Confirmed working on Ed's two machines before shipping (his log: slider 500 with 17ms buffered
at 07:10:31 -> 214ms at +3s -> 445 at +9s -> settled ~490 by +15s; auto-tune then walked it down
in 5ms steps with the buffer tracking; a drop to 20ms took effect immediately). Both directions,
auto-tune on and off.
Third fix in this batch, found while answering "is ASIO testing essential before we ship": the
ASIO slider only exists in BothIndependent, but MainForm pushes its persisted value at startup in
EVERY mode (and its auto-tune can tick). Now that all routes resolve to the shared value in
single-slider mode, that write would silently overwrite the visible slider with a hidden control's
number. SetMaxLatencyMs now ignores AsioLane writes when !independentLanes — in single-slider mode
the ASIO box governs nothing. Gate covers it, plus the ASIO half of the wiring (a stream on the
ASIO lane reads the ASIO slider; moving one lane doesn't disturb the other) — provable without an
ASIO device, since the change is about WHICH value a lane reads, not the driver path (untouched).
Docs: manual gains an honest paragraph on changing latency mid-listen (immediate down, a few
seconds up, the slight stretch is the change happening, no gap or click); About + RELEASE_NOTES
for 5.9; MANUAL regenerated. Version 5.9. Gate 74/74 + relay 7.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The About box's release notes had accumulated the ENTIRE version history back to v1.0 —
~70 KB in a single TextBox — and reading a control value that size crashes some screen
readers (user reports, 2026-08-11). The box now displays only the newest five version
blocks via a pure trim (TrimToLastVersions), ending with a plain pointer to the full
history on the GitHub releases page. The full constant stays in source as the archive.
Gate: new step pins the trim logic on synthetic notes AND the real shipped text (exactly
5 versions, size well under the crashing range — 5,516 chars vs ~70,000) so the crash
can't quietly return as releases accumulate. 73/73. Readme About section updated + MANUAL
regenerated; 5.8 notes mention the change.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Root cause found while REPRODUCING the suspected wrong-owner bug in a gate test (the repro
failed in a way the theory couldn't explain, and the empirical icacls run showed why): the
5.6 hardening's /T sweep applied (OI)(CI) grants to FILES, where such ACEs are inherit-only
— they grant the file itself NOTHING. Every file existing at harden time was left with
/inheritance:r + inherit-only ACEs = an effectively EMPTY ACL: unreadable/unwritable by the
user, admins, even SYSTEM. That is the Jonathan report (2026-08-06) end to end: profile save
"access denied" even elevated, logs unreadable in Notepad, his own icacls /T "fix" adding
useless inherit-only ACEs (137 processed, nothing healed), new files fine (echo test), and
the service failing to start (SYSTEM can't read a wedged profile).
The fix, in layers:
- BuildServiceDirAclArgs no longer sweeps /T: the lockdown applies to the FOLDER only.
Existing children are rebuilt by a new /reset pass (BuildResetChildrenArgs) as purely-
inherited from the hardened folder ACL — real file access again, stale/planted explicit
ACEs removed, and it HEALS files wedged by 5.6. Regression-pinned in the gate (the folder
args must never contain /T again).
- Second bug fixed in the same area: the elevated helper recorded ITS OWN token as the
"installing user" — under over-the-shoulder elevation that's the separate admin account
whose password was typed, not the person at the keyboard. Elevated verbs now carry
--as-user <SID> from the non-elevated app (validated: real user SIDs only — service
identities and builtin groups rejected) and install/repair re-record it, so a stale wrong
owner can't persist through reinstalls or self-update re-hardens.
- Self-heal everywhere: new --repair-service-access verb (re-record owner + re-harden);
"Repair service folder access" in the Service menu; a startup write-probe that offers the
repair when the folder is broken (settled startup sequence, ForegroundDialog, skipped on
--silent); the profile-save UnauthorizedAccessException catch offers it at the exact wall
users hit; and the service self-update's existing re-harden now runs the FIXED sequence,
so wedged fleet machines heal automatically when 5.8 rolls out — no user action needed.
- Logs readable again: Users get read-only on service\logs (inheritable, no /T needed —
propagation covers existing files) and on service-events.log. The profile stays locked
(it holds the obfuscated password). GrantUsersWriteToBin deleted — the folder ACL's
inherited user-Modify covers bin, and the reset wiped its explicit grants anyway.
- DoStart/DoStop no longer swallow the reason: exception recorded to service events, and
distinct exit codes (6 timeout, 7 SCM refused, 9 repair-didn't-stick) let the dialog say
what happened instead of the bare "(code 1)" that cost this diagnosis a day.
Gate: new "Service folder repair" step reproduces BOTH bugs for real in a scratch folder —
wedges a file with the exact 5.6 spec (proves reads genuinely die), locks the folder to the
wrong owner, asserts the app's probe reports broken, runs the exact shipped repair sequence
(ApplyServiceDirAcl), and asserts folder writable + wedged file readable again. Plus a
SID pass-through step (validation, parse, arg-building, logs-grant shape). 72/72 + relay 7.
Docs: Service-menu repair item + troubleshooting entry in readme; About + RELEASE_NOTES
rewritten for 5.8; MANUAL regenerated. Version 5.8. NOT released — awaiting Ed's test.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The v5.6 password change went down badly and broke the other ports: raising PBKDF2 to
600k changed the key recipe, so the SAME password produced a DIFFERENT key on 5.6 vs
every other build (the iOS/TestFlight app, older desktops) — same password, no audio.
Ed: back it out so the other ports can use it again; a password is still required, just
suggest a strong one.
Reverted:
- PBKDF2 100k again (RemSoundCrypto) — the key recipe now matches the other ports, so
the same password derives the same key and audio flows again. Pinned by a gate check
so an accidental change can't silently re-break cross-port compat.
- ForPlainPassword no longer refuses a weak password: ANY non-empty password derives a
key (encryption stays mandatory — empty still means no audio). Strength is not enforced.
- Removed every enforcement/nag: the streaming-tick force-strengthen, the startup
weak-password dialog, the status-line weak warning, the app's weak-SERVICE-password
launch + live nags, and the service-profile save-time block. The password dialogs just
suggest a strong password in their hint now; PasswordStrength.cs deleted (now unused).
Someone who set a strong password because of 5.6 feels no difference on update — their
password still loads and works, no prompt (Ed's requirement).
Kept (separate from "stronger passwords", not backed out): signed updates, password-
sealed remote volume, service startup volume, the update time-window, the nonce widening,
and the relay address-proof. NOTE: sealed remote-volume still needs both ends on 5.6+ —
ordinary audio does not. Flagging in case full remote-volume interop with old ports is
wanted too.
Docs: About + readme + release notes rewritten for v5.7 (plain English, positive framing,
no "must update"). MANUAL.md regenerated. Version 5.7. Gate 70/70 (dropped the now-moot
streaming-strengthening step) + 7 relay tests.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The everyone-must-update release. Four coordinated changes, each from the security
discussion Ed approved 2026-07-27, plus the remembered-apps polish:
1. SIGNED RELEASES. build-release.ps1 now signs the release zip (ECDSA P-256 /
SHA-256, --sign-update verb) with a private key that lives ONLY at Ed's chosen
location outside the repo; the matching public key is embedded (UpdateSignature)
and the updater REFUSES any release whose .sig asset is missing or does not
verify - a compromised GitHub account can no longer ship code to users. The
signing verb self-checks against the embedded key so a key/embed mismatch fails
the pipeline, and the gate proves the on-disk key matches the embed when present.
2. STRONGER PASSWORDS, ENFORCED (BREAKING). PBKDF2 raised 100k -> 600k (both peers
must derive the same key, so 5.6 cannot stream with pre-5.6 AT ALL - release
notes lead with it). New PasswordStrength rule (>= 8 chars, not an infamous
password) enforced at EVERY door: both password dialogs block weak NEW entries
with concrete plain-English advice; the streaming gate walks an existing weak
password through strengthening; and ForPlainPassword - the single derivation
choke-point shared with the service - refuses weak outright, so no path streams
on a guessable password. Headless service logs the why. Per Ed: painful once,
and this coordinated-update release is the cheapest moment it will ever have.
