7-Zip Linux File Permissions and Attributes

7-Zip manages Linux file system metadata through a combination of native archive header fields and external packaging workflows. While modern releases of 7-Zip for Linux can directly record standard POSIX permissions, symbolic links, and timestamps inside the native .7z container, capturing advanced metadata like extended attributes (xattrs) and POSIX Access Control Lists (ACLs) requires using the tar utility alongside 7-Zip compression.

Native POSIX Support in the .7z Format

Modern official releases of 7-Zip on Linux (version 21.02 and newer) natively store standard POSIX permissions (file mode bits: read, write, and execute) directly inside the .7z archive header. When you create an archive using the native 7-Zip binary:

7z a archive.7z /path/to/files

7-Zip queries the file's stat structure and embeds the standard Unix file attributes alongside the data. When the archive is extracted on a POSIX-compliant system, 7-Zip applies these recorded permission bits using the chmod system call.

Additionally, 7-Zip includes specific switches to retain file links:

  • -snl: Stores symbolic links as links rather than copying the target file.
  • -snh: Preserves hard links within the archive structure.

Extended Attributes (xattrs) and ACL Limitations

The native .7z container format was originally designed around Windows file systems and NTFS metadata streams. As a result, native .7z archives do not include built-in specifications for arbitrary Linux extended attributes (such as SELinux security contexts, user-defined user.* attributes, or capabilities) or POSIX ACLs.

When 7-Zip compresses files directly into a .7z archive, any metadata stored outside of standard file timestamps, basic permission masks, and link structures is dropped.

Preserving Full Metadata with the Tar Pipeline

To preserve extended attributes (xattrs), ACLs, and exact user/group ownership (UID/GID) on Linux, the standard approach combines GNU tar with 7-Zip. tar captures the comprehensive Linux metadata layer, while 7-Zip provides the high-ratio LZMA/LZMA2 compression.

Creating a Metadata-Preserving Archive

To preserve ACLs and extended attributes, stream the output of tar with the appropriate flags into 7-Zip:

tar --xattrs --acls -cf - /path/to/files | 7z a -si archive.tar.7z
  • --xattrs: Instructs tar to store extended file attributes.
  • --acls: Instructs tar to preserve POSIX access control lists.
  • -cf -: Creates the archive and outputs it to standard output.
  • -si: Directs 7-Zip to read data from standard input.

Restoring the Archive with Attributes

To extract the archive while restoring all extended attributes and permissions, reverse the pipeline:

7z x -so archive.tar.7z | tar --xattrs --acls -xf -
  • -so: Instructs 7-Zip to write the decompressed data to standard output.
  • -xf -: Directs tar to extract the archive from standard input while applying stored permissions, owners, ACLs, and xattrs.