party list already shows invite-only parties; knock closes the loop. The knocker can't run any tmux command against the server, so the channel is write(1), the same one invite uses toward guests, except here delivery failure is surfaced: the ping is the whole feature.
1.7 KiB
1.7 KiB
Roadmap
Direction, not promises. Two rules govern everything below (README §Security has the long form):
- Accidents, not adversaries: new checks earn their place by preventing a plausible mistake (stale state, a typo, a race), not by closing a hypothetical attack from a friend.
- Social, not mechanical: new features earn their place by encouraging people to work together in a terminal, not by adding machinery.
Next: small, high value
party log: per-party transcript viatmux pipe-paneinto the per-party dir (group-readable so every attendee can grab a copy);party log --stopends it. "What did we do last night?" for collectives, and the audit trail human+AI co-work needs.party clean: remove the caller's own crash leftovers (dirs they own whose socket is dead), turning the manualrm -rfrecovery in host's error message into a verb.
Later
- Matrix: live validation on NetBSD and DragonFly; one interactive attach/role/switch pass per release (automated coverage is all non-interactive).
Resist: by design, not by neglect
- No network transport: same-host is the perimeter; beyond it lies reinventing ssh.
- No per-pane ACLs: tmux can't enforce them; faking it with hooks would be a leaky abstraction. Document the limitation instead.
- No config files, no plugin system, no ACL syscalls: one POSIX file that runs on a 30-year spread of UNIXes is the identity; the 2026-04 simplification that removed per-OS ACL dispatch is not to be unwound.
- Watch the file size: heavy why-comments are a feature; feature growth that pushes the single file far past its current size is not.