3. RELAY ADDRESS-PROOF (watch-only). The relay sends every new client address a
random cookie and marks it verified when echoed - a forged source address can
never echo, killing the reflection attack. 5.6 clients echo automatically
(AddrCheck type 10, verbatim, self-limiting); the relay ships watch-only
(logs would-blocks) until the fleet updates, then one flag (--require-addr-check)
enforces. Per-IP entry cap (4) enforced immediately. Relay changes are committed
but NOT deployed to the Pi - they ride the v5.6 release moment.
4. Remembered-apps empty state teaches its lifecycle + manual sentence; About/
release notes written; version bumped to 5.6.
New gate steps: signing round-trip/tamper/wrong-key/embed-match; password rules incl.
the exact "Games" case; AddrCheck verbatim echo. Gate 69/69.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- csproj <Version> 5.4 -> 5.5.
- About box: prepend the v5.5 entry (UPnP close-hang fix + keyboard shortcuts on
every dialog).
- RELEASE_NOTES.md rewritten for v5.5.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- csproj <Version> 5.3 -> 5.4.
- About box: prepend the v5.4 entry (Use Windows default output + exclusivity, the
service-install freeze fix + start-after-install, service now outputs/apps only).
- RELEASE_NOTES.md rewritten for v5.4.
(The manual, readme.html, was already updated incrementally as each change landed.)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Verified findings from a multi-dimension code audit, plus the two install-flow bugs:
- Fix Opus encoder use-after-free on a codec/rate change while streaming (guard swap vs encode).
- Fix "both" single-file recording dropping audio + drifting (drain both directions in lockstep).
- Fix broken clip counter, UPnP teardown on exit, auto-update-restart foreground grant, and a
malformed-Opus-format packet orphaning a playout session forever.
- Post-install relaunch now respects start-minimised; uninstall is path-aware so it won't clear a
different copy's run-at-startup.
- Perf/hygiene: cache AppConfig off UI hot paths, fold per-peer EQ+gain into one pass, deterministic
disposal (tray menu, timers, COM shortcut, Process handles, process meter), ring-buffer overflow
guard, receiver session-lock fix, remote-control allow-list moved onto the UI thread.
- Remove dead code (two IsAsioBackend, SessionPlayout.Reset, IsSameEndpoint, RemSoundUpdater
IDisposable); several stale-doc fixes.
Deferred (not in this release): drift-estimator tweak, peer-discovery pruning, uninstall retry-loop,
encryption nonce. Wire format unchanged (interops v3.3-v5.1). Version -> 5.2.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
New Options -> Install / Uninstall RemSound on this PC: a per-user self-installer
(%LOCALAPPDATA%\Programs\RemSound, no admin) with optional desktop + Start-menu
shortcuts, login auto-start (reuses StartupAutoStart), Windows Installed-apps
registration, and copy-across of profiles+config, recordings and logs. Install
state is decided by a marker file, not a folder-path guess; the post-install
relaunch hands over foreground via AllowSetForegroundWindow so the installed copy
comes to the front; uninstall uses a batch remover (no PowerShell) and confirms
with two independent tick-boxes. All new dialogs use the house accessible controls
(AccessibleCheckBox, Theme.Heading).
Also: iOS (TestFlight) companion link alongside Android in README + manual;
slimmed-down default cue WAVs; About/RELEASE_NOTES/manual updated; version -> 5.1.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Multi-track recording drift fix (Ed's question — can the separate tracks drift over an hour?):
* Root: FlushPeerTracks skipped a peer that produced no samples in a render block, so a peer that
went quiet long enough for its session to be pruned (>4 s idle) would have its track fall behind
and desync. Now every peer track is padded to a full render block each cycle (silence when the
peer produced nothing), so all peer tracks stay sample-locked to the single render clock — they
can't drift apart however long the recording runs, and all end the same length. Same padding for
the single-file bypass path. OnRecordBlockComplete now carries the block's float count.
(The peer tracks are already resampled to the render clock per peer, so this makes peer-to-peer
sync exact; your own "me" track is capture-clocked — same soundcard for capture+playback = same
clock = no drift, different interfaces can drift slightly.)
* Self-test: two new steps — "Per-peer shaping DSP" (PeerDspChain unity/master-off/volume/parametric
+ ParametricToPeaking) and "v5 settings and shaping round-trip" (AppConfig defaults, NamedPeers,
MainTabOrder, parametric PeerShaping, recording default = Both).
* Logging (gated by the logging checkbox): master shaping switch, EQ-mode change, parametric band
add/delete, peer rename/clear/delete, and the applied Appearance settings after Preferences close.
* CLI: --list-profiles and --list-named-peers (read-only), in --help.
* Version bumped to 5.0; About-box changelog, RELEASE_NOTES.md and README updated for v5.
Build clean; --selftest passes.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Ships the per-profile "Lock to these exact peer addresses, no matter what" toggle.
Version 4.9; About changelog + RELEASE_NOTES added.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The same singer hit a rare crash: their transmitter (COMP3) was reachable at two
addresses at once — the VPN address 10.8.0.1 they chose and that machine's wireless
192.168.3.245 — and the discovery-driven endpoint-follow ping-ponged the connection
between the two (the log shows four moves in 58 ms) right where the process died with
no shutdown line, no managed exception, no dialog: a hard crash from the receiver
audio-session teardown/rebuild churn the thrash caused.
Fix: the follow loop now never moves off an endpoint that's still answering heartbeats,
only follows once the current one has been unreachable for a sustained grace period
(6 s), only to an address that is itself answering, and never more than once per cooldown
(15 s) — so it can't thrash, and a peer reached on a working address stays put (honours
the singer's "just stay on 10.8.0.1"). New endpointUnreachableSinceUtc + lastEndpointMoveUtc
state; genuine DHCP/network moves are still followed a few seconds later.
Also: a global crash handler (Program.WriteCrashReport on AppDomain.UnhandledException +
TaskScheduler.UnobservedTaskException) writes a crash-*.txt into the logs folder, so a
future "RemSound just vanished" report leaves a stack behind. Removed a stale doc comment
left over from the v4.7 adoption removal. Manual gains a "RemSound closed unexpectedly"
troubleshooting entry. Version 4.8; About + RELEASE_NOTES updated.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Removes the heartbeat "adopt a live address" feature (added v1.6). On a LAN with
more than one RemSound machine it could latch a receiver onto an unrelated sender
that happened to be pinging the audio port — then never recover to the real peer,
needing a manual restart (the singer's #15, with log). The feature guessed peer
identity from an untracked ping source with no way to verify it was the same peer;
on the stable VPN/LAN addresses RemSound is actually used with, it only ever caused
harm, since same-address reconnect already works via the continuous heartbeat.
Removed TryAdoptLiveHeartbeatAddress + IsPrivateLanAddress (MainForm) and
GetUntrackedPingSources + recentPingSources (HeartbeatService); the identity-safe
discovery-based following (by verified peer ID) stays. Manual troubleshooting entry
rewritten to match.
Also bundles the held changes since v4.6: status reads line-by-line with GB totals
and double-press-to-copy, CPU/memory in the status, the Install Scripts folder, and
the what's-new-after-failed-update fix. Version 4.7; About + RELEASE_NOTES updated.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- New "Use Windows default audio device, follows Windows changes" entry at the top of the
received-output and send-input WASAPI lists. Resolves the current Windows default live,
re-routes automatically when the default device changes, works alongside specific devices,
and persists across launches (a follower can't go stale). Optional "untick the others?"
prompt with a remembered "don't ask again", reset via a new Options item "Reset the default
audio device prompt".
- Manual updated for the feature, plus a sweep that corrected the now-stale Options-menu
section (retired Startup-behaviour item, four->five Preferences tabs, missing entries).
About changelog and RELEASE_NOTES updated; version 4.6.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Pre-v4.4 upgraders are offered a one-time dialog to copy their keyboard shortcuts
from one of their profiles (still readable in the profile files) instead of being
reset. Users who already went through v4.4's reset are deliberately NOT re-offered
(gated on KeyboardShortcutsGlobalNoticeShown). New KeyboardShortcutImportDialog +
AppConfig.KeyboardShortcutsImportOffered + MainFormHotkeyController.ReloadAndReRegisterAll.
