Repository navigation
Releases: JonathanRReed/Waves
Release list
Waves 1.7.3
Fixed
- Verify the connected Wave Link process before sending control commands and
recheck its identity when a connection is reused. - Pin the release-tag authority independently of candidate metadata.
- Keep raw CLI responses valid JSON while escaping terminal control characters.
- Keep Reset Mix available until restoring the mix and saving intent both succeed.
- Retain failed profile changes for retry and show a persistent Retry action.
- Preserve existing profiles when importing a matching name, including Unicode
case and accent equivalents. - Show route recovery in the final setup step without blocking optional routing.
- Open the correct app scope from menu overflow links.
- Capture fresh app icons after a process relaunch and isolate decoded cache entries.
- Bound profiler cleanup and support the compatible SDK on newer macOS toolchains.
Changed
- Update Sparkle to 2.10.0 for current macOS updater fixes.
- Share the sorted app roster across menu sections and waveform calculations.
- Index discovery candidates before applying the existing process identity checks.
- Render the DMG background at Retina resolution and preserve its Finder layout.
- Allow local build-only verification without closing or launching the installed app.
Known limitation
- If Chrome updates while running, quit and reopen Chrome before changing its
audio controls. macOS may keep the old main process in a separate code clone.
The universal DMG is signed and notarized. Older macOS runtime testing and the hands-on Stream Deck/device matrix are deferred with the release owner's approval. Local runtime, companion protocol, security remediation and package checks passed.
Waves 1.7.2 build 20
Waves 1.7.2 build 20 restores per-app control with Wave Link 3 and fixes Live activity reporting.
Fixed
- Keep playing Wave Link-controlled apps in Live by tracking Core Audio playback
separately from route ownership. - Remove terminated Wave Link-controlled apps from Live immediately.
- Omit parameters on parameterless Wave Link requests so Wave Link 3 accepts
the connection handshake and channel listing instead of returning Invalid params. - Preserve mix assignments, per-mix levels, and mute settings when moving apps
to independent channels. Leave apps in place when a safe match cannot be verified. - Match Wave Link's whole-percent volume steps so dragging a slider does not
report a false read-back failure. - Explain when an app's dedicated channel has not been added to a mix.
- Add setup and troubleshooting guidance in Mixer settings and Help, including
shared channels, silent output, connection failures, and diagnostics. - Stop flagging a full set of dedicated channels as a setup problem.
- Exercise the real server's rejection of null parameters in the loopback tests.
Independent app volume still requires a dedicated Wave Link software channel.
Apps sharing a channel, such as Zoom and Slack, must be separated in Wave Link.
Verification
The universal macOS package is Developer ID signed, notarized, and stapled. The application passed 691 tests, Thread Sanitizer checks, and local and hosted package verification. The release-policy checks passed 119 tests. Wave Link use was confirmed on the Mac mini.
The release owner approved deferring fresh performance comparisons, macOS 15 runtime testing, and the full physical Stream Deck matrix for this release. These checks are recorded as deferred in the attached publication evidence. No performance improvement or complete physical Stream Deck validation is claimed.
Requires macOS 14.2 or later. Supports Apple Silicon and Intel.
Waves 1.7.1 build 19
Waves 1.7.1 build 19 is a maintenance release. Download Waves.dmg, verify it against Waves.dmg.sha256, and drag Waves to Applications. Existing installs receive this build through Sparkle once the appcast is updated.
Waves 1.7.1 build 19 is a maintenance release: security repairs from the
September 5 source scan, Wave Link bridge hardening, Sparkle 2.9.6, and
release-tooling fixes. The release owner deferred exhaustive performance
benchmarks and the physical Elgato hardware pass for this release; the
Wave Link control path remains fail-closed and covered by loopback tests.
Changed
- Updated Sparkle to 2.9.6, which contains upstream security fixes. Testing did
not reproduce exploitability in Waves. - Added privacy-safe launch milestones and a repeatable comparison harness for
measuring startup. No startup improvement is claimed before the measurements
are complete. - Bound the release evidence, signed tag, external Elgato receipt, and published
files more tightly to their source revision and release authority.
