Skip to content

feat: optionally extract archives opened from Finder - #291

Open
athousanddetails wants to merge 1 commit into
sarensw:mainfrom
athousanddetails:feat/extract-on-open
Open

athousanddetails wants to merge 1 commit into
sarensw:mainfrom
athousanddetails:feat/extract-on-open

Conversation

@athousanddetails

@athousanddetails athousanddetails commented Oct 3, 2026 •

Copy link
Copy Markdown

Adds an opt-in General → When opening an archive → Extract immediately setting. Opening an archive through Finder/Open With then extracts beside the source using the existing smart-extraction rules, without first opening a browser, launcher, or welcome window. Open in MacPacker remains the default, and File → Open / Open Archive still browses archives regardless of the setting.

Closes #280.

File-open extractions run sequentially, with standalone password retry/cancellation and the existing folder-access and progress UI. Each archive uses its own parent folder. The app stays alive while an access/password prompt is pending and respects Quit on Last Window Closed after the queue finishes. Explicit app launch remains available through AppKit's untitled-document/reopen events.

Verification:

  • 580 tests passed in the final full Swift suite. Focused routing tests first reproduced the missing behavior and now pass.
  • Both Direct and Store universal Release builds succeeded. All 15 bundled Mach-O files passed the arm64/x86_64 architecture guard.
  • Manual cold Finder launch: ZIP extracted with all three contents verified byte-for-byte and no startup launcher/welcome window. The initial startup-order bug was caught and corrected during this test.
  • Encrypted-header 7z: incorrect-password retry, successful password extraction with byte-for-byte checks, and cancellation with no output/source loss. Cancellation also quit the app when configured.
  • Two encrypted archives opened together: cancelling the first advanced to the second prompt; the second extracted successfully.
  • Explicit app launch and Open Archive still displayed the archive browser with direct extraction enabled.
Before After
General settings before Optional immediate extraction

Password retry

Detailed verification: docs/verification/issue-280/README.md. Screenshots are genuine crops excluding the cursor. Testing used a separate local review identity; the installed app was not replaced, and the temporary app/files were removed afterward.

Scope: existing extraction/overwrite semantics are unchanged. This PR does not depend on #285; its standalone password-panel pattern is reused here. No additional application/helper, Finder extension, default-format association changes, or version changes.

AI disclosure: implementation, tests, and documentation were authored with Codex under this human-owned account. Manual app interaction and verification are described above.

Summary by CodeRabbit

  • New Features
    • Added a setting to choose whether archives opened from Finder are browsed in MacPacker or extracted immediately. Archives opened through File → Open continue to open for browsing.
    • Immediate extraction supports password-protected archives and handles multiple archives opened together.
  • Bug Fixes
    • MacPacker now stays open while extraction is in progress, even when no windows are visible.

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
AGENTS.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 01544ee3-ce6c-4a1c-8eae-5158aef6cd6a
📥 Commits

Reviewing files that changed from the base of the PR and between 518110d and 0a443b5.

⛔ Files ignored due to path filters (3)
  • docs/verification/issue-280/password-retry.png is excluded by !**/*.png
  • docs/verification/issue-280/settings-after.png is excluded by !**/*.png
  • docs/verification/issue-280/settings-before.png is excluded by !**/*.png
📒 Files selected for processing (10)
  • Config/products/macpacker.json
  • MacPacker/AppDelegate.swift
  • MacPacker/Core/ArchiveOpenExtractor.swift
  • MacPacker/Features/PasswordWindow/ArchiveOpenPasswordPrompt.swift
  • MacPacker/Features/Settings/GeneralSettingsView.swift
  • MacPacker/Localizable.xcstrings
  • Modules/Sources/Core/AppStorageKeys.swift
  • Modules/Sources/Core/ArchiveOpenBehavior.swift
  • Modules/Tests/CoreTests/ArchiveOpenBehaviorTests.swift
  • docs/verification/issue-280/README.md

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 2 remain after this review.


📝 Walkthrough

Walkthrough

MacPacker adds a preference for extracting archives opened from Finder. Eligible archives enter a sequential extraction queue, which handles password prompts and open errors. The app continues to browse archives opened through File → Open and defers termination while extraction remains active.

