* fix(security): remove hardcoded secrets, patch command injection, tighten CORS and Cypher guard
- run_import_workflow.py, run_multi_import.py: replace hardcoded budget
password with BUDGET_PASSWORD env-var (fail-fast if unset)
- server.js /ingest: replace shell-interpolated exec() with execFile()
so user-controlled title/body cannot inject shell commands
- authentik-values.yaml: blank out bootstrap_password and bootstrap_token
so they must be supplied at deploy time via --set or sealed-secret
- cluster-dashboard main.py: restrict CORS from allow_origins=["*"] to
env-configurable whitelist (default: dashboard.researchstack.info),
methods to GET, headers to Authorization+Content-Type
- neo4j_obsidian_connector_router.js (both copies): replace permissive
prefix-only readOnly regex with a deny-list that blocks
CREATE/MERGE/DELETE/DETACH/SET/REMOVE/DROP anywhere in the query, and
route readOnly queries through session.readTransaction()
Co-Authored-By: Allaun Silverfox <bigdataiscoming+9i37y6j2@protonmail.com>
* fix(security): add CALL procedure allowlist for Cypher readOnly, add OPTIONS to CORS
- Cypher guard: restore positive allowlist for CALL targets (only db.* and
apoc.meta.* allowed in readOnly mode). Extract cypherReadOnlyViolation()
helper for clarity. Both copies updated.
- CORS: add OPTIONS to allow_methods so preflight requests succeed.
Co-Authored-By: Allaun Silverfox <bigdataiscoming+9i37y6j2@protonmail.com>
* fix(security): use negative lookahead for CALL allowlist, remove dead CALL\s*\{ branch
- Replace two-regex CALL check with single negative-lookahead
CYPHER_CALL_DISALLOWED_RE = /\bCALL\s+(?!db\.|apoc\.meta\.)/i
This correctly blocks queries containing ANY disallowed CALL target,
even when bundled alongside an allowed CALL db.* or CALL apoc.meta.*.
- Remove dead CALL\s*\{ alternative from CYPHER_WRITE_RE — the trailing
\b never matched because { is a non-word character.
- Both copies updated identically.
Co-Authored-By: Allaun Silverfox <bigdataiscoming+9i37y6j2@protonmail.com>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Allaun Silverfox <bigdataiscoming+9i37y6j2@protonmail.com>
|
||
|---|---|---|
| .agents/plugins | ||
| .consolidation-manifests | ||
| .contextstream | ||
| .cursor | ||
| .devcontainer | ||
| .devin | ||
| .github | ||
| .hermes/plans | ||
| .kilo/rules | ||
| .opencode/agents | ||
| .roo | ||
| .vscode | ||
| .windsurf | ||
| 0-Core-Formalism | ||
| 1-Distributed-Systems | ||
| 2-Search-Space | ||
| 3-Mathematical-Models | ||
| 4-Infrastructure | ||
| 5-Applications | ||
| 6-Documentation | ||
| 6-Kernel-Shim | ||
| ai-math-discovery-systems | ||
| archive/2026-05-26 | ||
| data/erdos_famm_solved_scars | ||
| desi_model_projection_receipt_2026-05-13 | ||
| docs | ||
| obsidian-vault | ||
| pending/lean_unification | ||
| plugins | ||
| scratch | ||
| scripts | ||
| shared-data | ||
| test-results | ||
| workspace-config | ||
| .aider.conf.yml | ||
| .clinerules | ||
| .codeiumignore | ||
| .cursorrules | ||
| .gitattributes | ||
| .gitignore | ||
| .gitmodules | ||
| .mcp.json | ||
| .pre-commit-config.yaml | ||
| .python-version | ||
| .sops.yaml | ||
| AGENTS.md | ||
| airtable_compute_substrate_schema.json | ||
| airtable_hardware_substrates.csv | ||
| airtable_import_guide.md | ||
| airtable_integration_patterns.csv | ||
| airtable_math_workloads.csv | ||
| airtable_optimal_configurations.csv | ||
| airtable_performance_metrics.csv | ||
| airtable_scaling_analysis.csv | ||
| ARCHITECTURE.md | ||
| CHANGELOG.md | ||
| CITATION.cff | ||
| claims.yaml | ||
| CLAUDE.md | ||
| CONCEPTS.md | ||
| Containerfile | ||
| cupfox-config.nix | ||
| flake.lock | ||
| flake.nix | ||
| GEMINI.md | ||
| GETTING_STARTED.md | ||
| kilo.jsonc | ||
| LICENSE | ||
| Modelfile | ||
| NOTICE | ||
| opencode.json | ||
| package-lock.json | ||
| package.json | ||
| pyrightconfig.json | ||
| README.md | ||
| requirements-optional-science.txt | ||
| result-devcontainer | ||
| run-container.sh | ||
| system-packages-optional-science.txt | ||
| THIRD_PARTY_NOTICES.md | ||
| TODO_MAP.md | ||
Research-Stack (OTOM)
Ultra-low power, zero-decimal data routing and compression.