- Keyboard shortcuts dialog: new "Clear this shortcut" button; Delete inside the
capture box leaves a shortcut unassigned.
- Relabelled the three RemSound-app remote rows to "Send remote RemSound volume/..."
to distinguish them from the Windows-global ones.
- Manual (readme.html + MANUAL.md), About changelog, RELEASE_NOTES updated; version 4.5.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Fixes issue #14: shortcuts were stored on each Profile, so one set on profile A
didn't apply on profile B and seemed to vanish on switch. They now live in
AppConfig (one set shared by every profile). RemSoundSettingsStore's Load*/Save*
hotkey methods re-point to AppConfig (callers unchanged); the per-profile cache
fields, profile load/save plumbing, and the HotkeySetting helper class are removed.
Profile's HotkeyRecord fields stay only for back-compat deserialization.
On upgrade, shortcuts reset to defaults (there's no single correct set to carry over
since profiles could hold different/partial sets). A one-time startup notice tells
upgraders to re-set them; fresh installs are silently marked done (nothing to reset).
Manual, About changelog and RELEASE_NOTES updated; csproj <Version> 4.4.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Both update cue variants ("update 1.wav" / "update 2.wav") replaced with a
gentler mix that signals an incoming update without interrupting work mid-flow.
About-box note added (tidied wording); csproj <Version> bumped to 4.3.1. No code
changes.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- New screen-reader hotkey "Speak the RemSound status information" (issue #13):
reads the status line aloud through the active screen reader via Tolk, fires from
anywhere (system-wide), unset by default. Built behind an IScreenReaderOutput seam
so a future build can swap Tolk for Prism on Windows 10+ without touching callers.
Tolk DLLs vendored under tolk/ and shipped next to the exe.
- New Logging tab in Preferences: Enable logs + Write logs now moved there, plus
opt-in startup "warn if logs folder exceeds N MB" and "delete logs older than N days",
and a "Delete all logs" button (Yes/No confirm). New LogMaintenance helper + AppConfig
settings drive it.
- Manual (readme.html + regenerated MANUAL.md), About changelog and RELEASE_NOTES
updated in plain English; csproj <Version> bumped to 4.3.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Connect no longer freezes: PushDiscoveryUnicastHints resolved remembered
hostnames with synchronous Dns.GetHostAddresses on the UI thread, blocking the
whole window for the DNS timeout on an unresolvable name. A screen-reader user
experiences that as the entire machine locking up. Resolution now runs off the
UI thread. Same class of bug as the v3.0.1 UPnP-on-the-UI-thread hang. (#10)
- New profile / profile switch no longer hides the window: OnShown ORed the
global StartMinimised into every instance, so creating a new profile while
Start minimised was on dropped the window to the tray and looked like a crash.
StartMinimised now applies only to a genuine cold launch; relaunches honour the
explicit per-instance flag. (#12)
- Smoother WASAPI audio: the receive producer loop and sender mix loop pace
themselves with WaitHandle.WaitOne, bound by the system timer (~15.6ms default).
Without a fine timer the 10ms feed slips to ~16-31ms and delivers audio in
chunky bursts (the desktop-render chunkiness behind Andre's dropouts/lag). New
SystemTimerResolution holds a 1ms timer whenever a stream is live, independent
of the opt-in Priority mode.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Starting straight into the tray (StartMinimised / --minimized) no longer plays the "minimise"
cue; only a genuine user minimise does (the startup path passes playCue:false)
- Restoring the window from the tray now lands focus on a real named control on the active tab so
NVDA announces it, instead of resting on the role-less QuietTabControl and surfacing silently
- Shared the focus-a-leaf-for-announcement helper between the main window and Preferences
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Audio cues
- Cues for send/receive on-off, minimise/restore, checkbox tick/untick, and tab switch
- Soft keyboard clicks while typing, with a distinct passkey sound on password fields
- Per-cue "Choose sound" variant picker; "(none)" silences a cue; front-most missing-sound warning
- Send/receive cues take priority over the generic checkbox sound; programmatic ticks stay silent
Preferences
- Redesigned into four tabs (General, Audio cues, Startup behaviour, Update settings)
- Startup behaviour moved in from the Options menu
- NVDA now announces the dialog on open (focus a real named control, not the quiet tab control)
Auto-tune
- Cause-aware: tells device render-callback stalls (more buffer can't fix) apart from genuine
network/buffer starvation, so it no longer pins latency high on chunky onboard cards
- Lowering the target eases the buffer down (glide) instead of trimming it, so no clicks while tuning
Sounds layout
- Shipped defaults moved out of the per-user folder into an install-side "default sounds" folder,
so updates can refresh them; user customs are Browse-picked file paths and are left untouched
- Startup migration removes both legacy sound folders; verified from oldest (v1.0-v3.3) and v3.4 layouts
Quiet automated launches
- New --silent launch flag mutes all cue sounds and suppresses the startup dialogs (migration notice,
update check, Realtek/mic/missing-sound warnings) so test launches never disturb the user
- run-tests / build-release / SelfTest repointed to the new "default sounds" layout
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Receiver: a plain (Mixed) stream now renders on an active lane when the
receiver is in two-lane (ASIO) mode, instead of being decoded into a ring
nothing reads. Fixes one-way silence ("my mic works for me but not for them").
- Receiver: drift resampler gains a buffer-depth correction term so a bloated
standing buffer eases back to the latency target over a long session.
- App: don't send audio until a peer is genuinely reachable (issue #8); status
no longer shows phantom send traffic with nobody connected.
- App: start-up cue sound (machine-wide toggle + custom path in Preferences).
- App: command-line options (CommandLine.cs) -- --devices, --selftest,
--diagnostics, --log, --close, --profile, --connect, --minimized, --version,
--help. New "Command-line options" manual section (readme.html + MANUAL.md).
- Version 3.9; About-dialog and RELEASE_NOTES updated.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
New profile: a File-menu item + Ctrl+N that loads a fresh blank template as a
new unsaved session via a LoadBlankTemplateNext handoff to Program.cs's relaunch
loop — reachable even when "start with a specific profile" boots past the picker
(issue #6). Offers to save the current profile first if dirty; deliberately
silent (no profile-switch cue).
Renamed the user-facing "blank template" to "New profile": the picker's synthetic
entry (now a distinct marker TYPE, collision-safe against a real profile named
"New profile"), the window title ("RemSound — New profile"), and the manual.
Fixed the password-mismatch warning flashing away: it's raised from the 1 Hz
statusTimer, which kept firing into the modal loop and rebuilt the peer lists
(SyncAllPeerLists) under the dialog, knocking it out of the foreground. Now the
tick is frozen while it's up, it's routed through ForegroundDialog, and a
re-entry guard ensures one warning that stays put. Audited: it was the only
popup raised from a recurring timer.
Docs: manual section "Connecting to one specific IP address (and only that one)"
explaining by-name vs by-fixed-IP and that a profile saves the exact address
(issue #7 — functionality already existed); About box + RELEASE_NOTES for v3.8;
MANUAL.md regenerated.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Coalesce capture-engine rebuilds (CompositeCaptureBackend): a swap-triggering
source change now arms a 250ms debounce timer and re-arms on each further
change, so a flap or quick reconfiguration produces ONE rebuild to the final
state instead of a burst (Andre's 16:40 four-rebuilds-in-33s crackle). In-place
updates still apply immediately; a pending rebuild whose target flaps back is
cancelled.
Auto-tune (TickRoute) now keys off the SECOND-highest arrival-gap/render-gap
second in the lookback window instead of the single worst, so a lone ~1s
OS/driver stall no longer balloons the buffer to the 200ms cap (the 16:51
trim burst); sustained jitter still reacts at full speed. Logs both gap-max
(true peak) and gap-used (value acted on).
