fengshui.engine audit

input_digest (recomputability) 可复算 Glossary

The fingerprint published with every chart this engine produces: a canonicalised SHA-256 hash of the normalised input, which lets anyone re-run the calculation and compare the result byte for byte.

kě fùsuàn · 可复算 (simplified) · 可復算 (traditional) · engine field input_digest

Source credibility (S/A/B/C/X): S (RFC 8785, FIPS 180-4 — open standards)    Rule computability (A/B/C): A

What it is

Most chart software asks you to trust its output. This engine is built as a pure function — same input, same ruleset, same output, no hidden clock or randomness — and input_digest is the promise that makes the claim checkable. It is defined precisely: the input is normalised (times as parsed instants with their offset, angles as six-decimal degrees in [0,360), coordinates in WGS84 with seven decimals, map keys sorted), serialised with JSON Canonicalization Scheme (RFC 8785, JCS), and hashed with SHA-256. The published value is sha256: followed by the lowercase hex digest, shipped next to engine_version and ruleset_id.

Together with output_digest (the same treatment applied to the output), this yields a three-field contract: what went in, which rule set and engine version decided, and what came out. A replay — locally in the browser, or through the public replay endpoint — either reproduces the output digest exactly or reports a structured diff. Nothing about the hash requires trusting the server: the computation runs on your device, and the digest is enough to archive and re-verify a chart years later.

What normalisation actually covers

The digest is only meaningful if "same input" means the same thing everywhere, so the specification pins the edge cases: a wall-clock time that is ambiguous under a historical daylight-saving change must be recorded as the user's confirmed candidate (with the tzdb version), not silently resolved; any environment dependency that can change the output — terrain tile version, magnetic model version — enters the digest via content-hashed data-source fields; request IDs, locale and tenant labels are explicitly excluded. This is why two independent implementations of the engine produce identical digests: the measured cross-binding comparison found the WASM and native builds agreeing on 400 of 400 samples, byte for byte.

How this engine uses it

Related entries

True Solar Time — the clearest example of a normalisation decision (which time is "the input time") that the digest pins down · Early / Late Zi Hour — a ruleset parameter, recorded in ruleset_id · Xia Gua / Ti Gua

Back to the glossary index.