tetrad_closure_signature_demo.py86_currents_closure_signature_demo.py87_aggregates_closure_signature_demo.py88_urules_consistency_signature_demo.py89_operator_catalog_discipline_signature_demo.py
06_navier_stokes
158_navier_stokes_two_face_refounded.py
07_number_theory
100_prime_families_orbits.py101_numbers_as_coupled_network.py102_nodal_flow_primes_equilibria.py116_nuf_emergent_prime_visibility.py146_primality_grammatical_inertness.py147_numbers_as_free_monoid_words.py148_capacity_arm_carries_von_mangoldt.py149_p14_is_the_capacity_arm_operator.py153_structural_frequency_rank_cyclotomy.py40_arithmetic_number_theory.py94_generative_number_construction.py95_primes_from_spectral_waves.py96_spectral_vibration_of_coherence.py97_goldbach_additive_multiplicative.pyemergent_chemistry_particles_demo.py
08_emergent_geometry
103_emergent_substrate_meets_riemann.py106_per_node_polarization_geometry.py107_orthogonal_structure_emergent_geometry.py108_emergent_field_generating_structure.py112_structure_predicts_coherence_flow.py113_overdamped_projection_bridge.py114_substrate_conserved_quantities.py117_emergent_geometry_residue_graph.py118_emergent_vs_classical_operator.py119_phase_sector_directed_residue.py120_symmetry_wall_substrate_vs_spectrum.py121_canonical_symmetry_break_negative.py122_factorization_phase_sector.py123_symmetry_sector_decomposition.py124_emergent_metric_fractal_consistency.py125_node_is_the_emergent_substrate.py126_two_layers_base_fiber.py127_base_is_emergent_not_imposed.py128_base_substrate_coemergence.py129_spectral_gap_base_fiber_clock.py130_operators_break_substrate_charges.py131_coemergent_loop_convergence.py132_geometric_phase_holonomy.py133_psi_topological_defects.py134_spectral_dimension_heat_kernel.py135_arrow_of_time_h_theorem.py136_heat_kernel_coefficients.py137_synchronization_transition.py138_structure_frequency_synchronization.py139_grammar_formal_language.py140_grammar_automaton.py141_grammar_rule_decomposition.py142_grammar_operator_quotient.py143_glyphic_function_sublanguage.py144_branching_combinator.py145_syntactic_monoid_starfree.py150_emergent_grammatical_pattern_parry.py151_grammar_in_emergent_geometry.py152_operator_contract_tetrahedron.py154_conductor_annotated_qr_spectrum.py155_ontological_position_of_numbers.py156_emergence_directness_law.py98_emergent_symplectic_substrate.py99_structural_diffusion.pyunified_fields_showcase.py
09_millennium
109_p_vs_np_coherence_synthesis.py110_bsd_rank_structural_pressure.py111_hodge_discrete_and_honest_gap.py
10_applications
159_empirical_confrontation_pipeline.py90_phase_gate_monitor_demo.py91_breast_cancer_phase_gate_demo.py92_wine_quality_phase_gate_demo.py93_structural_interface_demo.pypytorch_cuda_demo.py
README.md
scripts
replay
__init__.pyregister_manifest.py
__init__.pyREADME.mdrebuild_failure_manifest.pyrun_reproducible_benchmarks.pyrun_self_opt_validation.pyrun_self_optimization.pytnfr_is_prime.pyvalidate_conservation_law.pyverify_internal_references.py
src
core
