# Audit — 2017 beep-WAV transcript and residual tail

## Scope

This audit starts from the preserved 2017 textual transcript, not an
unrecovered audio file. It verifies the duration-token mechanics, the
A/x onion decode, and the limits of the remaining token tail.

## Source and preservation status

- Transcript/table source: `archive/recon/audio-files/03_beeps-wav_OCTAL-TRANSCRIPT-and-letter-table-VERBATIM.md`
- Source SHA-256: `17ec93163e486d15b705b87833959c2e4795e6cf8ef2f0f3cf1c9cf1404b9cff`
- Contemporary public solver record: <https://scienceblogs.de/klausis-krypto-kolumne/2017/03/08/how-a-blog-reader-solved-the-tengri-137-mystery/3/>
- Public-record boundary: The March 2017 discussion retains the reported Instaudio route and duration transcript, but it is a solver record rather than the lost WAV bytes.
- Original Instaudio object: `https://instaudio.s3.amazonaws.com/live/private/7fa2c325c0a7395c8856c5bb4f11b5616c6f60c5.wav`
- Object status: Current S3 object is a preserved 319-byte NoSuchBucket stub; original WAV bytes remain unavailable.
- Public-CDX check: 2026-07-27 returned `[]` for the exact object and `[]` for the object prefix.

The archive check is evidence of a failed recovery attempt, not proof that
no private browser cache or unindexed mirror exists.

## Mechanical reproduction

- `2994` base-9 digits on `60` preserved lines.
- Splitting at runs of `0` yields `710` non-empty packets.
- All `27` documented token classes map; unknown tokens: `[]`.
- The published meta-transcription matches exactly: `True`.
- Its structure is three identical blocks plus `djhedjhedjh`; token-label first occurrences are `abcdefghijklmnopqrstuvwxyzA`.
- The repeated A/x region has `176` bits and decodes MSB-first to `666666m7x6x5regc.onion`.

## The sentence and the correction

| Candidate second word | One-to-one substitution status | Result |
|---|---:|---|
| `MIND` | `False` | Fails because `g` and `j` both map to `N` once KNOWS / WHEN / OPEN are applied. |
| `BIRD` | `True` | Consistent with a one-to-one mapping and semantically apt, but not uniquely forced by the token pattern. |

`BIRD` is a valid and semantically apt contemporary correction, but its
validity does not uniquely select it from every possible four-letter word
consistent with the residual substitution positions.

## What `rssstuvwx` actually establishes

The repeated pre-A/x token run is `abccadefbgheijklmelndjecndeopcdebmekqdjerssstuvwx`. The decoded
sentence plus its terminal divider occupies `abccadefbgheijklmelndjecndeopcdebmekqdje`;
the exact remaining tail is `rssstuvwx`. It contains no current
word-divider token `e` and has equality pattern `ABBBCDEFG`.

The letters `r` through `x` are not author-supplied alphabet characters.
Norbert's table assigns each distinct duration packet its next Latin label in
first-occurrence order. All seven tail labels first occur inside this tail;
their raw base-9 packet runs, in order, are
`1141, 1212, 1212, 1212, 12, 15, 2121, 8, 141`. Alphabet positions, Caesar shifts,
or ASCII values applied to `rssstuvwx` would therefore operate on the
transcriber's canonical labels, not on a source-selected character stream.
The source supplies no numerical packing or delimiter rule for those packet
runs beyond their role as distinct tokens.

Under the extra assumption of a single injective substitution completed
from the `BIRD` reading, `rstuvwx` are still
unmapped and may draw from `cfjmquvxyz`. That
leaves `604,800` possible assignments
before any external language model, key, or author instruction is supplied.

This does **not** make the tail meaningless; it shows that the surviving
transcript alone does not determine a plaintext, password, or next action.
A claim to decode it must add a source-led codebook or a recovered primary
artifact and then pass a control, rather than choose a convenient word.