Mic-privacy detector widened: also catches a per-app Deny aimed at this exe
under ConsentStore\microphone\NonPackaged\<exe>, the HKLM NonPackaged gate,
and the Group-Policy/MDM force-deny (AppPrivacy LetAppsAccessMicrophone=2) —
the block shapes that silence WASAPI capture while ASIO sails past, and that
the old three-value check missed.
Forensic instrumentation so the next log proves what happened: capPeak=
(loudest pre-encode sample, per lane, on the diag line), mic-privacy verdict
logged at startup, ui: capture tick/untick events, and device-event: lines for
Windows endpoint changes.
Docs: mic-privacy + auto-tune sections updated in readme.html, MANUAL.md
regenerated, About-box changelog and RELEASE_NOTES for v3.7.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Replace the generated cmd.exe + robocopy update helper — which silently
failed on some machines — with an in-app C# installer:
* Stage the new version to a per-user temp folder off the install and run
the new RemSound.exe from there, so nothing in the install is locked by
the updater itself.
* Wait for the old process to fully exit (real WaitForExit), then
back-up-and-swap files in C# with retry + rename-aside; roll the install
back to the previous version on any failure, so a failed update can never
leave a half-installed RemSound.
* Log every step to updater.log; clean up old stages and legacy batch
artefacts on launch. Removed the old BuildInstallScript batch generator.
Route the "RemSound is already running" dialog and its follow-up message
through ForegroundDialog so they surface in front from a background-relaunched
copy, matching the earlier post-update fix.
Docs: rewrite the readme update sections for the new mechanism, regenerate
MANUAL.md, refresh the About-box changelog and RELEASE_NOTES.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Recover an unplugged/replugged output sound card automatically (issue #5):
detect the dead WASAPI device and remember the receive-output selection so it
re-ticks and re-opens when the card returns.
- Adaptive per-card WASAPI buffer target sized to each card's pull chunk, held
stable so it never flits about under CPU/network load.
- Consolidate all per-user data (config, profiles, logs, sounds) into one
"user settings and logs" folder; migrate every older layout; exclude it from
the updater so custom cue sounds now survive updates.
- Mic-privacy detector: warn once when a Windows-blocked mic is switched on, or a
profile loads with one already on.
- All warning/notice dialogs now come to the foreground even when minimised.
- Apply volume + mute on profile load (were saved but not restored).
- Crash-safe (atomic) profile/config saves.
- Fix two resource leaks (push-mode capture MMDevice; UPnP DeviceFound handler).
- Remove dead code (baseline-diff machinery, dead ASIO probes, no-op stubs).
- Docs: readme.html, MANUAL.md, About-box changelog and release notes for v3.5.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Builds on the v3.4 freeze (dd70613) with the fixes and tuning from live testing,
plus the v3.4 documentation pass.
Audio (receiver):
- Per-device WASAPI drift correction in MultiOutputPlayout. A pull-side resampler
(mirroring SessionPlayout's proven corrector) holds each output device's buffer at
a fixed low depth, cancelling the slow clock drift that made WASAPI peers "lag
apart" over long sessions. Feed-forward clock-ratio measurement plus a gentle
depth-restoring term; the first measurement window is discarded because WASAPI
start-up priming poisons it. ASIO already self-corrected; this brings WASAPI level.
- Output device buffer requested at 5 ms (WASAPI clamps it up to the device's minimum
period, ~10 ms) instead of 15 ms, since the corrector keeps it fed — a free saving.
UI / accessibility (MainForm, Program):
- Startup notices (what's-new About box, Realtek warning) now run one at a time via a
single sequence instead of separate BeginInvokes, so they no longer stack into
nested modals that couldn't be closed. The loading splash is skipped for a
tray-bound quick switch.
- Quick profile switch keeps RemSound in the tray if it was there, and plays the
switch cue immediately on click.
- Profile-switch cue now plays on click for every switch path (recent menu, quick
switch, File > Open) and no longer on a fresh start into the first profile. It was
also previously dead on the rebuilt form (pendingProfile was nulled first).
- Realtek ASIO toggle's accessible name now reads "Enable"/"Disable" to match the
visible text, instead of "Toggle" (screen reader read the wrong word).
Docs (plain English):
- RELEASE_NOTES.md: v3.4 entry.
- About dialog: v3.4 "what's new".
- readme.html (the canonical bundled manual): quick switch, the hotkey read-outs, the
new profile-menu-open cue, Realtek auto-detect/disable, and the config-folder path.
- MANUAL.md regenerated from readme.html via sync-manual.py so the two stay in sync.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Headline: all audio is now encrypted (AES-256-GCM), keyed by a per-profile
password. Mandatory — v3.3 only interoperates with v3.3+.
Encryption
- RemSoundCrypto (Core): PBKDF2 key derivation, AES-GCM encrypt/decrypt
(low-alloc, into-span), password fingerprint, light on-disk obfuscation.
- Wire: SenderLane encrypts the audio payload (PCM split across parts when the
+28 overhead crosses MTU); AudioReceiver/StreamSession decrypt via a shared
single-thread AudioDecryptor. Fingerprint piggybacks on the Format packet
(offset 36, backward-compatible) so a peer can detect a password mismatch.
- Profile.Password (scrambled), carried through BuildCurrentProfile; MainForm
derives + pushes the key/fingerprint to sender + receiver (RecomputeAudioCrypto).
- UX: ask-for-password on profile create; File -> Change this profile's password
(ProfilePasswordDialog); Options -> Profile passwords (manager); a gate that
prompts before streaming without a password; and a clear "passwords don't
match" / "peer needs to update" message driven by the fingerprint.
Cue fixes
- CuePlayer (NAudio) replaces System.Media.SoundPlayer, which silently failed
on the 96 kHz/24-bit cue WAVs (and any custom file) — cues now play reliably,
resampled to 48 kHz/16-bit. Also fixes the Preferences preview button.
- Connect/disconnect cues now audio-gated with hysteresis: connected when audio
flows OR heartbeat healthy; lost only when audio stops AND heartbeat
unreachable. Kills false disconnects and the receive-only "no cues" case.
- Honest cue logging (played / muted / not loaded).
Smaller
- Endpoint stickiness: keep the audio target pinned to the heartbeat-proven
address instead of chasing a multi-homed peer's other (unreachable) address.
- "Online/offline" label now audio+heartbeat aware, not discovery-only.
- "Show what's new after each update" preference (on by default).
Docs: About v3.3 block, RELEASE_NOTES, README (encryption as a headline),
manual section 12 "Passwords and encryption" (+ renumber), MANUAL.md regenerated.
Version 3.2.0 -> 3.3.0.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- New "Update sound" cue (CueId.Update / update.wav). Plays just before an
update starts installing, on every path (manual, background-silent,
startup-silent), so a silent background update gives an audible heads-up
before RemSound closes to restart. Per-profile mute + custom-sound override
in Preferences, same infrastructure as the other cues:
* Profile.EnableUpdateCue + RemSoundSettingsStore Load/Save + round-trip
* MainForm updateSound field, TryLoadCueSound, play in InstallUpdateAsync
gated by LoadEnableUpdateCue
* PreferencesDialog "Update sound" CueRow + ResolveCueFilePath mapping
* update.wav shipped in sounds\ via csproj Content
- Single-instance "switch to the running copy" now actually brings the window
to the front. The second copy grants the running copy foreground rights via
AllowSetForegroundWindow before signalling, and lingers briefly so it can
raise itself before we exit — without this, Windows' foreground lock left
the running window only flashing in the taskbar (Ed's report).
- Docs: About box v3.2 block, RELEASE_NOTES.md, manual cue section (now seven
cues, with the update cue described), MANUAL.md regenerated.
- Version bumped 3.1.3 -> 3.2.0.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Fixes the chained-fault runaway Andre hit after an update (multiple copies
stacking, audio climbing to deafening, terminal kill to recover).
- Single-instance lock (SingleInstanceCoordinator + SingleInstanceDialog,
wired in Program.Main). A named mutex makes two copies impossible. A second
launch offers: switch to the running copy (default; surfaces it from the
tray via a named activation event), or force the running copy closed and
start fresh (Process.Kill, retried elevated if the target is elevated).
This is the structural fix that makes the stacking runaway impossible.