__init__.pyevaluation.py
tnfr
backends
__init__.pyjax_backend.pynumpy_backend.pyoptimized_numpy.pyREADME.mdtorch_backend.py
cli
__init__.py__init__.pyiarguments.pyarguments.pyiexecution.pyexecution.pyiinteractive_validator.pyREADME.mdutils.pyutils.pyi
compat
__init__.pydataclass.pyjsonschema_stub.pymatplotlib_stub.pynumpy_stub.pyREADME.md
config
__init__.py__init__.pyiconstants.pyconstants.pyidefaults_core.pydefaults_init.pydefaults_metric.pydefaults.pyfeature_flags.pyfeature_flags.pyiglyph_constants.pyoperator_names.pyoperator_names.pyiphysics_derivation.pyprecision_modes.pypresets.pypresets.pyiREADME.mdsecurity.pythresholds.pytnfr_config.py
constants
__init__.py__init__.pyialiases.pyaliases.pyicanonical.pymetric.pymetric.pyioperational.py
core
__init__.pycontainer.pydefault_implementations.pyexceptions.pyinterfaces.pyREADME.md
dynamics
__init__.py__init__.pyiadaptation.pyadaptation.pyiadaptive_sequences.pyadaptive_sequences.pyiadelic.pyadvanced_cache_optimizer.pyadvanced_fft_arithmetic.pyaliases.pyaliases.pyibifurcation.pycache_aware_fft_engine.pycanonical.pycanonical.pyicomputational_hub.pycoordination.pycoordination.pyidistributed_fft.pydnfr.pydnfr.pyidynamic_limits.pyemergent_centralization.pyemergent_integration_engine.pyfeedback.pyfeedback.pyifft_backend.pyfft_cache_coordinator.pyfft_dispatchers.pyfft_engine.pyfft_workers.pyfused_dnfr.pyhomeostasis.pyhomeostasis.pyiintegrators.pyintegrators.pyilearning.pylearning.pyimetabolism.pymulti_modal_cache.pynbody_tnfr.pynbody.pynodal_optimizer.pyoptimization_orchestrator.pypropagation.pyREADME.mdruntime.pyruntime.pyisampling.pysampling.pyiselectors.pyselectors.pyiself_optimizing_engine.pyspectral_structural_fusion.pystructural_cache.pystructural_clip.pysymplectic.pyunified_backend.pyunified_mathematical_cache_orchestrator.py
engines
computation
__init__.pyfft_engine.pyunified_fft_engine.pyunified_gpu_system.py
constants
__init__.pycanonical.pyoperational.py
integration
__init__.pyemergent_integration.py
pattern_discovery
__init__.pymathematical_patterns.pymulti_modal_cache.py
self_optimization
__init__.pyengine.py
__init__.pyREADME.md
errors
__init__.pycontextual.py
factorization
__init__.py
flatten
README.md
gamma
README.md
glyph_history
README.md
glyph_runtime
README.md
immutable
README.md
initialization
README.md
io
README.md
math
__init__.pyfields_symbolic.pygrammar_validators.pyoptimizer.pyREADME.mdsymbolic.py
mathematics
__init__.pybackend.pybackend.pyidynamics.pydynamics.pyiepi.pyepi.pyigenerators.pygenerators.pyiliouville.pymetrics.pymetrics.pyinumber_theory.pyoperators_factory.pyoperators_factory.pyioperators.pyoperators.pyioptimized_primality.pyprojection.pyprojection.pyiREADME.mdruntime.pyruntime.pyispaces.pyspaces.pyispectral.pytransforms.pytransforms.pyiunified_cache.pyunified_numerical.pyzeta.py
metrics
