Can unrar Extract Files and Calculate SHA-256?

The standard unrar command-line utility cannot natively calculate SHA-256 hashes while extracting files to disk. While RAR archives include internal integrity checks, they rely on CRC32 for older archives or BLAKE2sp for the RAR5 format rather than SHA-256. However, users can achieve simultaneous extraction and SHA-256 generation by piping extracted data streams to hashing utilities or by using scripts to process the data concurrently.

Native Capabilities and Limitations

The official unrar binary provides commands for testing and extracting archives, but it lacks any built-in flag to generate cryptographic hashes like SHA-256.

When you run unrar t archive.rar, the program checks the archive's internal checksums:

  • RAR4 and earlier: Uses 32-bit CRC (CRC32).
  • RAR5: Uses 256-bit BLAKE2sp checksums for file data integrity.

Because SHA-256 is not implemented in the RAR specification for file validation, unrar cannot output this specific hash natively during an extraction command like unrar x.

Method 1: Streaming a Single File to Disk and Hash

For archives containing a single file, or when targeting a specific file inside an archive, you can stream the decompressed output directly to standard output (stdout) using the p (print) command. By combining this with Unix tools like tee and sha256sum, you can write the file to disk and calculate the hash in a single pass without reading the file twice:

unrar p -inul archive.rar filename.ext | tee filename.ext | sha256sum
  • p: Prints file data to stdout.
  • -inul: Suppresses standard unrar status and error messages, ensuring only pure file data enters the pipe.
  • tee filename.ext: Writes the incoming stream to disk while passing it along.
  • sha256sum: Calculates the SHA-256 checksum from standard input.

Method 2: Handling Multi-File Archives

The streaming method does not work cleanly for entire multi-file archives because unrar p streams all uncompressed files into a single, contiguous data stream. To extract multiple files and obtain individual SHA-256 hashes, you have two primary options:

Post-Extraction Hashing

The most straightforward approach is to extract the files first and calculate the hashes immediately afterward:

unrar x archive.rar /destination/path/
cd /destination/path/ && sha256sum * > checksums.sha256

Python Automation for True Concurrency

If storage performance or single-pass reading is critical, you can write a small script using Python's rarfile library. This approach reads the decompressed stream of each entry inside the archive in memory chunks, writing to the disk and feeding hashlib.sha256() at the same time:

import hashlib
import rarfile

with rarfile.RarFile("archive.rar") as rf:
    for member in rf.infolist():
        if member.isdir():
            continue
        hasher = hashlib.sha256()
        with rf.open(member) as source, open(member.filename, "wb") as target:
            while chunk := source.read(65536):
                target.write(chunk)
                hasher.update(chunk)
        print(f"{hasher.hexdigest()}  {member.filename}")

This script achieves true simultaneous disk-writing and SHA-256 calculation across all files within the archive.