Changelog
All notable changes to Iblis are recorded here; the website renders this source directly.
Format: Keep a Changelog, with SemVer versions. Shell, catalog, and plugins ship independently; entries cover shell + repo scaffold unless prefixed.
[0.2.0-alpha.59] — 2026-09-27
This release also delivers 0.2.0-alpha.58, which was tagged but never reached the update feed (its CI publish was blocked by an external quota issue).
Fixed
- Playback no longer freezes on "Buffering" after a pause, and seeking into a part of a long track that has not loaded yet no longer stops playback with a media error. This hit rendered tracks, imported files, and stem audition alike (reported by a beta user; the media pipeline mishandled ranged reads on the app's internal audio streams).
- A paused track no longer shows a stray "Buffering" label when the audio download goes idle.
[0.2.0-alpha.58] — 2026-09-26
Added
- Song idea and Write lyrics in Create. Describe a topic, mood, language, and structure, pick a model, confirm, and get an editable draft; nothing is placed in your prompt or lyrics until you choose Insert, Replace, or Append. Lyrics come back with section tags ([verse], [chorus], [bridge]).
- Local model: use a model server already running on this computer (Ollama, LM Studio, or llama.cpp llama-server) for song ideas and lyrics. No key, no cost, nothing leaves the machine. Turn it on in Settings > Local model, set the port, and use Test connection to list its models.
- OpenRouter can now write song ideas and lyrics with your own key. Every request names the model, shows the price estimate, and asks first; routing uses no provider fallback and no data retention.
Fixed
- Verbose diagnostics no longer re-send the same log lines every 30 seconds while the app sits idle. Each batch now carries only what was logged since the previous one, and an idle app sends nothing.
[0.2.0-alpha.57] — 2026-09-25
Added
- Stem splitting in Library track details: split a track into vocals, drums, bass, and other (or six stems with guitar and piano), watch each step, cancel at any time, and audition the stems together with solo, mute, and per-stem volume. Each stem shows its own waveform and the BPM or key measured on that part; stems can be dragged into a DAW, shown in their folder, exported to a folder, or deleted. The original track is never changed. Separation runs on this computer through a signed stem separator plugin (three Demucs models), on the GPU when available.
- Settings > Stems: choose the default separator and whether separation uses the GPU, the CPU, or picks automatically.
- Detected BPM and key now show as badges in the player and at the top of track details. A track that was never analyzed gets an Analyze button.
- Skins can style stem lanes with six new tokens (
stem.vocalsthroughstem.piano); existing skins get colors derived from their palette.
Fixed
- Track details no longer blink and reload every second while BPM and key detection is running.
[0.2.0-alpha.56] — 2026-09-25
Fixed
- Starting a training no longer fails the disk-space check for a small song folder the wizard already passed. The check at Start now uses the number of songs in your folder, like the wizard does, instead of assuming ten songs, so a machine with enough room for your folder can start its training.
[0.2.0-alpha.55] — 2026-09-25
Security
- Official builds now ignore the developer environment variables that point the app at alternative servers. Only builds you make from source honour them, so nothing on your machine can quietly redirect where your product key or uploads go.
- The YAML parser used by the updater was updated to a version without known CPU-exhaustion issues.
[0.2.0-alpha.54] — 2026-09-25
Security
- Updates are now signed. Before Iblis downloads a new version it fetches a release signature published beside the installer and checks it against a key built into the app; after the download it checks the installer's bytes against that signature again. An update that fails either check is refused and never installs. A new version whose signature is not out yet shows as "being published" until it is.
Changed
- Settings -> Updates and the Home banner say when an update is being checked or is still being published, instead of "downloading".
[0.2.0-alpha.53] — 2026-09-24
Fixed
- Imported
.safetensorsfiles must lay their tensors out exactly as the format's reference loader expects: no gaps, no overlap, no unclaimed bytes at the end. The same rule now runs in the app, on the server, and in the trainer, so a file one of them accepts the others accept too.
[0.2.0-alpha.52] — 2026-09-24
Changed
- Iblis is free. Generation and training no longer need a product key in any build, and a keyless install sees no key banner. A product key now connects the app to hosted services only: community Styles publishing and downloads, and uploads. Settings -> Product key says so plainly.
- Training without a product key is private: the name is checked on this machine, nothing uploads, and the finished style lands in your Styles with a Private badge. With a product key, trainings publish to community Styles as before.