Changes

Finder Archive Extraction

Layer / File(s) Summary
Archive-open preference and rules
Modules/Sources/Core/ArchiveOpenBehavior.swift, Modules/Sources/Core/AppStorageKeys.swift, MacPacker/Features/Settings/GeneralSettingsView.swift, Modules/Tests/CoreTests/ArchiveOpenBehaviorTests.swift, MacPacker/Localizable.xcstrings, docs/verification/issue-280/README.md, Config/products/macpacker.json
Adds the persisted browse or extract preference and rules for extraction eligibility and launch-window suppression. Adds the settings picker, localization, tests, verification notes, and changelog entry.
Queued extraction and password handling
MacPacker/Core/ArchiveOpenExtractor.swift, MacPacker/Features/PasswordWindow/ArchiveOpenPasswordPrompt.swift
Adds sequential archive processing, folder access checks, password and file-access providers, extraction, and open-error handling.
Finder routing and app lifecycle
MacPacker/AppDelegate.swift
Routes eligible Finder-opened archives to the extractor and other URLs to archive windows. Handles untitled browser requests and defers termination while extraction is active.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant AppDelegate
  participant ArchiveOpenExtractor
  participant ArchiveState
  participant ArchiveOpenPasswordPrompt
  AppDelegate->>ArchiveOpenExtractor: Enqueue eligible Finder URL
  ArchiveOpenExtractor->>ArchiveState: Open archive with password provider
  ArchiveState->>ArchiveOpenPasswordPrompt: Request archive password
  ArchiveOpenPasswordPrompt-->>ArchiveState: Return password or cancellation
  ArchiveOpenExtractor->>ArchiveState: Extract archive to containing folder
Loading

Merge Risk: ⚪ Minimal · up to 0a443

The Finder extraction feature is mergeable after normal checks. Cancelling a password prompt for certain damaged archives may hide an error message, but it does not prevent the user from trying another way to open the archive.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 0a443

Immediate extraction makes opening an archive write files without a separate extraction action. The behavior is explicitly opt-in, preserves default browsing, and retains folder authorization and password prompts. No authorization bypass was established, but interruption and partial-output handling remain incompletely verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The relevant exposure is local filesystem data reachable through the application's existing permissions and sandbox grants. Requested output is beside each source archive or in its smart-extraction subfolder. That requested destination alone does not establish engine-level confinement against malicious archive paths or links.

Security Findings and Attack Paths

  • inferred — An attacker-supplied archive opened by an opted-in user can now reach full extraction without a separate browser extraction action. This increases automatic write reachability, but the reviewed route retains eligibility and folder-access controls; no introduced bypass was established.

Trust Boundaries and Controls

  • observed — Recognized application URLs are handled before Finder extraction routing. Extraction requires explicit preference selection and retains destination authorization and source-file access resolution rather than treating receipt of a Finder URL as unrestricted filesystem authority.

Resilience and Maintainability Implications

  • observed — Password continuations are consumed once, and closing the prompt resolves cancellation. Shared extraction records success, cancellation, password cancellation, or failure before clearing its busy state. Full extraction delegates directly to the engine's destination-writing operation; the inspected shared layer does not provide a staged atomic commit or rollback.

Hardening Proposals

  • proposed — For automatic extraction, consider an explicit staged-output commit policy with defined collision, repetition, and cancellation behavior. This would strengthen failure containment; it is a hardening proposal, not evidence of an introduced vulnerability.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 22.22% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 18 functions across 7 files. (3 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: making Finder-opened archives extract immediately as an option.
Linked Issues check ✅ Passed Issue #280 requests an option to extract archives opened from Finder instead of browsing them. The PR adds a persisted setting with “Open in MacPacker” as the default and “Extract immediately” as the …
Out of Scope Changes check ✅ Passed The settings UI, archive-open routing, extraction queue, password prompt, localization, tests, changelog entry, and verification documentation support issue #280. The reviewed summary identifies no un…
Full details: Docstring Coverage

Explanation

Docstring coverage is 22.22% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 18 functions across 7 files. (3 skipped: 3 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Feature request: Extract archives on open

1 participant