Summary
- RFC 3533 gave each Ogg page a capture pattern, stream tag, sequence number, segment table and CRC, allowing a decoder to find and check a page without claiming that the page contained a whole codec packet.
- The format deliberately left identity, time, authenticity, decoding and rendered outcome to other layers: a valid page could begin with a packet whose missing first part had been on an earlier page.
Imagine arriving halfway through a reel and finding one frame in perfect condition. Its perforations align. Its dyes are intact. The inspection stamp is genuine for that frame. None of those facts tells you whether the previous frame is missing, whether this image belongs to the same scene, or whether the projector will turn the surviving material into a coherent performance. RFC 3533 gave digital media a similarly bounded inspection unit: the Ogg page.
Published in May 2003 as an Informational RFC from the Independent stream, the document defined Ogg version 0 as a container. Encoders created logical bitstreams and divided them into packets. Ogg took those packets as ordered sequences of bits, divided them into segments, wrapped groups of segments into pages, and interleaved pages from one or more logical streams into a physical bitstream. The container did not become the audio or video codec merely because it carried the codec’s output.
The four-byte capture pattern OggS marked a possible page boundary. After finding it, a decoder still had to parse the header, determine the segment table and page length, and calculate the page CRC. The 32-bit CRC used polynomial 0x04c11db7. Verified erratum 8825 now clarifies an ambiguity in the original wording: the calculation covers both the header, with the CRC field zeroed, and the page content. The receipt is therefore stronger than a header-only check. It remains a page-local corruption check, not a signature.
That distinction becomes visible in the lacing table. Each one-byte lacing value describes a segment. A value of 255 says the packet continues into another segment; a value below 255 ends it. A zero value can denote an empty packet or close a packet whose size is an exact multiple of 255. A header flag says whether the page begins with a packet continued from the previous page. One codec packet can therefore occupy several pages. Page B may pass its own CRC even though the opening bytes of its first packet disappeared with page A. The surviving page is valid; the packet is not whole.
The page sequence number exposes a different piece of evidence. It rises separately inside each logical stream, so a decoder can notice a missing page. Detection is not reconstruction. A gap can establish that custody was broken without revealing the lost bytes, the affected codec frames or the audible consequence. Conversely, a continuous page sequence proves only continuity of those page numbers. It does not prove that an application retained every page, reassembled every packet, accepted every codec header, decoded every frame or delivered output to a listener.
The logical-bitstream serial number is equally useful and equally limited. Ogg generates it randomly to route interleaved pages back to the correct logical decoder. RFC 3533 explicitly says the number has no connection to the content or the encoder. It is not a work identifier, author identifier, device identity, account, rights statement or provenance seal. Turning it into any of those would be a policy invention laid over a local demultiplexing tag.
BOS and EOS flags mark the beginning and end of a logical stream. A BOS page carries codec-identifying material defined by that codec’s media mapping; additional headers may follow before data. An EOS page can even be a nil page containing position information and a flag but no media payload. Grouped streams begin together and have pages interleaved; chained streams follow one another without overlap. These flags make structure legible. They do not prove that every intended media unit exists between the boundaries, that concurrent audio and video remain synchronized, or that an application rendered the final sample.
Time belongs beyond the container. RFC 3533 states the point unusually plainly: Ogg has no concept of time. Its granule position is an increasing, unitless marker whose meaning comes from the codec and its media mapping. An audio mapping might count samples; a video mapping might count frames; a page on which no packet finishes can carry the special value minus one. An application needs codec knowledge to turn that field into temporal information.
The later Opus mappings make this architectural boundary concrete. RFC 7845 and its successor RFC 9639 define a 48 kHz granule clock, pre-skip, end trimming and seeking behavior for Opus in Ogg. Those rules are not latent inside the eight bytes of the base header. They are supplied by the mapping. Reading a raw granule position as universal seconds would therefore confuse a container landmark with a codec-specific presentation decision.
The MIME trail offers another useful lesson in bounded symbols. RFC 3534 initially registered application/ogg; RFC 5334 later obsoleted it, refined that use and registered audio/ogg and video/ogg. IANA’s current registry coordinates those names. A correct media type helps select handlers and describe broad content. It cannot attest that an individual object has intact packet history, a supported codec, safe content, synchronized tracks or successful playback.
Security follows the same pattern. RFC 3533 supplies no generic encryption or signing for the container or its contents. A codec bitstream may itself be encrypted or signed, but the page CRC does not acquire authenticity from that possibility. The RFC also warns implementations to handle manipulated bitstreams, buffer overflows and related hazards correctly. Parsing a page successfully is not a safety verdict about what later code will do with its lengths, packets or codec state.
The current errata record reinforces the need to label evidence by status. Erratum 8825’s coverage clarification is Verified. Erratum 6796 corrects “pages” to “segments” in an example and is also Verified. Erratum 8824 argues that the precise CRC32 parameterization remains under-specified, but it is only Reported. A careful account can disclose that open question without silently rewriting the RFC as though review had already settled it.
The operational chain is longer than a green checksum light: receive bytes; find a capture pattern; establish a page boundary; parse the lacing table; verify the CRC; check sequence continuity per logical stream; reconstruct complete packets; identify the media mapping; accept codec headers; interpret granule positions; synchronize multiplexed streams; decode frames; render output; and observe what a listener or viewer actually received. RFC 3533 made the early links inspectable. Its lasting discipline is refusing to call those links the whole chain.
Sources
- RFC 3533 — HTML
- RFC 3533 — plain text
- RFC Editor information page
- IETF Datatracker record
- IETF Datatracker history
- RFC 3533 errata
- RFC 3534 — application/ogg
- RFC 5334 — Ogg media types
- RFC 7845 — Ogg Opus mapping
- RFC 9639 — current Ogg Opus mapping
- RFC 6716 — Opus codec
- RFC 2119 — requirement words
- RFC 8174 — BCP 14 clarification
- RFC 6838 — media-type procedures
- IANA media-type registry
- Xiph Ogg framing description
- Heng Lu — Running Code Is Primary
- Heng Lu — On Reality Layers
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
