tmux-party/ROADMAP.md
veg ff92d812ad docs: state the accidents-not-adversaries threat model; add ROADMAP
The gates in front of destructive operations exist to stop mistakes
(stale rosters, typos, racing hosts); stopping a malicious group
member is a side effect, not the design goal. Written into README
§Security and the man page so future checks are judged by that bar.
ROADMAP.md captures the direction: social features (knock, log,
clean) over further hardening, plus the explicit resist list.
2026-07-04 14:41:43 +00:00

2.3 KiB

Roadmap

Direction, not promises. Two rules govern everything below (README §Security has the long form):

  • Accidents, not adversaries. New checks earn their place by preventing a plausible mistake — stale state, a typo, a race — not by closing a hypothetical attack from a friend.
  • Social, not mechanical. New features earn their place by encouraging people to work together in a terminal, not by adding machinery.

Next — small, high value

  • party knock <name> — an uninvited group member pings the host via write(1): "veg wants to join fiesta". party list already shows invite-only parties; knock completes that loop. The feature most likely to cause spontaneous pairing.
  • party log — per-party transcript via tmux pipe-pane into the per-party dir (group-readable so every attendee can grab a copy); party log --stop ends it. "What did we do last night?" for collectives, and the audit trail human+AI co-work needs.
  • party clean — remove the caller's own crash leftovers (dirs they own whose socket is dead), turning the manual rm -rf recovery in host's error message into a verb.

Later

  • Group ergonomics — the default party group needs root and a relog before anyone's first party. On boxes where everyone already shares a group, host could offer (or default to) the caller's primary group when party doesn't exist. Fits the trust model; costs a little existence-confidentiality.
  • One liveness primitive — fold is_party_alive into party_conn_state; two concepts where one would do.
  • Matrix — live validation on NetBSD and DragonFly; one interactive attach/role/switch pass per release (automated coverage is all non-interactive).

Resist — by design, not by neglect

  • No network transport. Same-host is the perimeter; beyond it lies reinventing ssh.
  • No per-pane ACLs. tmux can't enforce them; faking it with hooks would be a leaky abstraction. Document the limitation instead.
  • No config files, no plugin system, no ACL syscalls. One POSIX file that runs on a 30-year spread of UNIXes is the identity; the 2026-04 simplification that removed per-OS ACL dispatch is not to be unwound.
  • Watch the file size. Heavy why-comments are a feature; feature growth that pushes the single file far past its current size is not.