__init__.py__init__.pyibuffer_cache.pybuffer_cache.pyicache_utils.pycoherence.pycoherence.pyicommon.pycommon.pyicore.pycore.pyidiagnosis.pydiagnosis.pyiemergence.pyexport.pyexport.pyiglyph_timing.pyglyph_timing.pyilearning_metrics.pylearning_metrics.pyilocal_coherence.pyphase_coherence.pyphase_compatibility.pyREADME.mdreporting.pyreporting.pyisense_index.pysense_index.pyitelemetry.pytetrad.pytrig_cache.pytrig_cache.pyitrig.pytrig.pyi
multiscale
__init__.pyhierarchical.pyREADME.md
navier_stokes
__init__.pyconservative_face.pyoperator.py
node
README.md
observers
README.md
operators
network_analysis
__init__.pysource_detection.py
postconditions
__init__.pymutation.py
preconditions
__init__.pycoherence.pydissonance.pyemission.pymutation.pyreception.pyresonance.py
strategies
__init__.pydefaults.pygpu_strategies.pystrategy.py
__init__.py__init__.pyialgebra.pycanonical_patterns.pycascade.pycoherence.pycontraction.pycoupling.pycycle_detection.pydefinitions_base.pydefinitions.pydefinitions.pyidissonance.pyemission.pyexpansion.pygrammar_application.pygrammar_canon.pygrammar_context.pygrammar_core.pygrammar_dynamics.pygrammar_error_factory.pygrammar_memoization.pygrammar_patterns.pygrammar_telemetry.pygrammar_types.pygrammar_u6.pygrammar_validate.pygrammar.pygrammar.pyihamiltonian.pyhealth_analyzer.pyintrospection.pyjitter.pyjitter.pyilifecycle.pymetabolism.pymetrics_basic.pymetrics_core.pymetrics_network.pymetrics_structural.pymetrics_u6.pymetrics.pymutation.pynodal_equation.pyoperator_contracts.pypattern_detection.pypatterns.pyREADME.mdreception.pyrecursivity.pyregistry.pyregistry.pyiremesh.pyremesh.pyiresonance.pyself_organization.pysilence.pystructural_units.pytransition.py
parallel
__init__.pyauto_scaler.pydistributed.pyengine.pymonitoring.pypartitioner.pyREADME.md
performance
guardrails.py
physics
__init__.py_helpers.pycalibration.pycanonical.pycell.pyclassical_mechanics.pyconservation_gauge_unification.pyconservation.pydissipative_conservation.pyemergent_chemistry.pyemergent_particles.pyextended.pyfields.pygauge.pyintegrity.pyinteractions.pylife.pylyapunov.pypatterns.pyphase_transition.pyquantum_mechanics.pyREADME.mdsignatures.pyspectral_conservation.pyspectral_metrics.pystructural_diffusion.pysymplectic_substrate.pytelemetry.pyunified.pyvariational.pyvectorized_ops.py
primality
__init__.py
recipes
__init__.pycookbook.pyREADME.md
riemann
__init__.pyadmissible_family_sweep.pyadmissible_rescaling.pyaggregates_closure_signature.pyalpha_sweep.pyanalytic_continuation_dirichlet.pyanalytic_continuation.pycoercivity_uniform.pycoupling_weights_type_signature.pycurrents_closure_signature.pydelta_phi_max_type_signature.pydirichlet_l.pydnfr_type_signature.pyepi_type_signature.pyhilbert_polya.pyli_keiper.pylyapunov_spectral_positivity.pynodal_pulse.pynodeaware_gauge_sweep.pynuf_type_signature.pyoperator_catalog_discipline_signature.pyoperator.pyoscillatory_correction.pypaley_gap_coercivity.pyphi_type_signature.pyprime_ladder_hamiltonian.pypulse_coherence.pyremesh_infinity_residue_split.pyremesh_window_type_signature.pyspectral_emergence.pystructural_zero_density.pytelemetry.pytetrad_closure_signature.pytwisted_admissible_family_sweep.pytwisted_admissible_rescaling.pytwisted_alpha_sweep.pytwisted_coercivity_uniform.pytwisted_hermite_family.pytwisted_hilbert_polya.pytwisted_li_keiper.pytwisted_lyapunov_spectral_positivity.pytwisted_nodeaware_gauge_sweep.pytwisted_oscillatory_correction.pytwisted_paley_gap_coercivity.pytwisted_prime_ladder_hamiltonian.pytwisted_spectral_emergence.pytwisted_structural_zero_density.pytwisted_weil_explicit_formula.pytwisted_weil_positivity.pyurules_consistency_signature.pyvon_mangoldt.pyweil_explicit_formula.pyweil_positivity.py
schemas
__init__.pygrammar.jsonREADME.md
sdk
__init__.py__init__.pyiadaptive_system.pyadaptive_system.pyibuilders.pybuilders.pyifluent.pyfluent.pyiREADME.mdself_opt.pysimple.pytemplates.pytemplates.pyiutils.py
security
__init__.pycrypto.pydatabase.pyREADME.mdsubprocess.pyvalidation.py
sequencing
__init__.pypatterns.pyREADME.md
services
__init__.pyorchestrator.pyREADME.md
sparse
__init__.pyREADME.mdrepresentations.py
structural
README.md
telemetry
__init__.pycache_metrics.pycache_metrics.pyiconstants.pynu_f.pynu_f.pyiREADME.mdunified_telemetry_system.pyverbosity.pyverbosity.pyi
tools
__init__.pydomain_templates.pyREADME.mdsequence_generator.pytnfr_is_prime_cli_optimized.pytnfr_is_prime_cli.py
topology
__init__.pyasymmetry.pyREADME.md
utils
cache_layers.pycache.pycache.pyicallbacks.pycallbacks.pyichunks.pychunks.pyidata.pydata.pyifast_diameter.pygraph.pygraph.pyiinit.pyinit.pyiio.pyio.pyinumeric.pynumeric.pyiREADME.mdtopology.pyunified_cache.py
validation
__init__.py__init__.pyiaggregator.pybase.pycompatibility.pycompatibility.pyiconfig.pygraph.pygraph.pyihealth.pyinput_validation.pyinterface_baselines.pyinvariants.pymultichannel_interface.pyphase_gate.pyREADME.mdrules.pyrules.pyiruntime.pyruntime.pyisequence_validator.pysignal_confrontation.pysoft_filters.pysoft_filters.pyispectral.pyspectral.pyistructural_interface.pytemporal_interface.pyunified_validation_system.pyvalidator.pywindow.pywindow.pyi
visualization
__init__.pycascade_viz.pyhierarchy.pyREADME.mdsequence_plotter.py
yang_mills
__init__.pyclosure.pyderivability.pyscaling.pystructural_gap.pyu6_sweep.py
__init__.py__init__.pyi_compat.py_version.py_version.pyialias.pyalias.pyibackend_config.pycache.pycache.pyiexecution.pyexecution.pyiflatten.pyflatten.pyigamma.pygamma.pyiglyph_history.pyglyph_history.pyiglyph_runtime.pyglyph_runtime.pyiimmutable.pyimmutable.pyiinitialization.pyinitialization.pyiio.pyio.pyilocking.pylocking.pyinode.pynode.pyiobservers.pyobservers.pyiontosim.pyontosim.pyipy.typedrng.pyrng.pyisecure_config.pyselector.pyselector.pyisense.pysense.pyistructural.pystructural.pyitokens.pytokens.pyitrace.pytrace.pyitypes.pytypes.pyiunits.pyunits.pyi
tetrad_evaluator.py
.pre-commit-config.yaml.semgrep.yaml.zenodo.jsonARCHITECTURE.mdbandit.yamlCHANGELOG.mdCITATION.cffCONTRIBUTING.mdEMERGENT_CANON_AUDIT.mdEMERGENT_DERIVATION_PLAN.mdLICENSE.mdMakefileMANIFEST.inpyproject.tomlpyrightconfig.jsonPYTORCH_CUDA_INTEGRATION.mdREADME.mdSECURITY.mdTESTING.mdTNFR_Website_Content_Brief.md
FILE: src/tnfr/security/subprocess.py

