Skip to content

fix: show Finder actions on external drives - #290

Open
athousanddetails wants to merge 1 commit into
sarensw:mainfrom
athousanddetails:fix/finder-external-volumes
Open

athousanddetails wants to merge 1 commit into
sarensw:mainfrom
athousanddetails:fix/finder-external-volumes

Conversation

@athousanddetails

@athousanddetails athousanddetails commented Oct 3, 2026 •

Copy link
Copy Markdown

Finder only requested MacPacker menus inside the home folder, so archive actions were missing on external drives even when file access had been granted. Register the visible mounted volume roots at startup and refresh them on mount, unmount, and rename. Existing home roots remain registered; the startup filesystem root is excluded. This does not grant additional file access.

Closes #275.

Verification:

  • Reproduced the missing menu on a physical FAT32 USB drive; the patched Finder extension shows it.
  • Invoked Extract Here and ZIP compression through Finder on disposable files on that drive. Both outputs matched their source contents byte-for-byte.
  • Regression tests failed before the fix. All 5 focused tests now pass; the full suite passed 580 tests before the two additional sandbox-home/normalization cases were added.
  • Both Direct and Store universal Release builds succeeded; 15 bundled Mach-O files passed the arm64/x86_64 guard. The Direct build was rerun after adding the approved release note.
  • Physical hot-plug/rename notifications were not manually exercised; root replacement is covered by automated tests.
Before After
Missing external-drive menu External-drive menu available

Detailed evidence: docs/verification/issue-275/README.md. Screenshots are genuine crops excluding the cursor. The temporary review extension and disposable test files were removed; the installed app was not replaced.

AI disclosure: implementation, tests, and documentation were authored with Codex under this human-owned account. Verification included automated tests/builds and direct Finder interaction described above.

Summary by CodeRabbit

  • Bug Fixes
    • Finder actions now work more reliably on external drives. Mounted volumes are recognized, and Finder updates its observed locations when volumes are mounted, unmounted, or renamed.
  • Documentation
    • Added verification notes covering Finder behavior on a mounted USB drive and the checks performed for this release.

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
AGENTS.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: d951add0-7d7b-499d-beb2-02f10d715f63
📥 Commits

Reviewing files that changed from the base of the PR and between 518110d and cd252fa.

⛔ Files ignored due to path filters (2)
  • docs/verification/issue-275/after.png is excluded by !**/*.png
  • docs/verification/issue-275/before.png is excluded by !**/*.png
📒 Files selected for processing (5)
  • Config/products/macpacker.json
  • FinderExtension/FinderSync.swift
  • Modules/Sources/FinderMenu/FinderObservedDirectories.swift
  • Modules/Tests/CoreTests/FinderObservedDirectoriesTests.swift
  • docs/verification/issue-275/README.md

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 2 remain after this review.


📝 Walkthrough

Walkthrough

FinderSync now observes mounted volumes in addition to user directories. It refreshes its observed roots at startup and after volume mount, unmount, or rename notifications. The change also adds root-selection tests, verification notes, and a localized changelog entry.

Changes

External-volume Finder actions

Layer / File(s) Summary
Build and test observed roots
Modules/Sources/FinderMenu/FinderObservedDirectories.swift, Modules/Tests/CoreTests/FinderObservedDirectoriesTests.swift
The new helper returns directory URLs for the home directory, /Users/<userName>, and mounted file URLs. It normalizes paths, excludes /, and ignores non-file URLs. Tests cover root selection and refreshed roots.
Refresh Finder roots on volume changes
FinderExtension/FinderSync.swift, Config/products/macpacker.json, docs/verification/issue-275/README.md
FinderSync refreshes its roots at startup and after volume mount, unmount, or rename notifications. It removes observers on deinitialization. The changelog and verification notes describe the fix and checks. The notes state that physical hot-plug and rename notifications were not manually tested.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix · Severity of issue fixed: Medium

Sequence Diagram(s)

sequenceDiagram
  participant NSWorkspace
  participant FinderSync
  participant FinderObservedDirectories
  participant Finder
  NSWorkspace->>FinderSync: Report volume mount, unmount, or rename
  FinderSync->>FinderObservedDirectories: Build roots from home, username, and mounted volumes
  FinderObservedDirectories-->>FinderSync: Return observed directory URLs
  FinderSync->>Finder: Assign observed directory URLs
Loading

Suggested reviewers: sarensw

Merge Risk: ⚪ Minimal · up to cd252

The external-drive Finder action change is ready to merge after normal checks. Physical hot-plug and rename behavior has not been manually exercised.

Security Architecture Review

Security architecture risk: 🔵 Low · up to cd252

Actions become available on more mounted volumes, but directory registration does not grant file access. Requests still pass through existing validation and folder-access checks. No introduced permission bypass was established; live volume-change behavior and some failure states remain incompletely verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The incremental exposure is Finder-action visibility across non-hidden mounted file volumes in the extension's user session, not just removable drives. Names and content on those volumes can be untrusted, but root registration does not itself confer filesystem privileges.

Security Findings and Attack Paths

  • inferred — The checked path runs from mounted-volume selection through the existing URL request route to app-owned permission checks and archive operations. The parser already accepts absolute paths outside the home directory and does not authenticate caller provenance. That pre-existing entrypoint is not newly created by this PR; expanded menu visibility did not establish a new authorization bypass in the inspected flow.

Trust Boundaries and Controls

  • observed — Finder selections arrive as paths, not access grants. The access store checks existing security-scoped coverage, the Downloads-specific access path, or an explicit folder grant. A prompted grant must cover the requested folder before the access check succeeds.

Resilience and Maintainability Implications

  • inferred — Repeated refreshes with identical inputs produce the same set, and successful later enumeration can replace stale menu roots. Enumeration failure or out-of-order callbacks could affect menu availability, but the inspected flow does not turn retained observed roots into file-access authority. Callback serialization and setter ordering remain unproven rather than demonstrated security failures.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 9 functions across 3 files. (2 skipped: 2 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the fix that makes Finder actions available on external drives.
Linked Issues check ✅ Passed Issue #275 requires Finder menu registration for mounted external volumes when access is already granted, with updates when volumes mount or unmount. FinderSync now refreshes observed directories at…
Out of Scope Changes check ✅ Passed The changelog entry, issue verification documentation, and tests support the external-volume Finder fix in issue #275. The summary identifies no unrelated changes.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 9 functions across 3 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Finder context menu does not appear on external volumes

1 participant