Skip to content

OPM.js v1.7

Choose a tag to compare

@YueyuHoshizora YueyuHoshizora released this 02 Oct 18:21
· 42 commits to main since this release

Package 1.7.0, canonical voice format v6. GitHub distribution and npm registry publication are separate; this release does not publish to npm. Historical v1.6 artifacts remain immutable.

Musical scheduling, rendering and expressive control

  • Beat-based Transport: AudioContext-clock pause/resume, seek, loops, meter, BPM and bounded tempo maps; only owned musical notes and automation restart, not an exact DSP snapshot.
  • Incremental PCM16/PCM24/Float32 WAV encoding with exact frames and RIFF32 limits, without retaining a complete file.
  • Static same-origin module Worker rendering with progress, cancellation and acknowledged sink backpressure, including transferred-buffer ownership.
  • Part-scoped performance policies: physical key IDs, sustain, polyphonic/mono legato and last/high/low priority; not a MIDI driver.
  • Independently ramped feedback, LFO rate/depths, ratios/fixed frequencies and live ADSR; voice v6 adds per-operator AM/PM targets while strict legacy inputs 1–5 remain accepted.
  • Immutable eco/standard/high DSP profiles (2×/4×/8×); standard preserves the previous default output.
  • Atomic bank replacement, removal and detached canonical JSON export, plus complete declarations, bilingual examples and shared-score demo integration.

Observed release verification

Reviewed release commit: 5312ab8275824cf1d5824badde28e2f53d6378f7.

  • Independent read-only static review: A PASS — Release17Data; B PASS — Release17Protocol; C PASS — Release17DSP; D PASS — Release17Supply. Reviewers ran no runtime gates and certified no external npm settings. No waiver.
  • Fresh clean package 1.7.0 checkout: 272/272 behavioral tests, strict source/development/NodeNext-consumer types, generated build, source/built AST security checks and installed-package render/WAV/types passed. Full tooling/runtime audits found zero vulnerabilities; runtime dependencies are empty. Sound-quality, voice-quality and the report-only local benchmark passed.
  • Actual quality/security CI on the exact reviewed commit: all six jobs passed — Node 22/24/26 and Chromium/Firefox/WebKit. Native AudioWorklet smoke/stress, installed Vite production/CSP deployment, package checks, audits, quality matrices and enforced warmed-p99 benchmark budgets passed. Pages deployment passed on the same commit.
  • The independent v1.7 tag CI run also passed all six jobs on the same release commit before publishing this release.
  • Assistant-managed native Chromium 150: built demo startup and finite nonzero 48-kHz AudioWorklet PCM passed in eco/standard/high, with zero DSP errors. Native Worker eco/PCM16, standard/PCM24 and high/Float32 outputs matched whole-core WAV bytes for 11,520 frames, including transferred sink buffers, one close and no abort/DSP errors in each completed row.
  • All 105 clean generated distribution assets are byte-identical to the canonical committed distribution. The exact attached 119-entry tarball passed isolated local-artifact/installed-consumer verification; duplicated/untracked local assets were excluded without deleting user files.

Artifact

opm.js-1.7.0.tgz — 378,969 bytes.

SHA-256:

01b9f5abfb85d749e4cbd1c750c76e68248aecb8dd06f9a7fd994be406a016e6

Limits

Listening quality, physical iOS/Android interruption behavior, arbitrary-patch alias freedom and the operating-system file chooser remain unverified. Local CPU measurements are host-dependent, not underrun counters. Managed-browser probes also encountered target closures and a ten-second sequential Worker startup deadline; high/Float32 subsequently passed in an isolated fresh managed tab (40.2 ms), not a universal startup guarantee. GitHub Actions reported deprecated action runtime annotations while forcing those pinned actions onto Node 24; all jobs passed. No npm authentication, registry provenance/signatures or registry publication is asserted.