tmux-party/ROADMAP.md
veg a011e4b03c feat: party clean removes the caller's own crash leftovers
Turns the manual rm -rf recovery from host's EEXIST message into a
verb, behind the same gates cmd_close uses: own-basename glob, no
symlinks, ownership check, and a dead socket. Live parties are skipped
with a pointer to party close.
2026-07-11 12:32:39 +00:00

37 lines
1.5 KiB
Markdown

# Roadmap
Direction, not promises. Two rules govern everything below (README
§Security has the long form):
- **Accidents, not adversaries:** new checks earn their place by
preventing a plausible mistake (stale state, a typo, a race), not by
closing a hypothetical attack from a friend.
- **Social, not mechanical:** new features earn their place by
encouraging people to work together in a terminal, not by adding
machinery.
## Next: small, high value
- **`party log`:** per-party transcript via `tmux pipe-pane` into the
per-party dir (group-readable so every attendee can grab a copy);
`party log --stop` ends it. "What did we do last night?" for
collectives, and the audit trail human+AI co-work needs.
## Later
- **Matrix:** live validation on NetBSD and DragonFly; one
interactive attach/role/switch pass per release (automated coverage
is all non-interactive).
## Resist: by design, not by neglect
- **No network transport:** same-host is the perimeter; beyond it lies
reinventing ssh.
- **No per-pane ACLs:** tmux can't enforce them; faking it with hooks
would be a leaky abstraction. Document the limitation instead.
- **No config files, no plugin system, no ACL syscalls:** one POSIX
file that runs on a 30-year spread of UNIXes is the identity; the
2026-04 simplification that removed per-OS ACL dispatch is not to be
unwound.
- **Watch the file size:** heavy why-comments are a feature; feature
growth that pushes the single file far past its current size is not.