Fixed
- Preserve URL automation route provenance and reject changes that Wave Link
owns instead of reporting them as Waves changes. - Refuse control authority when different runtime identities claim the same
logical app, and keep the incumbent route's controller and settings instead
of letting a spoofed bundle identifier displace them. - Keep automation authority on URL volume, mute and unmute commands so they
cannot relocate channels that Wave Link owns. - Bound Wave Link metadata reads and JSON-RPC responses: regular files up to
64 KiB only, one deadline per request, 64 messages and 4 MiB per response,
and socket closure on timeout or cancellation. - Coalesce Core Audio device-change notifications into a bounded mailbox so a
burst cannot queue unbounded tasks or UI refreshes. - Record the confirmation event when a first control request finds the route
already in the requested state. - Strip terminal control characters and escape sequences from app-supplied
text beforewavesctlprints it. - Release tooling: disable Git replacement objects in the release launcher, and
make the phase runner finish TERM-resistant descendants and report cleanup it
cannot confirm instead of claiming success. - Bound the local control listener's self-check and backlog handling so a stalled
or saturated check cannot hold shutdown work indefinitely. - Stage DMG and publication work in private directories, retain failed DMG
workspaces when detach fails, and publish completed files transactionally.
Release evidence
The attached release-evidence.candidate.json and release-evidence.publication.json are the sealed manifests embedded in the signed v1.7.1 tag. security-scan-receipt.json records the security review and finding dispositions; remote-elgato-approval.json records that the release owner deferred the physical Wave Link and Stream Deck pass for this release. notary-log.json is Apple's notarization log for the attached DMG and release-source-identity.json binds the build to its exact source revision.
Waves 1.7.0
Waves 1.7.0 build 16 is about running well next to Elgato Wave Link and being
a lighter process: it fixes the Wave Link control path that could not find
Wave Link 3's control port, stops two sources of Core Audio churn that could
destabilize other audio apps, and cuts idle and per-gesture CPU work across
the app.
Added
- Test Connection in Settings › Mixer: a read-only check that discovers
Wave Link 3's control port, performs the handshake, and lists its channels
with how many software channels are free, so "Wave Link is not running" and
"every channel already holds an app" are distinguishable without logs. - A Wave Link bridge check in Diagnostics and a matching section in the
diagnostics export (endpoint, Wave Link version, channel layout, last
error).
Fixed
- Find Wave Link 3's control port on real installs. Wave Link 3 chooses an
ephemeral port at every launch and the macOS location of its port file is
undocumented, so the previous file-then-scan discovery could fail outright
and leave every app uncontrollable while Wave Link ran. Waves now asks the
kernel which ports the code-signature-verified Wave Link process is
listening on and accepts only a port that answers the Wave Link 3
handshake. Nolsofprocess is spawned any more. - Stop conferencing auto-pause from silently moving apps between Wave Link
channels. Automation may mute an app that already has its own channel and
is refused honestly otherwise; only your own level change relocates an app. - Keep the Wave Link control socket open briefly after a change so a slider
drag reuses one connection, and skip the notifications Wave Link pushes on
the same socket instead of treating them as replies. - Explain Wave Link states in plain language in mixer rows, the route badge,
Settings, and Help, and name the app rather than its bundle identifier when
no free Wave Link channel is available. - Feed the per-app IO proc only the tap's input stream. An aggregate device
carries every stream of its output device, so a device that also records
(USB headsets, microphones with a headphone jack, audio interfaces,
virtual devices) put its input stream ahead of the tap's; every IO cycle
was then a geometry mismatch, the app was silenced, and Waves held the
device's input open. The device's own input streams now stay disabled for
the IO proc and the callback addresses the tap's buffers by offset. - Bound geometry-mismatch recovery. A rebuild now has to render clean for a
full second before it counts as recovered; a mismatch that returns sooner
backs off and gives up after three attempts, releasing the tap so the app
is audible again. Previously a persistent mismatch destroyed and recreated
the tap and aggregate device four times a second for as long as the app
ran, with every other audio client on the Mac watching the device list
change twice per cycle. - Stop re-probing audio-capture authorization on the 8-second session
refresh and on every device-change event. The probe is a system-wide tap
that every audio client observes being created and destroyed; it now runs
at startup, on an explicit diagnostics refresh, and on Recover Routes. - Coalesce overlapping device-change passes and ignore the inventory events
Waves's own private aggregates raise, so a default-output change no longer
rebuilds every route twice, and a route pinned to a device that did not
change keeps its live tap instead of dropping out. - Remove the verified-router hot path from the level tick. The router check
ran a full code-signature validation on every audio-playing process, twice,
four times a second (roughly ten milliseconds per process per check). It now
reads each process's published bundle identifier from Core Audio, validates
only a process that claims to be Wave Link, caches the verdict for that
process lifetime, and runs only on ticks that re-observe conflicts.
