v0.5.0
fretwire 0.5.0
The editor leaves the desktop window. fretwire-serve runs the same editor as a daemon on a
headless machine — a Raspberry Pi on the pedalboard — and you open it in a browser on your
laptop. fretwire-mcp opens the same editor to an AI assistant, with a curated tool surface
and every write behind a flag. The POD Go goes from reconciled to verified: an owner
has driven one from fretwire in both directions, its .pgb backups convert, and a restore has
completed on the hardware. And fretwire can now tell you when a newer release exists — opt-in,
once a day, and it never installs anything.
18 commits since v0.4.0.
Serve mode
A Helix Floor owner runs a Raspberry Pi between the Floor's two paths for NAM captures, and every
Linux machine they own is headless. What they wanted was not a Pi build of a windowed app; it was
the editor on that machine, opened from a laptop on the same network. That is fretwire-serve:
- The same built frontend the GUI embeds, served over HTTP with a WebSocket for the pedal's
live pushes, so footswitches and panel changes follow in the browser exactly as they do in the
window. Nothing was forked — the command layer was lifted into a transport-neutral crate
(fretwire-commands) that the GUI, the daemon and the MCP server all consume unchanged. - Loopback by default, no token needed; use an SSH tunnel from the laptop. A wider
--bindrequires a bearer token: generated once into~/.local/share/fretwire/serve-token
and printed at startup as the link to open (http://<host>:8317/#token=…). The link is the
credential — there is no login page, and no TLS to start with: a LAN bind assumes a trusted
network, and a tunnel, a VPN or a TLS proxy cover the rest. - One editor at a time. A second browser gets a clear refusal rather than two undo histories
fighting over one pedal; the seat frees when the first closes, and a reload re-attaches to a
session that is still open. - Your files stay yours. IR uploads and downloads, preset exports and restores travel inside
the request, so in the browser they come from and go to your machine, not the Pi's disk —
with a checkbox to keep a backup on the daemon's disk instead. Data import stays server-side
(fretwire import-dataover SSH; the installer is a gigabyte).
Confirmed live on the LAN: a wide bind, the printed link opened from another machine, editing and
footswitch follow through the browser. docs/serve-mode.md has the survey and the security
posture in full.
An MCP server
fretwire-mcp is a stdio MCP server, so an assistant such as
Claude Code can read and edit the pedal through fretwire:
- Curated, not the whole command set — fourteen read tools that work offline against fretwire
export files and the model catalog (a preset as its blocks in signal order, a diff as the lines
that changed), plus live reads once connected. - Writes only when you say so.
--allow-writesadds the edit-buffer tools (parameters,
bypass, blocks, snapshots, preset changes, undo);--allow-saveadds the single tool that
writes flash. An ungated tool is not refused, it is not listed, so an assistant cannot be
talked into a write you did not enable. - Parameters are set in display units, as HX Edit shows them (
6.5,450 ms, an enum's
label, on/off); the same formatting rules run backwards.
Firmware and flash traffic never appear, as everywhere in fretwire.
Update check
fretwire otherwise makes no network connection at all, so this one is built to stay small:
- One
HEADrequest to GitHub'sreleases/latestpage, redirects not followed; the tag is read
off theLocationheader. No API, no JSON, and nothing about you goes with it — the User-Agent
is the bare wordfretwire. - Opt-in. The first-run screen asks; an existing install asks once in the editor. The
answer, and Check now, live in the About dialog behind the version number in the header.
FRETWIRE_NO_UPDATE_CHECK=1pins it off.fretwire check-update [--auto on|off]is the
terminal form, for a headless daemon. - Once a day, silent when offline, and strictly newer — a checkout ahead of the last tag
is never nagged. - It only ever reports. The badge links the release page with the instruction for how this
binary was installed (.deb/.rpm, AppImage,cargo install, or a checkout). A self-replacing
binary would fight apt and dnf, so that is not on the table.
POD Go: verified
Everything about the POD Go's entry is now measured, and fretwire has driven one both ways:
- Backups convert.
