How UnRAR Handles Files with Trailing Dots

Extracting archives that contain files with trailing dots presents unique challenges due to how different operating systems process file paths. This article explains how the unrar utility processes files ending with dots, detailing the differences between Windows and Unix-like operating systems, the automated sanitization rules applied by the utility, and the security measures implemented to prevent file system conflicts.

The Underlying Operating System Restrictions

The behavior of unrar largely depends on the target operating system's file system specifications:

  • Windows: The Win32 namespace prohibits file and directory names from ending with a period (.) or a blank space. Traditional Windows APIs automatically strip trailing dots during path resolution, which can cause unexpected file overwrites or render files inaccessible through standard graphical interfaces.
  • Linux and macOS: POSIX-compliant file systems treat trailing dots as valid, distinct characters in a filename, allowing files like document. to exist alongside document.

Sanitization and Truncation on Windows

When running unrar in a Windows environment, the utility detects invalid characters to maintain compatibility with the operating system:

  1. Automatic Stripping: By default, unrar strips trailing dots from file and folder names before writing them to the disk. For example, a file archived as report. will be extracted as report.
  2. Collision Handling: If stripping the trailing dot causes a name collision with an existing file (such as extracting both data. and data), unrar invokes its standard overwrite prompts or relies on command-line flags like -o+ (overwrite) or -or (automatically rename).

Handling on Unix-like Systems (Linux and macOS)

On Linux and macOS, unrar generally preserves trailing dots because the underlying file systems natively support them. However, modern releases of unrar include security safeguards:

  • Path Normalization: If a trailing dot creates an ambiguous path component (such as .. or trailing dots in directory segments that could be parsed as relative traversal indicators), unrar normalizes or rejects the path to prevent directory traversal exploits.
  • Standard Extraction: For regular files where a trailing dot does not pose a security hazard, the utility writes the file exactly as named in the RAR header.

Security Mitigations

Historically, malicious archives have used trailing dots and spaces to bypass extension filters or execute directory traversal attacks. In patched, modern versions of unrar:

  • Directory Name Traversal: Trailing dots in directory names within an archive are sanitized to prevent vulnerabilities where security scanners miss malicious payloads.
  • Invalid Name Warnings: If unrar encounters a name it cannot safely normalize for the host platform, it issues a warning, skips the problematic entry, or modifies the name to comply with local file system integrity rules.