34 lines
1.5 KiB
Markdown
34 lines
1.5 KiB
Markdown
# Roadmap
|
|
|
|
Direction, not promises. Two rules govern everything below (README
|
|
§Security has the long form):
|
|
|
|
- **Accidents, not adversaries:** new checks earn their place by
|
|
preventing a plausible mistake (stale state, a typo, a race), not by
|
|
closing a hypothetical attack from a friend.
|
|
- **Social, not mechanical:** new features earn their place by
|
|
encouraging people to work together in a terminal, not by adding
|
|
machinery.
|
|
|
|
## Later
|
|
|
|
- **Matrix:** live validation on NetBSD and DragonFly; one
|
|
interactive attach/role/switch pass per release (automated coverage
|
|
is all non-interactive). The 2026-07-11 pass covered knock, log,
|
|
clean, and group auto-selection live (two-user on the tmux 3.3
|
|
floor box and OmniOS; auto-selection spot-checked on macOS and
|
|
OpenBSD), so the standing gap is NetBSD/DragonFly plus the
|
|
per-release attach/role/switch ritual.
|
|
|
|
## Resist: by design, not by neglect
|
|
|
|
- **No network transport:** same-host is the perimeter; beyond it lies
|
|
reinventing ssh.
|
|
- **No per-pane ACLs:** tmux can't enforce them; faking it with hooks
|
|
would be a leaky abstraction. Document the limitation instead.
|
|
- **No config files, no plugin system, no ACL syscalls:** one POSIX
|
|
file that runs on a 30-year spread of UNIXes is the identity; the
|
|
2026-04 simplification that removed per-OS ACL dispatch is not to be
|
|
unwound.
|
|
- **Watch the file size:** heavy why-comments are a feature; feature
|
|
growth that pushes the single file far past its current size is not.
|