Changed
- A slider nudge mid-drag, an automation step, or a startup restore row no
longer rewrites the session file, rebuilds the diagnostics checklist, or
re-reads the login item over XPC; the committing change does that once. - Icons are captured only for apps that can become mixer rows, not for every
helper and agent process on each 8-second pass. - Adaptive Mix drops to its idle cadence after two seconds of silence across
managed apps and returns to the fast cadence on the first audible pass. - The header waveform and row meters cap at 60 frames a second in the
frontmost window instead of following a 120 Hz display. - Level ticks invalidate only each row's meter, not the whole row.
- The control-socket state broadcast is built only while a client is
connected.
Waves 1.6.1
Waves 1.6.1 build 15 is a maintenance release: it makes Waves coexist
correctly with Elgato Wave Link regardless of which Wave Link generation is
installed, and cleans up internal structure without changing behavior.
Added
- Choose Waves or Elgato Wave Link as the ordinary per-app audio controller
while both apps remain open. Changes persist and rebuild routes immediately. - Disable Wave Link compatibility when using a custom routing workaround. This
bypasses all Wave Link-specific ownership and mixed-output safeguards.
Fixed
- Treat verified active Wave Link output as a global single-owner boundary,
including idle apps and browser or Electron helper processes, so Waves never
leaves a second renderer attached and doubles audio. - Let Waves send per-app volume and mute changes through a dedicated Wave Link
software channel, with read-back confirmation and no fallback renderer when
Wave Link cannot guarantee independent control. - Verify that Wave Link's signed Elgato process owns the loopback control port
before sending any app or channel command. - Discover Wave Link 3's per-launch control port from its published
ws-info.json, falling back to the documented scan range, and accept the
interface revision current Wave Link 3 releases actually report. - Recognize legacy Wave Link 1.x and 2.x installs, which use a different
bundle identifier, so they receive the same monitoring-only protection
against duplicate audio. The control bridge stays Wave Link 3-only and
fails closed for older generations. - Serialize Wave Link bridge writes and close the control socket after each
sequence, so rapid volume drags cannot interleave replies or leave Wave
Link out of sync with what Waves reports. - Yield a stale bridge result when Wave Link quits while a change is in
flight and Waves reclaims the route, so a live Waves route is never
mislabeled as Wave Link-managed. - Keep Wave Link settings changes from claiming untouched or excluded apps
when the conflict later clears. - Refuse boost, equalizer, and output-routing changes for Wave Link-managed
apps instead of reporting them applied. - Stop reporting apps such as Zoom as managed when Wave Link can send a parallel
copy around the Waves route. Compatibility mode now yields the route, while
the explicit compatibility opt-out remains available for custom routing. - Request Wave Link's cryptographic signing metadata when verifying its live
process, allowing compatibility mode to recognize the signed router reliably. - Keep onboarding primary button labels legible by removing a second
onboarding-wide accent tint from the already themed setup flow. - Keep local builds working on machines with either supported macOS 26 SDK
layout.
Changed
- Split the two largest source files (the app store and the audio backend)
into focused per-responsibility files with no behavior change. - Documented the Wave Link loopback control connection, its code-signature
verification, and the opt-in control socket in the privacy and security
policies.
Waves 1.6.0
Waves 1.6.0
Version 1.6.0 build 14.
- Quick mixer compact redesign and pinned app limit updates.
- Updater maintenance and release boundary fixes.
This is a signed and notarized macOS notarized build.
Waves 1.5.0
Waves 1.5 is the largest update yet, focused on making per-app audio control feel dependable, understandable, and polished from first launch onward.
Highlights
- A premium guided setup explains local audio processing, walks through only the permissions and readiness steps your Mac needs, and offers an optional mixer tour that can be ended immediately.
