How 7-Zip Processes macOS XAR Archives

This article explains how the 7-Zip file archiver interprets, decompresses, and extracts macOS XAR (eXtensible ARchive) packages. Readers will learn the structural layout of the XAR format—including its binary header, XML table of contents, and data heap—and how 7-Zip reads these components to allow Windows and Linux users to inspect Apple installer packages without needing macOS.

Structure of a XAR Archive

The XAR format is commonly used across Apple ecosystems for software distribution, primarily appearing within macOS .pkg flat installers and Safari extension files. A standard XAR file is organized into three distinct parts:

  1. Header: A small, fixed-size 28-byte binary header containing magic bytes, header size, version information, and checksum properties.
  2. Table of Contents (TOC): A zlib-compressed XML document containing complete file system metadata, directory hierarchies, file attributes, checksums, and offsets into the heap.
  3. Heap: The raw, contiguous data stream containing the contents of all archived files, either compressed or uncompressed.

Magic Byte Identification

When a file is loaded, 7-Zip scans the initial bytes to identify the container format. It looks for the XAR magic signature 0x78617221 (which translates to ASCII xar!). Upon finding this signature, 7-Zip routes the file to its internal XAR handler module rather than attempting generic archive decompression.

Parsing the XML Table of Contents (TOC)

Once the header verifies that the archive is valid, 7-Zip reads the TOC metadata:

  • TOC Decompression: The header specifies the compressed and uncompressed lengths of the TOC. 7-Zip reads this byte range from the file and decompresses it using its native zlib/Deflate implementation.
  • XML Processing: 7-Zip uses a lightweight built-in XML parser to process the decompressed TOC. It maps out each <file> tag, extracting attributes such as file path, original file size, compressed size, modification times, permissions, and checksum hashes (commonly SHA-1 or SHA-256).
  • Heap Offset Mapping: The XML attributes define the exact byte offset and length where each file payload begins within the subsequent heap area. 7-Zip maps these references into its virtual file directory tree for user display.

Decompressing Heap Payloads

Files stored within a XAR archive's heap can be compressed individually using different algorithms. The XML TOC explicitly states the compression type applied to each stream:

  • Supported Codecs: Individual files are typically compressed with gzip/deflate, bzip2, or lzma/xz. Uncompressed streams are also supported.
  • On-Demand Extraction: When a user extracts or views a file, 7-Zip seeks directly to the specified offset in the heap. It then calls the corresponding decompression filter based on the codec identifier found in the TOC for that specific file stream.

Nested Archives in macOS Installers

In macOS .pkg files, XAR acts as an outer container. Processing a .pkg file with 7-Zip often reveals files named Payload, PackageInfo, or Bom.

The Payload file inside a XAR archive is frequently a nested compressed CPIO archive (sometimes using gzip or Apple's proprietary PBZX stream compression). While 7-Zip handles the outer XAR container natively, unpacking the contents of the inner Payload may require secondary extraction steps within 7-Zip if the payload uses standard compression formats.

Read-Only Implementation

7-Zip's support for XAR is strictly read-only. It can unpack, browse, test, and extract files from a XAR container, but it cannot create new XAR archives or modify existing ones. This allows cross-platform analysis and asset extraction without altering macOS-specific package signatures or XML formatting.