- Prompt-free update exit. InstallUpdateAsync sets updatingInProgress before
Application.Exit(); the close path's skipPrompt now honours it, so no
unsaved-changes dialog (whose default button is Cancel) can abort the
update's restart.
- Read-only persistence fix. BuildCurrentProfile now carries
currentProfileReadOnly into the saved snapshot. Previously a deliberate
save of a locked profile wrote ReadOnly=false, silently unlocking it on
disk — which re-armed the save prompt that then blocked the update.
- In-process double-install guard. updateInstallStarted stops the ~4 s
startup check and the background poll both staging an install + helper.
- Docs: About box, RELEASE_NOTES.md, readme.html + MANUAL.md ("Only one copy
of RemSound runs at a time").
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Tray icon now re-registers itself (hide+re-show) whenever the meaningful
state changes — peer connect/drop, send/receive toggle, recording
start/stop — so the name a screen reader announces stays in step with
the live state. Fixes the persistent "no peers" then "1 peer" double
announcement that the old "show window then minimise again" trick used
to clear by hand. Same root cause as the v3.1.1 stuck-tooltip fix, just
exposed when the state changes a moment after the icon appears.
- Recording shows as a plain "recording" flag in the tray rather than a
live timer. A ticking timer would have either flickered the icon once a
second or left a screen reader announcing a stale time next to the live
one. Removed the now-dead FormatRecordingElapsed helper.
- Bundles the earlier Win7 updater fix (6cbde0d): a failed secure
connection is no longer mislabelled as "you're up to date".
- About box, RELEASE_NOTES.md, readme.html and MANUAL.md updated to match.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Bug: if v3.1 installed via auto-update on a profile with StartMinimised
on, the tray icon's hover tooltip got stuck at the initial "RemSound -
starting up" string. The snapshot tick was running and SetTooltip was
being called every second with the live state, but Windows shell kept
showing the original cached text on hover. The fix-by-workaround was a
hide-then-re-show cycle which forced the shell to rebuild the icon
registration with the latest NotifyIcon.Text.
Root cause: NotifyIcon.Text values set BEFORE the icon's first
NIM_ADD (i.e. while Visible=false) become the shell's "initial"
tooltip when the icon eventually appears. Subsequent NIM_MODIFY calls
from text changes DO propagate, but the shell tends to keep showing
the original text on hover - presumably a tooltip-cache eviction
quirk. In the resume-after-update-with-StartMinimised flow, the
window briefly shows then BeginInvokes a Minimize that flips
Visible=true before the snapshot timer has had a chance to fire, so
the shell registers with the stale "starting up" string.
Fix: drop the hard-coded "starting up" initial text from the
controller ctor entirely. The controller now takes a Func<string>
buildTooltip callback from MainForm and calls it in Minimize() right
before flipping Visible=true, so the shell's NIM_ADD sees current
live state instead of a stale string. The 1 Hz snapshot tick keeps
working for ongoing live updates while the icon is visible.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Two new cues join the existing connect / disconnect / record-start /
record-stop set:
* profile-save cue (sounds\save.wav by default) fires in
SaveProfileTo after a successful Save or Save As. Honours the
Profile.EnableSaveCue per-profile flag.
* profile-switch cue (sounds\profile.wav by default) fires in the
MainForm Shown handler after a profile finishes loading - covers
both startup-with-profile and mid-session profile switches.
Honours the Profile.EnableProfileSwitchCue flag. Because cue
loading runs AFTER settings.ApplyProfile in the ctor (line 542),
the profile being entered determines which sound plays - not the
one being left, exactly as Ed asked.
The audio cue UI in PreferencesDialog stays as a CheckedListBox (up /
down navigates, Space toggles) with TWO action buttons below that
operate on whichever cue is selected:
* Play [cue name] (Alt+P) - previews via SoundPlayer.Play on the
resolved path (custom override if set, default in sounds\
otherwise). Independent of the tick state.
* Browse for [cue name]... (Alt+B) - opens a WAV picker. If the
user picks a file inside RemSound's own sounds\ folder, it's
treated as "use default" and the override is cleared - avoids
pinning the user to a specific shipped default that a future
release might replace. Right-click "Use default sound" reverts.
Custom cue paths AND enable flags are per-profile. Lives on
Profile.CustomCuePaths (Dictionary<string,string>) and the per-cue
EnableXxxCue bool? properties. Cache mirror in
RemSoundSettingsStore.Settings.
All default WAVs moved from the install-root flat layout into a
sounds\ subfolder (csproj Content rules updated). save.wav and
profile.wav are bundled defaults.
Tray menu rewritten (MainFormTrayController) per Ed's spec:
* Show RemSound (W) - now uses Win32 SetForegroundWindow after the
standard Activate() because WinForms Activate is blocked by the
foreground-lock when invoked from a tray-menu click, which left
screen-reader users having to Alt+Tab to reach the restored
window.
* Enable sending (S) / Enable receiving (R) - tickable, reflect
current state, TOGGLE rather than always-on.
* Profiles (P) - submenu populated from AppConfig.RecentProfiles
with the same &1..&5 mnemonics the File menu uses. Pre-populated
once at construction so WinForms recognises it as a submenu and
fires DropDownOpening - originally I relied entirely on the
open event, which the framework skipped for items with no
DropDownItems, producing the "Profiles does nothing" bug.
* Exit (X).
Tray tooltip now built dynamically from snapshot tick (1 Hz):
"RemSound - [recording for MM:SS,] N peer(s), sending (lane),
receiving (lane)". Recording timer only included while
RecordingController.IsRecording is true (added
RecordingStartedUtc accessor for the elapsed calculation). Lane is
derived from which device-list ticks are active, not just the audio-
mode setting, so a BothIndependent user with only WASAPI inputs ticked
honestly reads as "sending (WASAPI)".
Fixes:
* Initial tooltip "RemSound" produced a "RemSound RemSound" read on
NVDA because the process name and tooltip matched. Set to
"RemSound - starting up" so the duplicate disappears.
* Recent profile menu items no longer carry a "Recent profile N:"
AccessibleName prefix in either the tray submenu or the File
menu's Recent profiles - now just the profile name. Number-key
mnemonics (&1..&5) untouched.
Manual (readme.html) updated: new section 17 "Audio cue sounds"
documents all six cues, the Play/Browse buttons, the right-click
"Use default sound", and the per-profile semantics. Sections 17-21
renumbered to 18-22. New "System tray icon and its menu" subsection
inside section 4 documents the redesigned right-click menu and the
hover tooltip. MANUAL.md regenerated via sync-manual.py. About box
gets a v3.1 block at the top. RELEASE_NOTES.md fully rewritten for
v3.1.
No wire format change - v3.1 talks to other v3.0.x machines exactly
as before.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Bug: Andre reported audio latency feeling laggier after long sessions
on his Win10 desktop receiving Opus from his laptop. His 23-hour log
showed working set climbing from 83 MB at startup to 3.5 GB at the
end, with the managed heap staying tiny (~5-7 MB) the whole time.
CPU climbed alongside (from steady-state ~7% mid-session to peaks of
~60% by the end) and audio threads ended up doing ~4x the work they
did at the start. Andre's perception of latency drift was the CPU
pressure showing up in audio scheduling, not the buffer itself
growing (bufAvg stayed roughly stable at 25-28 ms).
Root cause: Concentus.Native (introduced in v2.2 / shipped in v3.0)
returns concrete NativeOpusDecoder / NativeOpusEncoder objects that
implement IDisposable and own native libopus state. Three call sites
were taking the IOpusDecoder / IOpusEncoder interface reference and
never calling Dispose:
* StreamSession.Dispose — comment literally said "IOpusDecoder has
no Dispose; nothing else to free", which was correct for the
pure-managed Concentus.OpusDecoder pre-v2.2 but stopped being
correct the moment we added the native binding
* OpusEncoderState.Dispose — same misleading comment, same bug
* SenderLane.OnCodecChanged — overwrote the existing encoder field
without disposing the old instance on codec change
Compounding factor: Program.Main sets GCSettings.LatencyMode =
GCLatencyMode.SustainedLowLatency to keep audio scheduling smooth
(it suppresses gen2 collections). That's correct for the hot path
but it ALSO suppresses the finalizer pass that would have released
the leaked native handles as a backstop. Because the managed heap
stayed tiny, the GC never saw enough pressure to force a gen2 pass
on its own, and the native state piled up indefinitely. Multi-output
receive multiplied the per-output growth.
