tmux-party/ROADMAP.md
veg a011e4b03c feat: party clean removes the caller's own crash leftovers
Turns the manual rm -rf recovery from host's EEXIST message into a
verb, behind the same gates cmd_close uses: own-basename glob, no
symlinks, ownership check, and a dead socket. Live parties are skipped
with a pointer to party close.
2026-07-11 12:32:39 +00:00

1.5 KiB

Roadmap

Direction, not promises. Two rules govern everything below (README §Security has the long form):

  • Accidents, not adversaries: new checks earn their place by preventing a plausible mistake (stale state, a typo, a race), not by closing a hypothetical attack from a friend.
  • Social, not mechanical: new features earn their place by encouraging people to work together in a terminal, not by adding machinery.

Next: small, high value

  • party log: per-party transcript via tmux pipe-pane into the per-party dir (group-readable so every attendee can grab a copy); party log --stop ends it. "What did we do last night?" for collectives, and the audit trail human+AI co-work needs.

Later

  • Matrix: live validation on NetBSD and DragonFly; one interactive attach/role/switch pass per release (automated coverage is all non-interactive).

Resist: by design, not by neglect

  • No network transport: same-host is the perimeter; beyond it lies reinventing ssh.
  • No per-pane ACLs: tmux can't enforce them; faking it with hooks would be a leaky abstraction. Document the limitation instead.
  • No config files, no plugin system, no ACL syscalls: one POSIX file that runs on a 30-year spread of UNIXes is the identity; the 2026-04 simplification that removed per-OS ACL dispatch is not to be unwound.
  • Watch the file size: heavy why-comments are a feature; feature growth that pushes the single file far past its current size is not.