.pgbis.hxbunder the hood — decoding its container (a tagged archive
with an index table at the end, which the Floor's happened to hide) filled in every remaining
device field: identity0x210007,Factory/Usersetlists of 128,01A-32Dbanking, a
byte-exact footswitch map.hxb-convertthen learned the POD Go's own chain shape, IR presets
(the sixth value is the pedal's own) and the looper, and all 135 of the owner's presets
convert. A restore completed on the pedal. - Structural edits, the POD Go way. POD Go Edit has no add or delete: move is a
whole-document rewrite (op 78 then op 21), empty a slot is bare op 28. fretwire reproduces
the rewrite — slot rotation, renumbered targets, rotated snapshot matrices — verified against
the capture's own before/after pair, and uses it on a POD Go. Filling an empty slot sends op 39
where the owner has shown it holds (slots 1–8) and refuses slots 9 and 10, where it crashed
the pedal once. Swapping the wah or volume block to another type is refused client-side: the
pedal rejects it and then wedges until a reboot. - The move that aborted was ours. The chunked writer's slow-credit guard, calibrated on a
Helix Floor, fired on a POD Go whose normal turnaround for anything touching the preset is
20–26 ms. The guard is Helix-only now; the silence guard stays for every device. - The GUI's In/Out labels probe the POD Go's own I/O symbols, and the IR Select dropdown is
labelled from the IR list.
docs/pod-go.md is the survey; the fixed chain and what would still help are spelled out there.
An Arch package
packaging/PKGBUILD had never been built. It has now — on this release the workflow runs
makepkg in a stock Arch container, installs the result, checks the udev rule, desktop entry and
the GUI's libraries, and attaches fretwire-<version>-1-x86_64.pkg.tar.zst here. Install it
with sudo pacman -U. An AUR listing follows when AUR registration reopens to new accounts.
(makepkg's lto option produced C objects rust-lld cannot link — options=('!lto') is why.)
Also
- The README leads with the whole HX family, and the Helix Rack is named for what it is:
recognised and covered by the udev rule, never yet plugged in. If you own one,fretwire detectsayingHelix Rack: presentis the report we are missing. - Package descriptions in the
.deb,.rpmand Arch package name the family, not the Stomp.
Known limits
- Serve mode has no TLS of its own; put it behind a tunnel or a proxy beyond a trusted LAN.
The staticfretwire-servebinaries have been run on x86-64; the arm64 one, like the arm64
CLI, has not been run on ARM hardware here. - POD Go: a
moveon the hardware has not yet completed end to end since the guard fix (the
abort came before chunk 3); slots 9 and 10 stay unreachable from fretwire; the IR directory is
scanned rather than decoded. - The update check has never seen a real newer release — this one is what 0.6.0 will test.
- Grid and routing planning is still DSP-0 only; the settings namespace is mapped in part;
IR reorder is delete-and-re-upload. - No firmware, flash or DFU traffic, by design and permanently. See
docs/safety.md.
Installing
Grab the .deb, .rpm, .AppImage or the Arch .pkg.tar.zst for the GUI, or the static
tarballs that run on any distro, x86-64 or arm64: fretwire-cli-* (the CLI),
fretwire-serve-* (the daemon, one file with the editor inside — for the Pi), and
fretwire-mcp-* (the MCP server). The deb, rpm and Arch package install the udev rule and
the CLI alongside the app; for the AppImage or the tarballs, install packaging/70-hxstomp.rules
yourself and replug the pedal.
On first run the app imports the model and preset reference data from your own HX Edit
installation (POD Go owners: from POD Go Edit), and asks whether to check for new versions.
Nothing proprietary is shipped in these packages, and nothing is sent anywhere unless you say yes.
Thanks
@jamesremuscat on issue #15, whose captures of POD Go Edit's every structural verb, .pgb
backup, usbmon timings and hardware rounds took the POD Go to verified; the Helix Floor owner on
Reddit whose Pi-between-the-paths setup is the reason serve mode exists; and the Floor testers
whose logged sessions keep the write path honest.