Repository navigation
OPM.js v1.4
Highlights
- Immutable prepared patches and bounded reusable DSP voice state, plus cached worklet patch registration.
- Live pitch/glide, expression, stereo pan and FM/LFO modulation controls without envelope retriggering; optional per-operator velocity sensitivity.
- Absolute audio-clock starts, scheduled stops/controls, explicit late-start/drop policy, timestamped lifecycle events and a bounded lookahead scheduler.
- A 1,728-case numerical sound matrix, native AudioWorklet contention/stealing checks and 108 preset/conversion acceptance cells.
- Seventh browser example: preset/original-synthetic-DX7 A/B audition, raw peak/RMS reports and locally rendered WAV downloads.
- Installed-package Vite deployment example with complete worklet/module assets and LICENSE, non-root paths, CSP and MIME/404 failure checks; gated manual npm publishing workflow.
Migration
- Package version is 1.4.0; release tag is v1.4. Node.js 22+ remains required; there are no runtime dependencies.
- Canonical voices are version 3. Version 1/2 inputs remain accepted under their original field rules; omitted velocity sensitivity preserves legacy audio. DX7 six-to-four-operator and velocity conversion remain explicitly approximate.
opm.voicesis a defensive read-only snapshot. UseloadVoice()to replace stored patches.playNote({at})uses absolute AudioContext seconds and cannot be combined with relativetime. Scheduled stop/controls share that clock; same-frame stop precedes onset, then controls. Late-start keeps its full duration;late: 'drop'rejects missed starts.- Deploy the complete
dist/tree and retain LICENSE. Every one of its 22 JS modules has a matching map and generated declaration; maps intentionally embed TypeScript source.
Installation
Download opm.js-1.4.0.tgz and SHA256SUMS, verify the digest, then install:
shasum -a 256 -c SHA256SUMS
npm install ./opm.js-1.4.0.tgzThis GitHub release does not publish to the npm registry. See README, both usage guides and CHANGELOG for runnable examples and verification details.
Local verification
- Node.js 26.7.0 on macOS arm64: build, all 108 tests, strict source/development/generated-consumer types, source/generated AST security gates, installed 1.4.0 render/WAV/types and both npm audits passed. Runtime dependency tree is empty.
- All 1,728 sound cases and 108 preset/conversion cells passed.
- Owned isolated headless Chromium 153.0.8010.12 / Playwright 1.63.0, sandboxed and explicitly muted: real stereo/pan, routing/context lifecycle, worklet stress and installed-tarball Vite 8.3.2 production smoke passed. Stress accepted/started 769 notes, stole 760, rejected one intentional late note, peaked at 0.672 and ended with zero active/pending notes and zero DSP errors.
- Vite
/opm-example/deployment verified real signal/lifecycle, blocked inline CSP, exact deployed LICENSE and visible missing-worklet/wrong-MIME failures. - Apple M5 report-only benchmark: 300 warmup blocks excluded, 2,000 measured 128-frame blocks per scenario at 48 kHz. Raw burst p99/worst 1.131/3.303 ms, with one missed 2.667 ms deadline; prepared burst 0.913/1.133 ms, with zero misses. Host/scheduler/GC-dependent observations are not a universal realtime guarantee.
Local browser checks are not locked Playwright 1.56.1 or Firefox/WebKit coverage. Controlled spectral fixtures and unweighted RMS are not hardware-fidelity, arbitrary-FM alias-free or perceptual-LUFS claims. No microphone capture or recording upload was used.
Independent security review
- Release14Inputs: A/B static approval, including voice/DX7/API/worklet data boundaries and WAV/render/application file inputs.
- Release14DspSupply: C/D static approval for this GitHub-only release, including bounded DSP callback/pool safety, generated artifacts, deployment licensing and publishing controls.
- No evidence-backed release blockers remained. Runtime checks were performed separately by 語喵; reviewers did not execute tests or browser checks. External npm trusted-publisher/environment configuration and registry provenance remain unverified prerequisites for a separately authorized npm publication.
Artifact identity
- Reviewed release commit:
325668c8db47acd553a0501f90267aa0ae6dbdb0 - Tarball:
opm.js-1.4.0.tgz(178,943 bytes; 75 intended entries) - SHA-256:
23b3237b5db83c7cbb36a02b04a4610d8ba2104c55fa157272cedc0ce913b994 - The exact packed artifact was installed separately and exercised prepared pitch parity, live glide/expression/pan, release-to-silence and PCM16 WAV export (4,096 frames / 16,428 WAV bytes, zero DSP errors); all 22 module/map/declaration triplets were checked.
Release-commit CI and deployment
- Quality and security passed for the exact release commit: Node 22/24/26 and locked-tool browser Chromium/Firefox/WebKit jobs, including numerical matrices, package/security gates and native worklet smoke/stress; Chromium also passed production Vite deployment checks.
- GitHub Pages deployment passed for the same commit. The live example catalog serves all seven examples.