Bare 'party host' now walks staff, users, wheel, party and gates on the first group the caller belongs to, announcing the pick. Boxes where people already share a system group need no setup; the curated 'party' group remains the fallback and the explicit --group / TMUX_PARTY_GROUP paths are unchanged. Caller membership is the only probe (id -nG, portable everywhere); whether a guest is a member stays an invite-time warning, where it can actually be answered.
44 lines
1.9 KiB
Markdown
44 lines
1.9 KiB
Markdown
# Roadmap
|
|
|
|
Direction, not promises. Two rules govern everything below (README
|
|
§Security has the long form):
|
|
|
|
- **Accidents, not adversaries:** new checks earn their place by
|
|
preventing a plausible mistake (stale state, a typo, a race), not by
|
|
closing a hypothetical attack from a friend.
|
|
- **Social, not mechanical:** new features earn their place by
|
|
encouraging people to work together in a terminal, not by adding
|
|
machinery.
|
|
|
|
## Next: small, high value
|
|
|
|
- **`party knock <name>`:** an uninvited group member pings the host
|
|
via `write(1)`: "veg wants to join fiesta". `party list` already
|
|
shows invite-only parties; knock completes that loop. The feature
|
|
most likely to cause spontaneous pairing.
|
|
- **`party log`:** per-party transcript via `tmux pipe-pane` into the
|
|
per-party dir (group-readable so every attendee can grab a copy);
|
|
`party log --stop` ends it. "What did we do last night?" for
|
|
collectives, and the audit trail human+AI co-work needs.
|
|
- **`party clean`:** remove the caller's own crash leftovers (dirs
|
|
they own whose socket is dead), turning the manual `rm -rf` recovery
|
|
in host's error message into a verb.
|
|
|
|
## Later
|
|
|
|
- **Matrix:** live validation on NetBSD and DragonFly; one
|
|
interactive attach/role/switch pass per release (automated coverage
|
|
is all non-interactive).
|
|
|
|
## Resist: by design, not by neglect
|
|
|
|
- **No network transport:** same-host is the perimeter; beyond it lies
|
|
reinventing ssh.
|
|
- **No per-pane ACLs:** tmux can't enforce them; faking it with hooks
|
|
would be a leaky abstraction. Document the limitation instead.
|
|
- **No config files, no plugin system, no ACL syscalls:** one POSIX
|
|
file that runs on a 30-year spread of UNIXes is the identity; the
|
|
2026-04 simplification that removed per-OS ACL dispatch is not to be
|
|
unwound.
|
|
- **Watch the file size:** heavy why-comments are a feature; feature
|
|
growth that pushes the single file far past its current size is not.
|