Fix is in two parts:
1. Call (... as IDisposable)?.Dispose() at every release point —
StreamSession.Dispose, OpusEncoderState.Dispose,
SenderLane.OnCodecChanged before overwrite, AudioRecorder's
Concentus.Oggfile-backed OpusOggFileWriter.Dispose. The
as-IDisposable cast handles both the native and the pure-managed
path transparently (managed-only IOpusDecoder isn't IDisposable;
the as-cast yields null and the null-conditional is a no-op).
2. Periodic native-memory reaper in MainForm.SnapshotLogIfDue — once
every 300 snapshot ticks (~5 min), run
GC.Collect(2, Optimized, blocking, !compacting) +
WaitForPendingFinalizers on a background Task.Run so the gen2
work doesn't hitch the UI thread. Audio threads are separate and
unaffected. Serves as belt-and-braces for any future code path we
forget to wire and for cleaning up any per-call native scratch
the underlying library might accumulate that isn't owned by a
single .NET wrapper.
Expected behaviour after fix: working set settles around 100-200 MB
on a typical receive session and holds roughly flat for as long as
the app stays running. CPU stays at its early-session baseline
across multi-hour sessions. Andre's "latency drift" symptom should
disappear.
Wire format unchanged; same codec list, same UI, same defaults.
v3.0.2 talks to other v3.0.x peers exactly as v3.0 / v3.0.1 do.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Bug: ticking the "Automatically open my router for incoming connections
(UPnP)" box in Preferences could freeze the WinForms message pump until
Mono.Nat's NatUtility.StartDiscovery() returned. On Andre's setup it never
did — audio kept flowing (audio threads are independent of the UI thread)
but the window stopped repainting, the system-tray hotkey stopped
responding, and the only way out was Task Manager.
Pre-existing latent bug in the v2.1 UPnP code; we just shipped without
anyone exercising the path on a problematic network (multiple adapters /
VPN / SSDP-swallowing router).
Fix: three call sites moved off the UI thread via Task.Run -
* MainForm OnShown (startup re-enable from saved AppConfig.UpnpEnabled)
* MainForm Preferences applyUpnpEnabled callback (user ticks the box)
* MainForm power-resume handler (Refresh() after sleep/wake)
RouterPortMapper.Start() returns "immediately" only when StartDiscovery
returns quickly; on a slow network it can block synchronously for many
seconds. Same is true of Stop()'s socket teardown and Refresh()'s
teardown-then-restart sequence. All three are now safely backgrounded.
StatusChanged is unaffected - it already fires on the mapper's own thread
and the PreferencesDialog handler BeginInvokes back to the UI thread.
Live status label updates correctly during the new background discovery.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* New "Opus, live latency" codec mode: 2.5 ms frames (120 samples/ch at 48 kHz)
via the float-input encode path. End-to-end codec delay drops to ~5 ms (vs
~12.5 ms at standard 10 ms Opus). Test on LAN: 400 pps/lane, zero missed /
reordered / duplicate packets, ~15 ms one-way saved end-to-end.
* Wire-format change: AudioFormatInfo.FrameDurationMilliseconds renamed to
FrameSamplesPerChannel (int sample-count at announced sample rate). Removes
the lossy 48000*ms/1000 conversion that couldn't represent 2.5 ms. v3 <-> v3
exact; v3 <-> v2 still passes audio (Opus decoder is self-describing from
packet TOC) but v2 side over-sizes its buffer wildly. v2.x profiles auto-
migrate via <120 sentinel rule in RemSoundSettingsStore (anything below 120
is treated as legacy ms and multiplied by 48). Profile JSON key kept as
OpusFrameMilliseconds via [JsonPropertyName] so old profile files still load.
* Codec dropdown rebuilt with use-case names: "PCM 48K 24 bit - uncompressed",
"Opus, broadcast quality - loss tolerant", "Opus, live latency - for jamming
and monitoring". Middle 10 ms option retired; saved 480-sample profiles
collapse to broadcast quality (safer-side default).
* Profile auto-resume after self-update: RemSoundUpdater writes a one-shot
_resume-after-update.txt sentinel containing the active profile title before
exit; Program.Main reads + deletes it on next start and silently loads that
profile, skipping the picker. Helper batch's robocopy /XF excludes the
sentinel and the failure-branch cleans it up if the install aborts. Falls
through to normal startup behaviour (StartWithProfileTitle or picker) if the
sentinel is missing, empty, or names a profile that no longer exists.
* Read-only profile saves now go through on explicit Ctrl+S / File -> Save
with a one-time TaskDialog warning ("Save anyway" / "Cancel" + Do-not-show-
again). Lock continues to suppress the automatic unsaved-changes prompt on
close / profile switch (its main job). AppConfig.SaveOnReadOnlyMessageSuppressed
renamed to SaveOnReadOnlyWarningSuppressed; v2.x suppression flag is silently
discarded since the behaviour changed and the user needs to see the warning
once on each machine.
* Manual (readme.html) updated: codec table rewritten with the three new
choices and corrected bandwidth figures, send-rate description updated, new
sections "The same profile picks up automatically after an update" and
"Saving on purpose while a profile is locked".
* Subsumes the never-separately-released v2.2 work: native Opus encoder
(~97% less per-second memory churn on Opus send path via Concentus.Native),
efficiency tidy-ups (item 4 ASIO probe rate, item 6 WaitHandle, item 7
snapshot cache, items 14/16 heartbeat + discovery), legacy cleanup
(items 30/34/35/36: KeepAlive infrastructure, drift drop/repeat/accumulator
fields, fan-out cache stat). New diagnostic columns cpu/memMB/wsMB/
allocKBps/captureMs/sendMs/recvMs/renderMs gated on Enable-logs.
About dialog updated with v3.0 block at top; v2.2 block retained for the
subsumed work.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Single biggest change: added the Concentus.Native NuGet package. Concentus
2.0+ auto-detects native libopus at runtime and routes encode calls
through it; encoder state lives on the C side and is reused across calls
rather than `new`ing ~15 working buffers per call (Concentus issue #22,
open since 2018). Measured on the desktop test at 15:36:55 — Opus 10 ms
allocation rate dropped from 4,625 KB/s to 108 KB/s, a 97.7% reduction.
Process CPU dropped from 4.7% to 1.6% in the same config. Audio is bit-
for-bit identical (it's literally the same encoder, just better
packaged). `OpusEncoderState.cs` itself unchanged on the call site.
Diagnostic / measurement layer (gated on Enable-logs, zero cost when off):
* ProcessSelfMeter: CPU%, managed heap MB, working set MB, allocation
rate per second, GC counts per generation
* Per-thread work-time counters: captureMs / sendMs / recvMs / renderMs
expressed as milliseconds of CPU consumed by each audio thread per
second
* Inter-packet arrival gap measured at the user-space UDP socket
(rxNetGapMs) — pinpoints whether arrival jitter is in the network or
our own dispatch path
Small efficiency wins (each one was small but cumulative):
* deviceRefreshTimer interval 1s -> 3s (item 4)
* WaitHandle array allocations eliminated in MixingEngine.MixLoop and
MultiOutputPlayout.ProduceLoop (item 6)
* MultiOutputPlayout caches its output-buffer snapshot and only rebuilds
on SetOutputDevices, instead of rebuilding every 10 ms (item 7)
* HeartbeatService reuses an outbound ping byte[] instead of allocating
per send (item 14)
* PeerDiscoveryService caches broadcast addresses and invalidates on
Windows' NetworkChange event instead of walking all NICs every 1.5 s
(item 16)
Legacy / dead-code removal:
* KeepAlive packet's implementation (struct, enums, writer, reader, size
constant) — all dead since HeartbeatService landed 2026-05-06. Kept
the RemPacketType.KeepAlive enum value and silent-drop dispatch for
wire compat with any pre-2026-05-06 build still in the wild (item 30)
* driftDropFramesTotal / driftRepeatFramesTotal fields and accessors —
Phase-2 splice corrector relics, never incremented since Phase-4
resampler design landed; backed five always-zero diag log columns
(items 34 + 35)
* DriftAccumulator (always returned 0) — same shape, removed alongside
the driftAcc= column (item 35)
* TakeMaxFanOutCacheBytes / Ms + fanCacheMs column — FanOutSource was
retired in May (item 36)
Project documentation:
* RemSoundefficiency.md added as the canonical record of the efficiency
analysis, every item's status, and the measured wins from this round
* Honest item-by-item review of the original 50-item list — several
items I had sized optimistically in the original analysis turned out
to be already-done (item 20), already-optimal (item 22), or below
the meter floor (items 9, 15, 17, 25). Recorded so future passes
don't re-investigate.
