docs: state the accidents-not-adversaries threat model; add ROADMAP
The gates in front of destructive operations exist to stop mistakes (stale rosters, typos, racing hosts); stopping a malicious group member is a side effect, not the design goal. Written into README §Security and the man page so future checks are judged by that bar. ROADMAP.md captures the direction: social features (knock, log, clean) over further hardening, plus the explicit resist list.
This commit is contained in:
parent
938491df1e
commit
ff92d812ad
3 changed files with 63 additions and 0 deletions
51
ROADMAP.md
Normal file
51
ROADMAP.md
Normal file
|
|
@ -0,0 +1,51 @@
|
|||
# Roadmap
|
||||
|
||||
Direction, not promises. Two rules govern everything below (README
|
||||
§Security has the long form):
|
||||
|
||||
- **Accidents, not adversaries.** New checks earn their place by
|
||||
preventing a plausible mistake — stale state, a typo, a race — not by
|
||||
closing a hypothetical attack from a friend.
|
||||
- **Social, not mechanical.** New features earn their place by
|
||||
encouraging people to work together in a terminal, not by adding
|
||||
machinery.
|
||||
|
||||
## Next — small, high value
|
||||
|
||||
- **`party knock <name>`** — an uninvited group member pings the host
|
||||
via `write(1)`: "veg wants to join fiesta". `party list` already
|
||||
shows invite-only parties; knock completes that loop. The feature
|
||||
most likely to cause spontaneous pairing.
|
||||
- **`party log`** — per-party transcript via `tmux pipe-pane` into the
|
||||
per-party dir (group-readable so every attendee can grab a copy);
|
||||
`party log --stop` ends it. "What did we do last night?" for
|
||||
collectives, and the audit trail human+AI co-work needs.
|
||||
- **`party clean`** — remove the caller's own crash leftovers (dirs
|
||||
they own whose socket is dead), turning the manual `rm -rf` recovery
|
||||
in host's error message into a verb.
|
||||
|
||||
## Later
|
||||
|
||||
- **Group ergonomics** — the default `party` group needs root and a
|
||||
relog before anyone's first party. On boxes where everyone already
|
||||
shares a group, `host` could offer (or default to) the caller's
|
||||
primary group when `party` doesn't exist. Fits the trust model;
|
||||
costs a little existence-confidentiality.
|
||||
- **One liveness primitive** — fold `is_party_alive` into
|
||||
`party_conn_state`; two concepts where one would do.
|
||||
- **Matrix** — live validation on NetBSD and DragonFly; one
|
||||
interactive attach/role/switch pass per release (automated coverage
|
||||
is all non-interactive).
|
||||
|
||||
## Resist — by design, not by neglect
|
||||
|
||||
- **No network transport.** Same-host is the perimeter; beyond it lies
|
||||
reinventing ssh.
|
||||
- **No per-pane ACLs.** tmux can't enforce them; faking it with hooks
|
||||
would be a leaky abstraction. Document the limitation instead.
|
||||
- **No config files, no plugin system, no ACL syscalls.** One POSIX
|
||||
file that runs on a 30-year spread of UNIXes is the identity; the
|
||||
2026-04 simplification that removed per-OS ACL dispatch is not to be
|
||||
unwound.
|
||||
- **Watch the file size.** Heavy why-comments are a feature; feature
|
||||
growth that pushes the single file far past its current size is not.
|
||||
Loading…
Add table
Add a link
Reference in a new issue