- New route-health states make it clear when an app is visible, monitored, managed, yielded to another router, recovering, or needs attention.
- Wave Link coexistence is substantially safer. Waves verifies active Wave Link ownership, yields affected routes conservatively, and never wraps Wave Link's own mixed output.
- The mixer now has focused keyboard control, stronger VoiceOver semantics, accessible actions and announcements, Reduce Motion behavior, and clearer unavailable-state explanations.
- Settings are reorganized into focused panes for General, Mixer, Profiles, Sound, Shortcuts & Automation, Setup, and Diagnostics.
- Per-app routing, equalizer, boost, profiles, device memory, Adaptive Mix, automatic conferencing mute, and route recovery received broad lifecycle and persistence hardening.
- External control is available through an opt-in local protocol version 1 socket, the
wavesctlcommand-line tool, and the separately versioned Stream Deck companion.
Reliability and security
- Process identity, Core Audio object ownership, route teardown, callback geometry, and device changes are revalidated before native audio work.
- Persistence uses bounded, no-follow reads with additive schema-1 upgrades, corruption preservation, and durable migration markers.
- The local control socket is same-user only, rate-limited before decoding, queue-bounded, and published through a verified inode lifecycle.
- Release packaging now uses exact archived source, isolated universal builds, pinned signing identity, notarization, private artifact staging, and guarded publication checks.
Compatibility
- macOS 14.2 or later.
- Universal app for Apple Silicon and Intel.
- No virtual audio driver, system extension, reboot, account, or telemetry.
- Audio is processed locally and is never recorded or transmitted.
Open the DMG and drag Waves to Applications. Existing profiles, levels, equalizers, and preferences migrate in place.
Validation boundary
The signed and notarized build passed the local package, hosted CI, updater-signature, rollback, Intel, and first-run checks described in the repository. Physical Wave Link and Stream Deck hardware coverage, a compatible-host Thread Sanitizer run, long-duration soaks, and the independent final security receipt remain follow-up validation. This release does not claim those specific surfaces as verified.
Waves 1.4.4
A fail-open audio-routing patch for reliable coexistence with Elgato Wave Link.
Fixed
- Never wrap Wave Link's mixed output in a Waves renderer. One incompatible
nested route could otherwise mute every application carried by the personal
mix at once. - For ordinary apps, treat Wave Link as a competing router only while it has a
live audio stream. Merely opening or focusing Wave Link no longer tears down
unrelated Waves routes. - Release a process tap's hardware mute before stopping its renderer. If Core
Audio refuses to stop, keep the renderer and callback state alive so the app
remains audible while teardown is retried. - Stop teardown at the first failed native dependency instead of destroying an
aggregate device or process tap beneath a possibly live callback. Failed
callback owners remain retained through shutdown to prevent late access to
released state.
Performance
- Start managed-route IO immediately instead of asking Core Audio to wait for
the tapped application to emit its first audio buffer. - Skip the four-times-per-second competing-router scan when Waves has no managed
renderers to suspend.
Waves 1.4.3
A compatibility patch for Macs that use Elgato Wave Link 3.
Fixed
- Detect when Wave Link is actively routing app audio and leave those upstream sources untouched instead of creating a second process-tap renderer. Existing Waves routes are released, and new route attempts explain that Wave Link must be closed first, preventing every source from playing twice with a delay.
Waves 1.4.2
A reliability and security patch for real app audio routes and local control.
Fixed
- Stop nested audio helpers such as Zoom's
caphost.appfrom appearing as a
second mixer source while their audio is already attributed to the parent
app. This removes the delayed duplicate copy heard when Waves managed both
caphostandzoom.usat once. - Stop a delayed volume-drag update from rebuilding a route after that app is no
longer managed. - Show warm-start progress while the restored mixer is becoming ready.
- Make the external-control listener nonblocking so a client connection cannot
freeze the main actor while the accept backlog is drained.
Security
- Attribute audible helper processes by their actual enclosing app bundle path,
not a self-declared bundle identifier. - Rate-limit control requests before full JSON decoding while preserving a
request ID through a bounded top-level prefix scan. - Validate Core Audio string property sizes before writing into fixed-size
destinations. - Pass manually dispatched release tags through the workflow environment before
shell validation, avoiding direct expression interpolation in the script.