Wire format and audio pipeline unchanged from v1.5 onward — v1.5 through
v2.2 peers interoperate.
Headline features:
* Automatic router port opening (UPnP / NAT-PMP / PCP). Opt-in via
Preferences; surfaces external address + carrier-grade NAT detection.
* Lock profile (read-only). New File-menu tick that makes a profile
load-only — session changes don't persist, no save prompt on close.
Unblocks unattended shutdowns (NVDA gone, remote dropped, hibernate)
where the existing save prompt could deadlock.
* Check for updates on startup (default on) + brief countdown notice
before silent updates install, so a launch-time update doesn't make
the app silently vanish.
* "Cue sounds" -> "Audio cue sounds" label clarification.
Bug fixes:
* No sound after the computer wakes from sleep. PowerResumeHandler
rebuilds the audio backend automatically on resume; brief
"Reconnecting to audio driver" splash during the rebuild.
* Receiver audio silent after waking from hibernate. RefreshAudioDeviceLists
now treats a transient ASIO probe failure (returns -1/-1 because the
driver is mid-teardown / mid-reinit) as "retry next tick" instead of
clearing the user's tick selection.
Diagnostic-only changes (gated on the existing Enable-logs checkbox,
zero cost when off):
* AudioStepProbe split into cross-buffer vs within-buffer maxes so log
inspection can tell a real-content sharp transient apart from a
pipeline-boundary glitch. Plumbed through every probe owner.
* New rxNetGapMs + gc0/gc1/gc2 delta columns in the diag log to split
receive-side jitter into network-layer vs managed-runtime causes.
Files touched: RELEASE_NOTES.md + readme.html + 24 source files across
RemSound.Core / RemSound.Sender / RemSound.Receiver / RemSound.App.
Three new app files: PowerResumeHandler, RouterPortMapper,
UpdateInstallNoticeDialog.
Wire format and audio pipeline unchanged from v1.5 onward — v1.5
through v2.1 peers interoperate.
Opening an ASIO driver takes 1-3 seconds, synchronously, during MainForm
construction — confirmed in logs as a ~2.8s dead gap on an ASIO-profile
launch (a WASAPI-only launch is ~131ms for the same stretch). During that
gap the main window is blank / "Not Responding" and looks hung.
New AsioLoadingSplash shows a small "Loading audio driver, please wait..."
window on its OWN dedicated STA thread with its own message loop, so it
stays painted while the main thread is blocked opening the driver.
Program.cs starts it before new MainForm() and dismisses it after.
Deliberately, the ASIO driver open stays on the main UI thread — that
STA/message-pump thread is what ASIO/COM drivers are most compatible with,
and moving the open off it risks breaking drivers that can't be tested.
Only the cosmetic splash moved to a side thread; no ASIO/driver code is
touched. Splash shows only for profiles with an ASIO driver selected;
WASAPI-only profiles build fast and get no splash.
Version bumped to 2.0.0 to mark the milestone.
No wire-format or audio-pipeline changes — v1.5 through v2.0 interoperate.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
The install helper's robocopy line was:
robocopy "{stagingRoot}" "{installDir}" ...
installDir is AppContext.BaseDirectory, which always ends in a directory
separator, so the destination argument was a quoted path ending in a
backslash: "D:\...\publish\". Windows command-line parsing reads the \"
as an escaped quote, so robocopy never received a valid destination,
rejected the command line, and exited 16 (usage error, nothing copied)
instantly. The auto-updater has never worked in any release because of
this — v1.0-v1.2 failed silently, v1.3+ detected the failure and wrote
update-failed.txt but never fixed the robocopy line.
Fix: BuildInstallScript now strips trailing separators —
stagingArg = stagingRoot.TrimEnd('\','/'), installArg likewise — and
the robocopy line uses the trimmed forms. Verified by running the
corrected robocopy against real staged files: exit 3 (success), files
copied.
The broken helper is baked into every shipped build including v1.8, and
the helper is generated by the running version — so v1.8 and earlier
cannot auto-install v1.9. v1.9 must be installed by hand once; from v1.9
onward the updater works.
No wire-format or audio-pipeline changes — v1.5 through v1.9 interoperate.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Updater (RemSoundUpdater.cs), all from Andre's feedback:
* CheckForUpdateAsync now requests /releases?per_page=100 instead of the
default 30-item page, so a burst of server-vX.Y relay releases can't
push the newest client release off page 1.
* The install helper's robocopy now excludes remsound.config.json and the
logs / profiles / recordings folders — an update replaces app files
only and can never overwrite the user's own config or data.
* On a successful update the helper now also deletes _update-helper.log
and any stale update-failed.txt (the _update folder was already
removed), leaving a tidy install folder. The failure branch still keeps
them all for diagnosis.
* update-failed.txt rewritten as plain user-facing instructions: numbered
steps, no brand names, names the real _update folder, no robocopy
jargon. The exit code now goes to _update-helper.log only.
Manual (readme.html): rewritten in plain language — developer jargon
removed or explained in everyday terms — and a second pass removed the
keystroke-navigation choreography and screen-reader narration from the
prose. The Keyboard shortcuts section and all shortcut reference are
kept intact.
No wire-format or audio-pipeline changes — v1.5 through v1.8 interoperate.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
The client and the relay server are published from the same GitHub repo;
the server's releases use "server-" prefixed tags. RemSoundUpdater hit
/releases/latest, which is repo-wide — when a server release was newest,
the updater fed "server-v2.3" to ParseTag (-> a bogus 0.0.3) and concluded
"up to date", silently skipping real client updates.
CheckForUpdateAsync now lists /releases and picks the highest-versioned
release whose tag is a RemSound client tag (new IsClientReleaseTag: after
an optional leading "v", first char must be a digit). Drafts and
pre-releases are skipped. The server-side updater already filters to
"server-" tags, so client + server coexist in one repo cleanly.
Also rewrites build-release.ps1 with a data-safety check: it publishes to
a fresh staging folder and aborts the release if any logs/, profiles/,
recordings/ folder, .log file or remsound.config.json is present in the
staged output or the finished zip — preventing a repeat of the v1.5/v1.6
zips that shipped with developer logs and profiles.
No wire-format or audio-pipeline changes — v1.5/v1.6/v1.7 interoperate.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Three reliability fixes. Wire format and audio pipeline unchanged from
v1.4 / v1.5 — all interoperate.
Peer address recovery:
* When a tracked peer goes Unreachable (its resolved address — often a
stale DNS / Pi-hole record, or a peer that rebooted onto a new IP) but
the same peer is still heartbeat-pinging us from a different address,
RemSound now adopts the live address instead of transmitting to a dead
one. HeartbeatService records untracked ping sources; MainForm's
TryAdoptLiveHeartbeatAddress (1 Hz) re-points the sender, heartbeat
tracking and receiver allow-list. Conservative: fires only on the
unambiguous one-unreachable-and-one-source case, private-range (RFC1918)
addresses only so a relay can't hijack the sender, 10 s cooldown.
