Skip to content

OPM.js v1.4

Choose a tag to compare

@YueyuHoshizora YueyuHoshizora released this 02 Oct 07:19
· 70 commits to main since this release

Highlights

  • Immutable prepared patches and bounded reusable DSP voice state, plus cached worklet patch registration.
  • Live pitch/glide, expression, stereo pan and FM/LFO modulation controls without envelope retriggering; optional per-operator velocity sensitivity.
  • Absolute audio-clock starts, scheduled stops/controls, explicit late-start/drop policy, timestamped lifecycle events and a bounded lookahead scheduler.
  • A 1,728-case numerical sound matrix, native AudioWorklet contention/stealing checks and 108 preset/conversion acceptance cells.
  • Seventh browser example: preset/original-synthetic-DX7 A/B audition, raw peak/RMS reports and locally rendered WAV downloads.
  • Installed-package Vite deployment example with complete worklet/module assets and LICENSE, non-root paths, CSP and MIME/404 failure checks; gated manual npm publishing workflow.

Migration

  • Package version is 1.4.0; release tag is v1.4. Node.js 22+ remains required; there are no runtime dependencies.
  • Canonical voices are version 3. Version 1/2 inputs remain accepted under their original field rules; omitted velocity sensitivity preserves legacy audio. DX7 six-to-four-operator and velocity conversion remain explicitly approximate.
  • opm.voices is a defensive read-only snapshot. Use loadVoice() to replace stored patches.
  • playNote({at}) uses absolute AudioContext seconds and cannot be combined with relative time. Scheduled stop/controls share that clock; same-frame stop precedes onset, then controls. Late-start keeps its full duration; late: 'drop' rejects missed starts.
  • Deploy the complete dist/ tree and retain LICENSE. Every one of its 22 JS modules has a matching map and generated declaration; maps intentionally embed TypeScript source.

Installation

Download opm.js-1.4.0.tgz and SHA256SUMS, verify the digest, then install:

shasum -a 256 -c SHA256SUMS
npm install ./opm.js-1.4.0.tgz

This GitHub release does not publish to the npm registry. See README, both usage guides and CHANGELOG for runnable examples and verification details.

Local verification

  • Node.js 26.7.0 on macOS arm64: build, all 108 tests, strict source/development/generated-consumer types, source/generated AST security gates, installed 1.4.0 render/WAV/types and both npm audits passed. Runtime dependency tree is empty.
  • All 1,728 sound cases and 108 preset/conversion cells passed.
  • Owned isolated headless Chromium 153.0.8010.12 / Playwright 1.63.0, sandboxed and explicitly muted: real stereo/pan, routing/context lifecycle, worklet stress and installed-tarball Vite 8.3.2 production smoke passed. Stress accepted/started 769 notes, stole 760, rejected one intentional late note, peaked at 0.672 and ended with zero active/pending notes and zero DSP errors.
  • Vite /opm-example/ deployment verified real signal/lifecycle, blocked inline CSP, exact deployed LICENSE and visible missing-worklet/wrong-MIME failures.
  • Apple M5 report-only benchmark: 300 warmup blocks excluded, 2,000 measured 128-frame blocks per scenario at 48 kHz. Raw burst p99/worst 1.131/3.303 ms, with one missed 2.667 ms deadline; prepared burst 0.913/1.133 ms, with zero misses. Host/scheduler/GC-dependent observations are not a universal realtime guarantee.

Local browser checks are not locked Playwright 1.56.1 or Firefox/WebKit coverage. Controlled spectral fixtures and unweighted RMS are not hardware-fidelity, arbitrary-FM alias-free or perceptual-LUFS claims. No microphone capture or recording upload was used.

Independent security review

  • Release14Inputs: A/B static approval, including voice/DX7/API/worklet data boundaries and WAV/render/application file inputs.
  • Release14DspSupply: C/D static approval for this GitHub-only release, including bounded DSP callback/pool safety, generated artifacts, deployment licensing and publishing controls.
  • No evidence-backed release blockers remained. Runtime checks were performed separately by 語喵; reviewers did not execute tests or browser checks. External npm trusted-publisher/environment configuration and registry provenance remain unverified prerequisites for a separately authorized npm publication.

Artifact identity

  • Reviewed release commit: 325668c8db47acd553a0501f90267aa0ae6dbdb0
  • Tarball: opm.js-1.4.0.tgz (178,943 bytes; 75 intended entries)
  • SHA-256: 23b3237b5db83c7cbb36a02b04a4610d8ba2104c55fa157272cedc0ce913b994
  • The exact packed artifact was installed separately and exercised prepared pitch parity, live glide/expression/pan, release-to-silence and PCM16 WAV export (4,096 frames / 16,428 WAV bytes, zero DSP errors); all 22 module/map/declaration triplets were checked.

Release-commit CI and deployment

  • Quality and security passed for the exact release commit: Node 22/24/26 and locked-tool browser Chromium/Firefox/WebKit jobs, including numerical matrices, package/security gates and native worklet smoke/stress; Chromium also passed production Vite deployment checks.
  • GitHub Pages deployment passed for the same commit. The live example catalog serves all seven examples.