- If a key that used to work ends, Styles shows one dismissible notice that community Styles are paused. Generation, training, and your library keep working.
- Settings -> Updates shows the app version and whether this is an official build or a source build.
Added
- Settings -> Feedback: "Report a bug", "Request a feature", and "Ask a question" open the feedback form on the Iblis website in your browser, with the app version, build, and operating system filled in. You can attach your latest diagnostics reference. Nothing is sent until you submit the form.
Security
- Pre-open-source audit (
docs/security/audit-2026-09-24.md): external links open only https URLs; the app window can no longer navigate away from the app; plugin ids are validated before any remove or rollback touches disk; zip assets refuse symlink and unsafe entries; product keys are validated before they leave the machine and the licensing store is owner-only; verifiers pin the Ed25519 key type;nvidia-smiruns from its absolute path on Windows; web permissions are denied by default.
Changed (repo)
- Every service address now lives in one module,
electron/main/official-endpoints.ts. Only the official release build talks to the hosted services and auto-updates. An app built from source never auto-updates onto official installers, and its activation, uploads, diagnostics, and labs stay off unless the builder configures them. The plugin catalog stays readable in every build; it is public and signature-checked.
[0.2.0-alpha.51] — 2026-09-24
Fixed
- Training: "Check availability" and "Start training" failed inside the app before reaching Iblis, so no training could be reserved or started. Both work again. The processor benchmark's "compare providers" had the same fault and is fixed too.
- Windows: skins installed from the plugin catalog were never applied. They now appear in the skin picker.
- Windows: installing a plugin could fail with "operation not permitted" right after its last file downloaded. The installer now waits for every file to close and retries briefly while Windows Defender scans new files.
- Processor analysis: after one failed save, later results were no longer saved until restart. Each save now stands on its own.
- Accessibility: the active page in the sidebar, red status badges, and the training progress and history text now meet the 4.5:1 contrast minimum.
Changed (repo)
- The unit tests now also run on Windows in CI, which found the Windows bugs above. A Training end-to-end test drives the whole Training page against a stand-in training pack.
[0.2.0-alpha.50] — 2026-09-24
Fixed
- Some valid style and LoRA files (
.safetensors) were refused on import as "a pickle/zip container". It happened to roughly one file in thirty, depending only on the file's header size. They now import normally, and real pickle or zip files are still refused. - Imported
.safetensorsfiles are checked more strictly: a header with invalid text encoding, or with decimal numbers where whole numbers belong, is refused. - A malformed engine description or analysis result from a plugin could stop the check that validates it with an internal error. The check now reports the problem like any other invalid field.
Changed
- Plugin file paths are checked more strictly: names ending in a dot or
space, and any
:character, are refused. On Windows such names can point somewhere other than they appear to. No published plugin uses them.
Changed (repo)
- Shared test fixtures now pin the formats the app and the Iblis service exchange (licenses, the community styles index, diagnostics), and randomized tests cover the app's file and request parsers.
[0.2.0-alpha.49] — 2026-09-24
Fixed
- Accessibility: provider cards on the Plugins page now use the correct heading level, and the version line on Home has enough contrast to read.
Changed (repo)
- The app now has an automated end-to-end test suite that drives the real interface, including creating a track through a test engine. Coverage from these tests counts toward the project's quality floors.
[0.2.0-alpha.48] — 2026-09-24
Changed (repo)
- Internal cleanup with no change in behavior: the app's message handlers are grouped by area, and the last long functions in audio analysis and downloads are split into named steps.
[0.2.0-alpha.47] — 2026-09-24
Fixed
- A track file that could not be read now fails cleanly as a missing file instead of leaving an unhandled error in the background.
- A generation job that failed could leave an unhandled rejection behind in the queue; failures are now always observed and recorded.
- Requests to the engine and to the community service always carry your credentials, whatever form the other request headers take.
- A malformed lease from the licensing server is now treated as invalid instead of being converted to text.
Changed (repo)
- Large internal cleanup with no change in behavior: strict type-aware lint across the app, long functions split into named steps, no import cycles, and SPDX license headers on every source file.
[0.2.0-alpha.46] — 2026-09-24
Changed
- Iblis is now open-source software. The desktop app is licensed GPL-3.0-or-later and the plugin SDK Apache-2.0; the license text and the third-party notices now ship inside every install. The public source repository opens once its review is complete. The website, product keys, and community services stay operated by Meiux Meiux LLC.
- Security platform upgrade. The app now runs on Electron 44 (Chromium 152, Node 24), replacing Electron 33, which no longer received security fixes. The updater and installer tooling moved to electron-builder 26.
- No shared secrets in the app. Diagnostics uploads no longer rely on a password built into the installer; the server now limits uploads by rate and volume and recognizes your product key when you have one. Community uploads authenticate only with your product key.
Fixed
- On machines with few CPU cores, the Safe performance profile could use more threads than Balanced (and on a single-core machine, more than Max). Safe is now always the lightest profile.
Changed (repo)
- Whole toolchain refreshed: pnpm 12, Node 24 for all scripts, Vite 7, TypeScript 6, ESLint 10, Vitest 5, Svelte 5.57, current GitHub Actions; CI now lints, type-checks, tests, and bundles the app on every push.
[0.2.0-alpha.45] — 2026-08-24
Added
- XL Turbo / 8 experiment. When the installed ACE-Step engine pack carries an XL (4B) turbo model, Create offers it as a fixed 8-step experiment beside Turbo / 8, so the two can be compared with the same prompt, seed, and LM blueprint and differ by model only. It is labeled an experiment, never a quality tier; the validated Turbo / 8 recipe always keeps the 2B model whatever order the engine lists them in.
Changed
- (repo) Engine pack 0.1.5 preparation:
acestep.cppre-pinned to master9761469(2026-08-08; the/lmrequest form Iblis sends is unchanged), notices re-staged for the new pins plus the XL turbo model, and the Windows engine build can now publish a pack version's native bytes straight from CI to GCS (just engine-build 0.1.5). The pack itself ships only after Jack's Windows stability run.
[0.2.0-alpha.44] — 2026-08-24
Added
- Engine cards. Create and Settings > Engine now show every installed engine as a card with its signed facts: publisher, license, contract version, install size, models, what it can take (lyrics, styles, length window) and live readiness (running, busy, ready on demand, stopped). Picking a card sets the default engine for new takes only.
- Create fits the engine. The form shows only what the selected engine declares: Vocals, Styles, seed, negative prompt, BPM, key, and beats per bar each appear only when supported; the length field carries the engine's own window. New-style engines render their bounded Advanced controls (on/off, number, choice) straight from the signed descriptor, with help text and limits; ACE keeps its native tuning drawer unchanged.
- Exact target in the Library. A take made with a new-style engine now records and shows its operation, provider, engine family, resolved model and revision, signed-capabilities hash, every advanced control it was rendered with, and which extra outputs were kept.
- Preview outputs are kept. When an engine returns a preview beside the
mix, the validated preview is stored next to the track (
preview.wav) instead of being discarded with the job's staging.
Changed
- New-style engine profiles are labeled by their model instead of the ACE validated/expert wording, and are marked as fixed recipes.
[0.2.0-alpha.43] — 2026-07-22
Added
- Multiple engines, one workstation. Iblis can now host more than one music engine at a time. When several are installed, Create shows an Engine picker; your choice is remembered and every queued take records exactly which engine and version it was made for. Pending takes never silently switch engines — if the engine a take was queued for changes or is removed, the take stops with a clear message instead of guessing.
- Engines start on demand. New-style engines no longer launch at app start. The selected engine spins up when a take needs it and unloads itself after sitting idle, keeping memory free for the engine you actually use.
- Fixture Engine (beta channel). A tiny test engine that renders a real audio sketch in about a second, with its own models, phases, and controls. It exists to prove the new multi-engine plumbing end to end on your machine — including install, switching, cancel, update, and removal — before a real second engine ships.
Changed
- Track provenance for new-style engines records the exact operation, provider, model profile, and signed-capability fingerprint used.
Fixed
- Library View menu no longer repeats "Sort tracks". A hidden helper label was rendering visibly above the sort selector; the panel now shows a single heading, and its selector matches the player options styling.
- Folder names no longer truncate in the Library sidebar. The rename and delete actions previously reserved permanent space beside every folder, squeezing names like "Club Tools" into an ellipsis. They now appear over the row only while you hover or focus it, so the full name and track count stay readable.
Changed
- Tidier Library rows. The folder selector sits in a consistent right-aligned column across rows instead of trailing each row's wrapped metadata, and wrapped metadata lines are spaced more evenly.