Skip to content

feat: calculate and verify file checksums - #293

Open
athousanddetails wants to merge 1 commit into
sarensw:mainfrom
athousanddetails:feat/checksums-for-files
Open

athousanddetails wants to merge 1 commit into
sarensw:mainfrom
athousanddetails:feat/checksums-for-files

Conversation

@athousanddetails

@athousanddetails athousanddetails commented Oct 3, 2026 •

Copy link
Copy Markdown

Closes #233.

Finder now offers two optional actions, Checksums… and Verify Checksum from Clipboard, both off by default. For each selected file, MacPacker calculates CRC-32, MD5, SHA-1 and SHA-256 in one chunked background read. The window can copy any value, show a match or mismatch against a pasted checksum, and save a standard file.ext.sha256 checksum file. This uses system hashing APIs rather than an archive engine.

Verification

  • swift test --package-path Modules: 585 tests passed in 138 suites. New tests cover known values, empty files, a read-chunk boundary, clipboard parsing, and both Finder URL actions.
  • Direct and Mac App Store Release builds succeeded unsigned; the architecture check passed for all 10 and 5 bundled Mach-O files respectively (arm64 and x86_64).
  • Manually opened the checksum window through the app URL with two disposable files, confirmed all eight displayed hash values, and saw one matching and one mismatching SHA-256 result. Save .sha256… wrote the expected hash filename line. Confirmed both new settings are unchecked in the Release app. The unsigned build did not enable the live Finder extension, so Finder-menu click-through was covered by the menu and URL tests rather than a live context-menu test.
Before After
Finder settings before Finder settings with optional checksum actions

Two files checked against one SHA-256 value

AI disclosure: Codex was the primary author and performed the verification described above. The human contributor remains responsible for review before merge.

Summary by CodeRabbit

  • New Features
    • Calculate CRC-32, MD5, SHA-1, and SHA-256 checksums for selected files from Finder.
    • Compare file checksums with a checksum copied to the clipboard, and copy or save SHA-256 results.
    • Choose which checksum actions appear in Finder’s menu for file selections.
  • Documentation
    • Added the MacPacker 1.0.1 changelog entry in 16 languages.

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
AGENTS.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: a259c457-5adb-4056-be71-69e6a0a6b473
📥 Commits

Reviewing files that changed from the base of the PR and between 518110d and fef3ddd.

📒 Files selected for processing (13)
  • Config/products/macpacker.json
  • FinderExtension/FinderSync.swift
  • MacPacker/AppDelegate.swift
  • MacPacker/Core/UrlHandling/AppUrlChecksumHandler.swift
  • MacPacker/Features/Checksums/ChecksumWindowController.swift
  • MacPacker/Features/Settings/IntegrationSettingsView.swift
  • MacPacker/Localizable.xcstrings
  • Modules/Sources/Core/Checksums/FileChecksums.swift
  • Modules/Sources/FinderMenu/AppUrl.swift
  • Modules/Sources/FinderMenu/FinderMenuItem.swift
  • Modules/Tests/CoreTests/AppUrlTests.swift
  • Modules/Tests/CoreTests/FileChecksumsTests.swift
  • Modules/Tests/CoreTests/FinderMenuSettingsTests.swift

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 2 remain after this review.


📝 Walkthrough

Walkthrough

Adds CRC-32, MD5, SHA-1, and SHA-256 calculation and clipboard verification. Finder menu actions open a checksum window for selected files, where results can be copied or saved as SHA-256 files.

Changes

File checksum workflow

Layer / File(s) Summary
Checksum algorithms and parsing
Modules/Sources/Core/Checksums/FileChecksums.swift, Modules/Tests/CoreTests/FileChecksumsTests.swift
Adds calculation of four checksum algorithms, parsing of a single standalone hexadecimal checksum, and tests for expected values, parsing, and errors.
Finder checksum actions
Modules/Sources/FinderMenu/AppUrl.swift, Modules/Sources/FinderMenu/FinderMenuItem.swift, FinderExtension/FinderSync.swift, MacPacker/Features/Settings/IntegrationSettingsView.swift, Modules/Tests/CoreTests/AppUrlTests.swift, Modules/Tests/CoreTests/FinderMenuSettingsTests.swift
Adds two Finder actions, maps them to app URLs, limits them to file selections, and adds corresponding settings labels and tests.
Checksum window and app routing
MacPacker/AppDelegate.swift, MacPacker/Core/UrlHandling/AppUrlChecksumHandler.swift, MacPacker/Features/Checksums/ChecksumWindowController.swift, MacPacker/Localizable.xcstrings, Config/products/macpacker.json
Routes checksum app URLs through folder access checks to a window that calculates and displays results, supports clipboard verification, and saves SHA-256 checksums. Adds localized strings and a changelog entry.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant FinderSync
  participant AppDelegate
  participant AppUrlChecksumHandler
  participant ChecksumWindowController
  participant FileChecksumCalculator
  FinderSync->>AppDelegate: Forward checksum action
  AppDelegate->>AppUrlChecksumHandler: Handle checksum app URL
  AppUrlChecksumHandler->>AppUrlChecksumHandler: Check access to parent folders
  AppUrlChecksumHandler->>ChecksumWindowController: Open window with files and verification flag
  ChecksumWindowController->>FileChecksumCalculator: Calculate checksums for each file
Loading

Suggested reviewers: sarensw

Merge Risk: ⚪ Minimal · up to fef3d

No actionable merge-blocking issue remains in the reviewed checksum workflow; it is ready to merge after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to fef3d

The new actions reuse existing file-access permissions and keep results in a visible window. Copying or saving a checksum requires user action. No authorization bypass or automatic disclosure was established, but the externally callable workflow and its signed-runtime behavior warrant a bounded design review.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — An external caller able to deliver an app.macpacker URL can request checksum processing of paths accessible to this user’s app instance, including files beneath previously granted ancestor folders. This does not grant the caller new OS privileges or establish a return channel for results. Exposure is bounded by the app’s effective local file permissions, which were not validated in a signed runtime.

Trust Boundaries and Controls

  • observed — The receiving route validates scheme, action, and absolute-path syntax but does not authenticate Finder origin. Folder access—not sender identity—is the read control. Failed parent-folder access stops the checksum request; unavailable security scopes fall back to an attempted operation subject to ambient permissions and OS enforcement. Clipboard verification reads text into the app, while digest export requires explicit copy or save actions.

Resilience and Maintainability Implications

  • observed — The calculator opens the live path and does not detect replacement or mutation. Cancellation checks occur before each file and between chunks, with no final check before result publication. Weak model capture and controller removal limit post-close visibility; the evidence does not establish a security consequence from these edge conditions.

Hardening Proposals

  • proposed — Define whether verification covers the byte stream read at calculation time or a stable selected file. If a stronger integrity guarantee is intended, detect mutation or replacement and invalidate stale results. Consider receiver-side regular-file validation and an explicit cancelled-state publication check as defense in depth, without treating these additions as fixes for established vulnerabilities.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 12.82% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 39 functions across 11 files. (2 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: adding file checksum calculation and verification.
Linked Issues check ✅ Passed Issue #233 asks for CRC-32, MD5, SHA-1, and SHA-256 for selected files, plus checksum verification from clipboard text through Finder actions. The change summary reports a chunked, single-pass calcula…
Out of Scope Changes check ✅ Passed The reported changes support issue #233. The Finder menu model change filters file-only actions, while the window, app-URL routing, settings labels, localization, changelog, and tests implement or val…
Full details: Docstring Coverage

Explanation

Docstring coverage is 12.82% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 39 functions across 11 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Checksums for files

1 participant