Skip to content

feat(interpret): decode Google ei microseconds, and caveat its meaning - #35

Merged
h4x0r merged 2 commits into
mainfrom
worktree-google-ei-microseconds
Sep 25, 2026
Merged

h4x0r merged 2 commits into
mainfrom
worktree-google-ei-microseconds

Conversation

@h4x0r

@h4x0r h4x0r commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Google ei= URL timestamps now decode to the microsecond. Before this change they were truncated to the second.

  • Microseconds: the decoder reads the varint of microseconds that follows the 4-byte LE seconds. The unfurl #56 URL now renders 2020-04-20T17:24:06.540099Z, which matches unfurl and the ved parameter in the same URL.
  • Whole-seconds fallback: if the varint is missing, unterminated or ≥ 1 000 000, the reading falls back to whole seconds and its note says so.
  • Caveat on every reading: ei is when Google served the page, not necessarily when the query ran.
  • Parameter matching: only the ei and sei parameters match. Before this change gei=, rei= and similar names also matched.
  • Docs: docs/formats/identifiers.md gains a Google ei section.
  • Tests: new tests, plus an env-gated unfurl oracle that checks the decode to the microsecond.

🤖 Generated with Claude Code

h4x0r and others added 2 commits September 24, 2026 21:30
…ch (RED)

The ei= decoder reads only the 4-byte little-endian seconds. The bytes
after them are protobuf varints, the first a microsecond count: in the
unfurl issue #56 URL, ei decodes to 1587403446 s + 540099 us, and the
ved parameter in the same URL carries 1587403446540099 us (protobuf
13.1.1), which unfurl also reports.

New tests pin:
- the microsecond varint (unfurl #56 and the Cheeky4n6Monkey/Deed Poll
  example), plus an env-gated unfurl oracle to the microsecond;
- a whole-seconds note when the varint is truncated or >= 1e6;
- the caveat that ei is the page-serve time (session start or previous
  search), not necessarily the query time (unfurl #56);
- matching only the ei / sei parameter names, not gei= / rei=.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…g (GREEN)

Google's ei= parameter is 4 bytes of little-endian Unix seconds followed
by protobuf varints; the first is a microsecond count. The decoder now
reads it, so the unfurl #56 URL renders 2020-04-20T17:24:06.540099Z
rather than truncating to the second. This matches unfurl and the ved
parameter carried in the same URL.

- When the varint is missing, unterminated, or >= 1 000 000, the reading
  falls back to whole seconds and its note says so, so a truncated
  value is not presented as second-exact.
- Every reading notes that ei is when Google served the page the link
  was minted on (session start or a previous search), not necessarily
  when the query in the URL ran (unfurl #56).
- Only the ei and sei parameter names match. The old
  split("ei=") also fired on gei=, rei= and any other name ending in ei.
- google_ei moves from the fixed-note STRING_FORMATS table to a
  push_google_ei helper (like push_jwt) because its note now varies.
- docs/formats/identifiers.md gains a Google ei section with sources.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@h4x0r
h4x0r merged commit d36756c into main Sep 25, 2026
27 of 28 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant