A .cmf is a Standard MIDI track with its instruments packed in front. Creative made it in 1991 for the Sound Blaster's AdLib-compatible OPL2: instead of a General MIDI bank the player needs sixteen bytes of FM registers per patch, and the file carries them. The header is little-endian offsets to the patches, the music and three optional strings; the music is one MTrk's worth of events, running status and all, with four controller numbers of Creative's own, ending on End of Track.
1.0 and 1.1. A 1.0 header stops at 0x24: no instrument count and no tempo, and the count is what fits between the two offsets. 1.1 adds both. The three string offsets are zero when absent, and they point wherever the writer put the text, usually between the header and the patches.
Two OPL2 operators, interleaved: byte 0 is the modulator's first register, byte 1 the carrier's, byte 2 the modulator's second, and so on for five registers each. Then the feedback and connection byte, then five reserved. The registers are the chip's own: AM/VIB/EG/KSR/multiplier, KSL/level, attack/decay, sustain/release, waveform.
Delta time as a variable-length quantity, then a MIDI event, with running
status. Program changes select the patches above by index. Controllers 0x66 to 0x69 are
Creative's: a marker, rhythm mode on or off, pitch-bend range, transpose. The stream ends
on FF 2F 00, and most writers leave one more 0xFF after it.
Four bytes at zero.