If you just stumbled across this repository, you might see words like "Topological State Machine" and "Manifold Points" and assume this is dense, academic magic. It isn't.
This project is actually built on a very simple, grounded idea: Modern computing is incredibly wasteful.
Right now, running AI or compressing massive datasets requires giant, power-hungry GPUs because they rely on Floating-Point Math (heavy decimals like 3.14159...). We prove that you don't need decimals. You can map complex data (like the grammar of the English language) into structural shapes, and navigate them using only simple integers (whole numbers).
Because we only use addition, subtraction, multiplication, and modulo, this system can run on a $15 blank-slate microchip (an FPGA) instead of a massive server farm.
🛠️ How we know it works (Zero Guesswork)
We do not guess that our integer math works. We prove it. The core of this project is written in Lean 4, a strict mathematical theorem prover. If our logic has a flaw, the code physically will not compile. We currently have 746 verified Lean modules across a 3,313-job deterministic build (0 errors) securing this engine.
Python, Rust, and Verilog only exist in this repository to act as "dumb pipes" to feed data into our proven mathematical core.
📁 Repository Structure (By Goal)
Everything is numbered so you know exactly what depends on what.
| Folder | What it actually is (Plain English) |
|---|---|
0-Core-Formalism/ |
The Brain. Lean 4 code. The mathematically proven integer arithmetic. This is the source of truth. |
1-Distributed-Systems/ |
The Network. Code for making multiple computers talk to each other to share the workload. |
2-Search-Space/ |
The Navigator. Algorithms that search through our data shapes to find the best routes. |
3-Mathematical-Models/ |
The Library. Where we store our databases of equations and compressed English grammar shapes. |
4-Infrastructure/ |
The Drivers. Code that physically talks to the hardware, GPUs, and APIs. |
5-Applications/ |
The Executables. Python scripts that run the system end-to-end. (These are just shims connecting data to our Lean 4 Brain). |
6-Documentation/ |
The Manual. Where you'll find plain-English explanations and our theoretical papers. |
shared-data/ |
Raw data, cache, and exported files. |
📖 Where to start?
If you are new here, read these two files first:
- Explanation for Humans - A translation guide for our technical jargon.
- Calculator-Plain Math - Proof that every complex concept we use can be calculated on a high-school graphing calculator.
🚀 Quick Start
# 1. Compile the mathematically proven core (Takes ~1-2 minutes)
cd "0-Core-Formalism/lean/Semantics"
lake build
# 2. Run the English Manifold Builder (Compresses English via grammar shapes)
cd "../../.."
python3 5-Applications/scripts/redpajama_english_manifold.py
⚖️ The One Rule for Contributors
Lean is the source of truth.
If you add logic, it goes in 0-Core-Formalism/lean/Semantics/ and must be mathematically proven. Python scripts may not contain complex math, branching logic, or cost functions. Python is just the delivery boy for Lean.
🗄️ Infrastructure (Current)
| Component | Description |
|---|---|
4-Infrastructure/infra/ene-rds/ |
Rust workspace (8 crates) replacing the Python RDS stack — Axum HTTP API, PostgreSQL, Ollama embeddings |
4-Infrastructure/storage/ |
restic + Garage S3 (v2.3.0, Tailscale mesh) + rclone storage stack with automated observer agent |
.devcontainer/ |
NixOS hermetic devcontainer with OpenGL/X11, Lean, Python science stack, MCP servers (Notion + AWS) |
4-Infrastructure/infra/credential_server.py |
Credential gateway with apiProvider service kind and cupfox routing |
4-Infrastructure/shim/vcn_compute_substrate.py |
VCN H.265 video-as-compute substrate with auto-profiling (NVIDIA CABAC lossless vs. AMD UMA bandwidth optimization) |
4-Infrastructure/shim/qemu_framebuffer_packer.py |
Zero-copy framebuffer (/dev/fb0) packer with ARGB8888 100% density mapping (1 pixel = 1 scalar) |
6-Documentation/docs/specs/virtio_net_compute_fabric_spec.md |
Spec detailing Virtio-Net packet-as-computation (PIST) and QEMU graphics backplanes |
Research Stack — All Rights Reserved