subprocess.py

Command execution security utilities for TNFR.

This module provides secure wrappers for subprocess execution and input validation to prevent command injection attacks while maintaining TNFR structural coherence.

TNFR Context

These utilities ensure that external process execution maintains the integrity of the TNFR computational environment without introducing security vulnerabilities. They act as a coherence boundary between user input and system command execution.

Source Code

python
"""Command execution security utilities for TNFR.

This module provides secure wrappers for subprocess execution and input validation
to prevent command injection attacks while maintaining TNFR structural coherence.

TNFR Context
------------
These utilities ensure that external process execution maintains the integrity of
the TNFR computational environment without introducing security vulnerabilities.
They act as a coherence boundary between user input and system command execution.
"""

from __future__ import annotations

import re
import subprocess
from pathlib import Path
from typing import Any, Sequence

from ..errors import TNFRValueError

__all__ = [
    "validate_git_ref",
    "validate_path_safe",
    "validate_file_path",
    "resolve_safe_path",
    "validate_version_string",
    "run_command_safely",
    "CommandValidationError",
    "PathTraversalError",
]


class CommandValidationError(TNFRValueError):
    """Raised when command input validation fails."""


class PathTraversalError(TNFRValueError):
    """Raised when path traversal attempt is detected."""


# Allowlisted commands that are safe to execute
ALLOWED_COMMANDS = frozenset(
    {
        "git",
        "python",
        "python3",
        "stubgen",
        "gh",
        "pip",
        "twine",
    }
)

# Pattern for valid git refs (branches, tags, commit SHAs)
GIT_REF_PATTERN = re.compile(r"^[a-zA-Z0-9/_\-\.]+$")

# Pattern for semantic version strings
VERSION_PATTERN = re.compile(r"^v?(\d+)\.(\d+)\.(\d+)(-[a-zA-Z0-9\-\.]+)?$")

# Pattern for safe path components (no path traversal)
SAFE_PATH_PATTERN = re.compile(r"^[a-zA-Z0-9/_\-\.]+$")


def validate_git_ref(ref: str) -> str:
    """Validate a git reference (branch, tag, or SHA).

    Parameters
    ----------
    ref : str
        The git reference to validate.

    Returns
    -------
    str
        The validated reference.

    Raises
    ------
    CommandValidationError
        If the reference contains invalid characters.

    Examples
    --------
    >>> validate_git_ref("main")
    'main'
    >>> validate_git_ref("feature/new-operator")
    'feature/new-operator'
    >>> validate_git_ref("v1.0.0")
    'v1.0.0'
    >>> validate_git_ref("abc123def")
    'abc123def'
    """
    if not ref:
        raise CommandValidationError(
            "Git reference cannot be empty",
            context={"ref": ref},
            suggestion="Provide a valid git branch, tag, or SHA.",
        )

    if not GIT_REF_PATTERN.match(ref):
        raise CommandValidationError(
            f"Invalid git reference: {ref!r}",
            context={"ref": ref, "pattern": GIT_REF_PATTERN.pattern},
            suggestion="References must contain only alphanumeric characters, hyphens, underscores, slashes, and dots.",
        )

    # Additional security: prevent path traversal patterns
    if ".." in ref or ref.startswith("/") or ref.startswith("~"):
        raise CommandValidationError(
            f"Invalid git reference: {ref!r}",
            context={"ref": ref},
            suggestion="References cannot contain path traversal patterns.",
        )

    return ref


def validate_version_string(version: str) -> str:
    """Validate a semantic version string.

    Parameters
    ----------
    version : str
        The version string to validate.

    Returns
    -------
    str
        The validated version string.

    Raises
    ------
    CommandValidationError
        If the version string is invalid.

    Examples
    --------
    >>> validate_version_string("1.0.0")
    '1.0.0'
    >>> validate_version_string("v16.2.3")
    'v16.2.3'
    >>> validate_version_string("2.0.0-beta.1")
    '2.0.0-beta.1'
    """
    if not version:
        raise CommandValidationError(
            "Version string cannot be empty",
            context={"version": version},
            suggestion="Provide a valid semantic version string.",
        )

    if not VERSION_PATTERN.match(version):
        raise CommandValidationError(
            f"Invalid version string: {version!r}",
            context={"version": version, "pattern": VERSION_PATTERN.pattern},
            suggestion="Version must follow semantic versioning (e.g., '1.0.0' or 'v1.0.0').",
        )

    return version


def validate_path_safe(path: str | Path) -> Path:
    """Validate that a path is safe (no path traversal attacks).

