How 7-Zip Extracts RAR and RAR5 Files
7-Zip extracts files from RAR and RAR5 archives by utilizing a dedicated, reverse-engineered, and ported decompression engine integrated directly into its open-source codebase. While 7-Zip cannot create RAR archives due to proprietary licensing restrictions imposed by WinRAR’s developer, it can read and decompress them seamlessly. This process involves parsing unique archive signatures, interpreting distinct metadata structures, handling encryption protocols, and running customized decompression algorithms that accommodate differences between legacy RAR formats and the modern RAR5 format.
The Licensing Behind RAR Support
The RAR format is a proprietary standard developed by Eugene Roshal and owned by win.rar GmbH. The full compression algorithm remains closed-source, and its license explicitly forbids developers from reverse-engineering the compression mechanism to create non-WinRAR RAR encoders.
However, Roshal provides a free, source-code distribution of the decompression engine called unRAR. The author of 7-Zip, Igor Pavlov, integrated a modified version of this decompression logic directly into 7-Zip's modular file-processing architecture. This allows 7-Zip to unpack RAR files natively without requiring WinRAR or any external dynamic link libraries (DLLs) installed on the system.
Parsing Archive Headers and Metadata
When 7-Zip opens an archive, it determines the file type by reading
the "magic bytes" (file signatures) at the beginning of the file rather
than relying solely on the .rar extension:
- Legacy RAR (RAR 1.5 to RAR 4.x): Identified by the
byte sequence
52 61 72 21 1A 07 00. - RAR5: Identified by the byte sequence
52 61 72 21 1A 07 01 00.
Once the signature is verified, 7-Zip processes the archive headers. Legacy RAR versions use fixed-format headers with 16-bit and 32-bit fields to store information such as file names, timestamps, and attributes.
In contrast, RAR5 completely revamped this structure, employing variable-length integers (vints) to reduce header overhead and introducing extensible metadata blocks. 7-Zip parses these blocks sequentially to map the file directory, file sizes, and flags indicating whether compression or encryption was applied.
Decryption Handling
If the archive is password-protected, 7-Zip prompts the user for the password before unpacking the compressed payloads:
- Legacy RAR: Uses AES-128 in Cipher Block Chaining (CBC) mode. Password hashing is performed using a modified algorithm based on SHA-1 repeated thousands of times to derive the decryption key.
- RAR5: Upgraded to stronger AES-256 encryption in CBC mode. It derives the decryption key using the standard PBKDF2 (Password-Based Key Derivation Function 2) algorithm combined with HMAC-SHA-256.
7-Zip decrypts the data blocks in memory before passing the decrypted stream to the decompression pipeline.
Decompressing Legacy RAR Formats
Decompressing legacy RAR (primarily RAR 2.x, 3.x, and 4.x) requires handling a combination of specialized algorithms:
- Lempel-Ziv (LZSS): Scans for repeated byte patterns using sliding dictionary sizes ranging up to 4 MB.
- Huffman Coding: Encodes frequent symbols with shorter bit-lengths to optimize pattern representations.
- PPMd (Prediction by Partial Matching): Used primarily in RAR3 for text compression, using statistical models to predict incoming characters.
- Specialized Multimedia Filters: Specific pre-processing algorithms tailored for uncompressed audio, RGB images, and Itanium executable binaries to improve compression ratios.
7-Zip maintains separate internal code branches to decode each of these legacy variations according to the flags stored in the archive’s file headers.
Decompressing Modern RAR5 Archives
RAR5 discarded many legacy components to streamline performance and improve modern multi-core decompression speeds:
- Expanded Dictionary Sizes: RAR5 supports dictionary sizes up to several gigabytes (commonly between 32 MB and 1 GB, and up to 4 GB in specialized setups). 7-Zip allocates the designated buffer size dynamically in system RAM to track back-references across large files.
- Simplified Algorithms: RAR5 dropped PPMd and the old multimedia filters, relying entirely on a modernized LZSS variant coupled with dynamic Huffman coding.
- X86 Executable Filters: RAR5 retains specialized delta-encoding filters specifically for modern x86/x64 executable code, which 7-Zip reverses during file reconstruction.
7-Zip decodes the bitstream using prefix trees (Huffman tables), reconstructs the raw byte streams using reference offsets from the sliding dictionary, and writes the output directly to the destination path.
Checksums and Integrity Verification
The final step in 7-Zip's extraction process is integrity verification:
- In Legacy RAR, 7-Zip computes a 32-bit Cyclic Redundancy Check (CRC32) over the extracted bytes and compares it against the CRC value stored in the file header.
- In RAR5, archives can use either CRC32 or the cryptographic BLAKE2sp 256-bit hash. 7-Zip calculates the corresponding checksum in parallel with file writing.
If the calculated hash matches the header value, 7-Zip marks the extraction as successful and sets the original file attributes, timestamps, and permissions on the host file system.