Background
The standard Mac UX for ejecting a removable volume is "drag the volume icon to the Trash." Currently, USB sticks appear as sub-folders of the Unix volume (not as standalone Mac volumes), so the drag-to-Trash UX doesn't apply — and dragging the sub-folder to Trash would fail with a kernel EBUSY (the host path is a mountpoint, can't be rename()d).
Three pieces required in concert
- Refactor outside-world role to mount USB sticks at
/run/chimebox-usb/<dev> and put symlinks at outside-world/USB-*. Mac's rename-into-Trash then succeeds (it's renaming a symlink, not a mountpoint).
- New host-side inotify watcher on
outside-world/Trash/ that detects USB-* arrivals; after a 2s grace period (undo window) it umounts the corresponding device and removes the symlink.
- Custom disk-shaped icons for USB sub-folders so the kid intuits "this looks like a disk, drag-to-Trash means eject" (the standard Mac volume eject mental model).
Without (3), the kid won't drag because she fears losing her photos (just looks like a normal folder labeled "delete").
Until then
Use #2 (hotkey path).
Discovered
2026-05-14 in conversation about USB safety.
Background
The standard Mac UX for ejecting a removable volume is "drag the volume icon to the Trash." Currently, USB sticks appear as sub-folders of the Unix volume (not as standalone Mac volumes), so the drag-to-Trash UX doesn't apply — and dragging the sub-folder to Trash would fail with a kernel
EBUSY(the host path is a mountpoint, can't berename()d).Three pieces required in concert
/run/chimebox-usb/<dev>and put symlinks atoutside-world/USB-*. Mac's rename-into-Trash then succeeds (it's renaming a symlink, not a mountpoint).outside-world/Trash/that detectsUSB-*arrivals; after a 2s grace period (undo window) it umounts the corresponding device and removes the symlink.Without (3), the kid won't drag because she fears losing her photos (just looks like a normal folder labeled "delete").
Until then
Use #2 (hotkey path).
Discovered
2026-05-14 in conversation about USB safety.