    .. deprecated:: 0.2
       Use :func:`validate_file_path` instead for more comprehensive validation.

    Parameters
    ----------
    path : str | Path
        The path to validate.

    Returns
    -------
    Path
        The validated path as a Path object.

    Raises
    ------
    CommandValidationError
        If the path contains unsafe patterns.

    Examples
    --------
    >>> validate_path_safe("src/tnfr/core.py")
    PosixPath('src/tnfr/core.py')
    >>> validate_path_safe(Path("tests/unit"))
    PosixPath('tests/unit')
    """
    path_obj = Path(path)
    path_str = str(path_obj)

    # Check for absolute paths in untrusted input
    if path_obj.is_absolute():
        raise CommandValidationError(
            f"Absolute paths not allowed in user input: {path_str!r}",
            context={"path": path_str},
            suggestion="Use relative paths within the project directory.",
        )

    # Check for path traversal
    if ".." in path_obj.parts:
        raise CommandValidationError(
            f"Path traversal not allowed: {path_str!r}",
            context={"path": path_str},
            suggestion="Do not use '..' in paths.",
        )

    # Check for special characters that could be exploited
    if not SAFE_PATH_PATTERN.match(path_str):
        raise CommandValidationError(
            f"Path contains invalid characters: {path_str!r}",
            context={"path": path_str, "pattern": SAFE_PATH_PATTERN.pattern},
            suggestion="Path must contain only alphanumeric characters, hyphens, underscores, slashes, and dots.",
        )

    return path_obj


def validate_file_path(
    path: str | Path,
    *,
    allow_absolute: bool = False,
    allowed_extensions: Sequence[str] | None = None,
) -> Path:
    """Validate file path to prevent path traversal and unauthorized access.

    This function provides comprehensive path validation to prevent:
    - Path traversal attacks (../../../etc/passwd)
    - Unauthorized file access
    - Special character exploits
    - Symlink attacks

    TNFR Context
    ------------
    Maintains structural coherence by ensuring file operations preserve:
    - Configuration integrity (EPI structure preservation)
    - Data export authenticity (coherence metrics validity)
    - Model persistence safety (NFR state protection)

    Parameters
    ----------
    path : str | Path
        The file path to validate.
    allow_absolute : bool, default=False
        Whether to allow absolute paths. Default is False for user input.
    allowed_extensions : Sequence[str] | None, default=None
        list of allowed file extensions (e.g., ['.json', '.yaml', '.toml']).
        If None, any extension is allowed.

    Returns
    -------
    Path
        The validated path as a Path object.

    Raises
    ------
    PathTraversalError
        If path traversal patterns are detected.
    TNFRValueError
        If the path is invalid or contains unsafe patterns.

    Examples
    --------
    >>> validate_file_path("config.json", allowed_extensions=['.json', '.yaml'])
    PosixPath('config.json')

    >>> validate_file_path("data/export.csv")
    PosixPath('data/export.csv')

    >>> validate_file_path("../../../etc/passwd")  # doctest: +IGNORE_EXCEPTION_DETAIL
    Traceback (most recent call last):
    ...
    PathTraversalError: Path traversal detected
    """
    if not path:
        raise TNFRValueError(
            "Path cannot be empty",
            context={"path": path},
            suggestion="Provide a valid file path.",
        )

    # Convert to Path object
    path_obj = Path(path)
    path_str = str(path)
    path_parts = Path(path).parts

    # Check for null bytes (common in exploit attempts) - do this before resolve()
    if "\x00" in path_str:
        raise TNFRValueError(
            f"Null byte detected in path: {path!r}",
            context={"path": path_str},
            suggestion="Remove null bytes from the path.",
        )

    # Check for path traversal attempts in the original path first
    if ".." in path_parts:
        raise PathTraversalError(
            f"Path traversal detected in {path!r}",
            context={"path": path_str},
            suggestion="Relative parent directory references (..) are not allowed.",
        )

