Roadmap
What is planned for Zit, why, and what each item depends on. Plans, not promises; no dates.
Each item below is a known gap: it is listed on Limits or came out of the review in feedback/review-01.md. Status is as of 0.1.1. Nothing here is built until it says so, and the order is the current priority, not a schedule.
Distribution
| Item | Why | Status |
|---|---|---|
Publish the crate, so cargo install zit works |
Install without access to the repository | Done: zit 0.1.1 is on crates.io; cargo install zit --locked installs it |
Publish the Pi extension (pi install npm:pi-zit) |
Install without a local checkout | Done: pi-zit 0.1.0 is on npm. Still to do: a turn with a live model |
Release Autohand Code with autohand --zit |
A whole Autohand Code session in a Zit workspace | Built and run end to end; ships in the next Autohand Code release |
| Windows | Claude Code and Cursor run there; Zit is Unix-only (signals, libc) |
Not started |
Correctness
| Item | Why | Status |
|---|---|---|
| Resolve references by path and import, not only by name | A mention of Config depends on every Config in the repository (Limits) |
Not started |
| More languages with symbol granularity (Java, C#, C++, Kotlin, Ruby, PHP, Swift) | Files in those languages are one resource with no inferred reads | Not started |
| Re-measure false refusals | The 21–23% figure predates the interface-only staleness rule (ADR 16) | Not started |
| Signed evidence | Fetched check results are untrusted by default; trusting them (zit.trustFetchedEvidence) trusts whoever can push refs |
Not started |
Run [[derive]] and [prepare] only from trusted states |
A change’s own zit.toml commands run when you accept or materialise it |
Not started |
| Keep agents’ branches, tags and stashes out of the real repository | A workspace shares the repository’s refs | Not started |
| Stop children of interactive agents | Headless runs stop the agent’s process group; interactive runs stop only the agent | Not started |
Scale and teams
| Item | Why | Status |
|---|---|---|
| Claims across machines | Claims and live write sets are local to one machine | Not started |
| Verify non-conflicting changes as one batch | Changes are verified one at a time; merge queues batch (Compared) | Not started |
| An integrator for CI (for example a GitHub Action) | Today you run zit accept in a job yourself |
Not started |
| Stable-path workspaces for compiled projects | Each workspace is at a new path, so Cargo and similar tools rebuild per workspace (about 1.9 GB after ten Rust agents, Lesson 01) | Not started |
| Usage from Autohand Code and Pi | Only Claude Code (tokens and dollars) and Codex (tokens) report it to zit run |
Not started |
Evidence
| Item | Why | Status |
|---|---|---|
| Repeat the experiments on other repositories, languages and machines | Every real-agent result so far is from one or two runs on one Mac (Lessons) | Not started |
| Human review of what landed | Quality has been scored only by a blind model judge (Lesson 04) | Not started |
| A pnpm baseline for the dependency benchmark | The 327 MB against 1,619 MB comparison is against npm ci per worktree |
Not started |
| Linux disk benchmark with real dependencies | The Linux runs use a synthetic repository of small files | Not started |
From the research
Candidates from Prior art and objections, each answering a weakness found there. Sizes are estimates.
| Item | Why | Size |
|---|---|---|
| Parse-check the composed state before running checks | Text from git merge-tree can be syntactically wrong (Mori and Hashimoto, 2026) |
Small |
| Report false refusals and false accepts against test oracles | Merge-tool evaluations that ignore incorrect clean merges overstate quality (Schesch et al., 2024) | Medium |
| Replay public agent-conflict data: AgenticFlict, CooperBench, STALE | Measured accuracy on other people’s data instead of our own runs | Medium |
| A conflict graph from footprints, to verify independent changes together | Uber’s SubmitQueue commits independent changes in parallel; Zit verifies one at a time | Large |
| A structure-aware merge for adjacent insertions | Zit’s most common remaining rejection; semistructured merge removes it (Apel et al. 2011; Cavalcanti et al. 2017) | Large |
| Detect renames before deciding staleness | A rename is a delete plus an add, which stales every reader (RefFilter, 2025) | Medium |
| Compose open workspaces against each other in the background | Crystal’s speculative merging warns before anyone records | Medium |
| Measure how much parallelism refused claims give up | Pre-write admission serialised 93.3% of clean cases in Claim Plane (2026) | Small |
| A port and namespace per workspace | Agents share ports and machine-wide state today | Small to medium |
| An optional log of the commands an agent ran | Zit keeps the final message and cost, not what was run | Small |
Select checks from footprints instead of declared inputs |
Check inputs are trusted, not verified | Medium |
To propose or take on an item, open an issue (CONTRIBUTING.md).