Reconnect crash:
* Fixed IndexOutOfRangeException in MainForm.SyncConnectedList. A churny
peer-list rebuild (peer reboot) left SelectedIndex pointing past the
rebuilt item array; the 1 Hz status timer read SelectedItem and crashed
the app. New SafeSelectedItem bounds-checks the index; applied to all
three timer-driven sync methods. The status tick is also wrapped in
try/catch so a transient WinForms hiccup logs instead of crashing.
Long-run memory / CPU leak:
* A receiver left running for hours grew to gigabytes and climbing CPU.
Decoder sessions orphaned by peer reconnects were not reaped — every
reconnect mints a fresh (endpoint, streamId) key, and PruneIdleSessions
silently skipped sessions whose PlayoutEngine lookup missed. Rewrote it
to reap on each session's own LastWriteUtc (no cross-dictionary lookup),
added a hard MaxLiveSessions cap as a backstop, and a "stream sessions
live: N" diagnostic line. Bounds both memory and render-thread CPU.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Bug fixes:
* BothIndependent recording was double-tapped — when both WASAPI and
ASIO outputs were ticked, recordings came out garbled and ~2x the
expected duration. AudioRecorder now uses four per-lane rings
(sent-wasapi, sent-asio, recv-wasapi, recv-asio) plus a writer-
thread mix step that drains min(wasapi, asio) frames and sum-mixes
with the soft-tanh limiter. Tap signatures gained a RenderRoute
parameter; Mixed maps to the wasapi slot.
* A peer announcing on the WASAPI lane was inaudible when the
receiver only had an ASIO output ticked (and vice versa). The
session opened, samples flowed into the SessionPlayout ring, but
ReadForRoute(AsioLane) skipped any session whose Route was
WasapiLane so nothing drained the ring. PlayoutEngine now tracks
per-lane "is this lane backed by a device" via volatile bools
settable through SetLaneActive(RenderRoute, bool), called from
CompositeRenderBackend.SetOutputDevices whenever the device split
changes. ReadForRoute admits orphan sessions when the other lane
is inactive.
Menu reorganisation:
* New Options menu (Alt+O) holds Recording settings (Alt+S), Keyboard
shortcuts (Alt+K, Ctrl+K), Startup behaviour (Alt+T), Preferences
(Alt+P, Ctrl+P). Pre-v1.5 these were scattered across File menu,
Record menu, and inside the Preferences dialog itself.
* Record menu mnemonic moved from Alt+O to Alt+K, rendered as
"Record (Alt+K)" so the chord is visible despite K not being a
letter in "Record". Alt+R is taken by Receive audio.
* File menu — new Recent profiles submenu (Alt+F, R) listing the
five most-recently-opened profiles. Press 1..5 inside the submenu
to jump to a slot. Missing files are skipped from the menu but
kept in storage.
* Rename current profile moves to Alt+M (was R), Minimise to tray
moves to Alt+N (was M).
* Lock to audio clock was Alt+K, now Alt+D.
UX additions:
* Ctrl+O = Open profile (matches the menu chord).
* New global hotkey: Start / Stop recording. Pickable from Options
-> Keyboard shortcuts. Unbound by default. Works system-wide.
Wire format and audio pipeline unchanged from v1.4 — v1.4 and v1.5
peers interoperate.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Ships the dialog reorganisation and mnemonic adjustments from
commit 45b709d. No wire-format or audio-pipeline changes — v1.3 and
v1.4 peers interoperate.
About dialog gets a v1.4 release-notes block; csproj Version
property bumped 1.3.0 → 1.4.0; RELEASE_NOTES.md rewritten with the
v1.4 highlights and a one-paragraph upgrading-from-v1.3 note (clean
auto-update via Help → Check for updates is now expected to work on
Dropbox-installed copies since v1.3's helper hardening took effect).
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Anyone on v1.0 / v1.1 / v1.2 in a Dropbox-synced folder will hit the
auto-updater bug v1.3 fixes — but the fix lives in the running
version's helper, so their installed binary can't use it. Adds a
prominent "Already on an older version and inside a Dropbox folder?
Read this first" section at the top of the release notes with the
manual-install steps, and renames the existing install steps to
"Install (clean machine)" for clarity.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
v1.2's self-updater silently failed when the install folder lived
inside a Dropbox sync path. Dropbox held write locks on the existing
RemSound.exe / DLLs during the brief window between the parent exiting
and the helper script copying the new files in. The helper's robocopy
(/R:5 /W:1) gave up after 5 seconds, and the helper then
unconditionally relaunched the OLD binary — so the user saw the same
version they started with after pressing "Yes" on the install prompt,
with no visible error.
Helper script (BuildInstallScript) changes:
* Robocopy retries bumped to /R:60 /W:1 — up to 60 seconds per file.
Dropbox lock release happens reliably within that window in
practice.
* Robocopy exit code is captured and checked. Codes >= 8 are real
failures. On a failure the helper writes update-failed.txt to the
install folder with the cause + recovery steps, leaves the staging
folder intact, and does NOT relaunch the old binary. Earlier
versions silently relaunched the unmodified old binary, hiding the
failure.
* Helper appends a step-by-step trace to _update-helper.log (in the
install folder), with robocopy's own output included via /LOG+:.
* update-failed.txt, _update-helper.log, and _apply-update.cmd are
added to the /XF exclusion list so the helper's own state files
don't get copied to themselves on a repeat update run.
DownloadAndStageInstallAsync also clears any stale update-failed.txt
at the start of every new attempt, so a successful run leaves the
install folder clean.
readme.html "If install fails" section expanded with the new
update-failed.txt marker file behaviour and the _update-helper.log
location.
Wire format, audio pipeline, and recording feature unchanged from
v1.2 — this is updater-machinery-only.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
New user-facing features:
* Recording. Dedicated Record menu (Alt+O — moved from Alt+R to
avoid clashing with the Receive audio checkbox), Start/Stop on
Ctrl+R, settings dialog, per-profile source / format / bit-depth /
channel-mode / folder. Three source modes (received only, sent
only, both). Files are crash-resilient — a process crash
mid-recording leaves a playable file containing everything up to
the last header refresh (~5 seconds).
* Four output formats, all functional:
- WAV: 16/24-bit PCM or 32-bit float, custom writer with
periodic RIFF re-patching.
- MP3: LAME 128–320 kbps CBR (via NAudio.Lame).
- OGG-Opus: 96–256 kbps VBR (via Concentus.Oggfile, reusing the
Concentus encoder from the wire path).
- FLAC: 16/24-bit lossless (via CUETools.Codecs.FLAKE — pure
managed, no native DLL).
* Recording start/stop sound cues. record start.wav and
record stop.wav play around the recording transition. Played via
System.Media.SoundPlayer to the default Windows output, separate
from the recording pipeline so a normal recording does not contain
the cue.
* Per-cue Preferences. The old single "Mute connect/disconnect
sounds" checkbox is replaced by a CheckedListBox: Connect /
Disconnect / Recording start / Recording stop. Old profiles with
the legacy MuteConnectionCues=true are honoured on first load via
a migration path in the new Load* helpers.
* Receiver-side drift compensation switched from discrete
single-frame splices to a continuous WdlResampler at a smoothed
rate ratio. SessionPlayout.cs rewrite.
Diagnostics (only active with Enable logs ticked):
* Per-stage discontinuity probes — sender raw capture (per backend,
PushModeWasapi + Asio both wired), sender pre-encode (now per
lane in BothIndependent, fixing a cross-stream artefact), receiver
post-decode, post-ring, post-resampler.
* Wire-level packet sequence tracking on each PCM stream — in-order
/ missed / reordered / duplicated counts in the diag log.
* Clipped-sample delta in the diag log.
* New AudioStepProbe in RemSound.Core with per-channel scan helper.
UI changes:
* Record menu uses Alt+O (Rec&ord). Inside the menu, item mnemonics
unchanged (S / T / O / C).
* Auto-tune interval combo label is mode-aware: "Auto-tune latency
interval" in classic modes, "Auto-tune interval — WASAPI and ASIO"
in BothIndependent. The combo's Enabled state now follows EITHER
lane's auto-tune checkbox (was only the WASAPI one — bug).
Wire format and audio pipeline unchanged from v1.1 — v1.1 and v1.2
peers interoperate.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>