    # Normalize the path to resolve any . or .. components
    try:
        # Use resolve() with strict=False to normalize without checking existence
        normalized = path_obj.resolve()
    except (OSError, RuntimeError, ValueError) as e:
        # Catch embedded null byte errors from resolve()
        error_msg = str(e)
        if "null byte" in error_msg.lower():
            raise TNFRValueError(
                f"Null byte detected in path: {path!r}",
                context={"path": path_str, "error": error_msg},
                suggestion="Remove null bytes from the path.",
            ) from e
        raise TNFRValueError(
            f"Invalid path: {path}",
            context={"path": path_str, "error": error_msg},
            suggestion="Check path syntax and permissions.",
        ) from e

    # Check for absolute paths if not allowed
    if not allow_absolute and normalized.is_absolute():
        # For relative paths, ensure they don't escape to absolute paths
        if not Path(path).is_absolute():
            # This is a relative path that was resolved to absolute
            # We need to check if it contains .. components
            pass
        else:
            raise TNFRValueError(
                f"Absolute paths not allowed: {path}",
                context={"path": path_str},
                suggestion="Use allow_absolute=True if this is intentional.",
            )

    # Check for other dangerous patterns
    dangerous_patterns = [
        ("~", "Home directory expansion"),
        ("\n", "Newline character"),
        ("\r", "Carriage return"),
    ]

    for pattern, desc in dangerous_patterns:
        if pattern in path_str:
            raise TNFRValueError(
                f"{desc} not allowed in path: {path!r}",
                context={"path": path_str, "pattern": pattern},
                suggestion=f"Remove {desc.lower()} from the path.",
            )

    # Validate file extension if restrictions are specified
    if allowed_extensions is not None:
        suffix = path_obj.suffix.lower()
        allowed_lower = [ext.lower() for ext in allowed_extensions]
        if suffix not in allowed_lower:
            raise TNFRValueError(
                f"File extension {suffix!r} not allowed",
                context={
                    "path": path_str,
                    "suffix": suffix,
                    "allowed": allowed_extensions,
                },
                suggestion=f"Use one of the allowed extensions: {allowed_extensions}",
            )

    return path_obj


def resolve_safe_path(
    path: str | Path,
    base_dir: str | Path,
    *,
    must_exist: bool = False,
    allowed_extensions: Sequence[str] | None = None,
) -> Path:
    """Resolve a path safely within a base directory.

    This function ensures that the resolved path stays within the specified
    base directory, preventing path traversal attacks while allowing normal
    subdirectory navigation.

    TNFR Context
    ------------
    Ensures configuration and data files maintain operational fractality by
    restricting file access to designated structural boundaries (base directories).

    Parameters
    ----------
    path : str | Path
        The path to resolve (can be relative or absolute).
    base_dir : str | Path
        The base directory that the path must stay within.
    must_exist : bool, default=False
        If True, raise ValueError if the resolved path doesn't exist.
    allowed_extensions : Sequence[str] | None, default=None
        list of allowed file extensions.

    Returns
    -------
    Path
        The validated, resolved absolute path.

    Raises
    ------
    PathTraversalError
        If the resolved path escapes the base directory.
    TNFRValueError
        If the path is invalid or doesn't meet requirements.

    Examples
    --------
    >>> base = Path("/home/user/tnfr")
    >>> resolve_safe_path("config/settings.json", base)  # doctest: +SKIP
    PosixPath('/home/user/tnfr/config/settings.json')

    >>> resolve_safe_path("../../../etc/passwd", base)  # doctest: +SKIP +IGNORE_EXCEPTION_DETAIL
    Traceback (most recent call last):
    ...
    PathTraversalError: Path escapes base directory
    """
    if not path:
        raise TNFRValueError(
            "Path cannot be empty",
            context={"path": path},
            suggestion="Provide a valid file path.",
        )
    if not base_dir:
        raise TNFRValueError(
            "Base directory cannot be empty",
            context={"base_dir": base_dir},
            suggestion="Provide a valid base directory.",
        )

    # First validate the path itself
    path_obj = validate_file_path(
        path,
        allow_absolute=True,
        allowed_extensions=allowed_extensions,
    )

    # Resolve base directory to absolute path
    base_path = Path(base_dir).resolve()

    # Resolve the target path
    # If path is relative, resolve it relative to base_dir
    if not path_obj.is_absolute():
        resolved = (base_path / path_obj).resolve()
    else:
        resolved = path_obj.resolve()

    # Security check: ensure resolved path is within base directory
    try:
        resolved.relative_to(base_path)
    except ValueError as e:
        raise PathTraversalError(
            f"Path {path!r} escapes base directory {base_dir!r}",
            context={
                "path": str(path),
                "base_dir": str(base_dir),
                "resolved": str(resolved),
            },
            suggestion="Ensure the path is within the base directory.",
        ) from e

    # Check existence if required
    if must_exist and not resolved.exists():
        raise TNFRValueError(
            f"Path does not exist: {resolved}",
            context={"path": str(resolved)},
            suggestion="Ensure the file or directory exists.",
        )

    return resolved


def run_command_safely(
    command: Sequence[str],
    *,
    check: bool = True,
    capture_output: bool = True,
    text: bool = True,
    timeout: int | None = None,
    cwd: str | Path | None = None,
    env: dict[str, str] | None = None,
) -> subprocess.CompletedProcess[Any]:
    """Execute a command safely with validation.

    This function provides a secure wrapper around subprocess.run that:
    1. Never uses shell=True
    2. Validates the command is in the allowlist
    3. Ensures all arguments are strings
    4. Provides timeout protection

    Parameters
    ----------
    command : Sequence[str]
        Command and arguments as a list of strings.
    check : bool, optional
        If True, raise CalledProcessError on non-zero exit. Default is True.
    capture_output : bool, optional
        If True, capture stdout and stderr. Default is True.
    text : bool, optional
        If True, decode output as text. Default is True.
    timeout : int | None, optional
        Maximum time in seconds to wait for command completion.
    cwd : str | Path | None, optional
        Working directory for command execution.
    env : dict[str, str] | None, optional
        Environment variables for the subprocess.

    Returns
    -------
    subprocess.CompletedProcess
        The result of the command execution.

    Raises
    ------
    CommandValidationError
        If the command is not in the allowlist or arguments are invalid.
    subprocess.CalledProcessError
        If check=True and the command returns non-zero exit code.
    subprocess.TimeoutExpired
        If timeout is exceeded.

    Examples
    --------
    >>> result = run_command_safely(["git", "status"])
    >>> result.returncode
    0
    >>> result = run_command_safely(["git", "log", "-1", "--oneline"])
    """
    if not command:
        raise CommandValidationError(
            "Command cannot be empty",
            context={"command": command},
            suggestion="Provide a valid command sequence.",
        )

    # Validate all arguments are strings
    if not all(isinstance(arg, str) for arg in command):
        raise CommandValidationError(
            "All command arguments must be strings",
            context={"types": [type(arg).__name__ for arg in command]},
            suggestion="Ensure all command arguments are strings.",
        )

    # Extract base command (handle paths like /usr/bin/python)
    base_cmd = Path(command[0]).name

    # Validate command is in allowlist
    if base_cmd not in ALLOWED_COMMANDS:
        raise CommandValidationError(
            f"Command not in allowlist: {base_cmd!r}",
            context={"command": base_cmd, "allowed": sorted(ALLOWED_COMMANDS)},
            suggestion=f"Use one of the allowed commands: {sorted(ALLOWED_COMMANDS)}",
        )

    # Validate cwd if provided
    if cwd is not None:
        cwd = str(cwd)

    # Execute with shell=False (explicit for clarity)
    return subprocess.run(
        list(command),
        check=check,
        capture_output=capture_output,
        text=text,
        timeout=timeout,
        cwd=cwd,
        env=env,
        shell=False,  # CRITICAL: Never use shell=True
    )