How Unrar Extracts Circular Symlink Archives
This article explains how the unrar utility handles
archive extractions containing circular symbolic link references without
causing infinite loops, filesystem corruption, or system crashes. It
covers the mechanics of symbolic link creation in Unix-like
environments, path resolution safeguards, and the specific security
measures modern versions of unrar use to isolate cyclic
link structures.
The Mechanism of Symbolic Link Creation
When unrar extracts a symbolic link, it treats the link
as a metadata record rather than following the path to its target. Under
POSIX-compliant systems, unrar reads the link target stored
in the RAR header and invokes the standard symlink() system
call. Because symlink() merely records the target path
string in the filesystem without dereferencing it, creating a circular
reference (such as Link A pointing to Link B, which points back to Link
A) succeeds instantly at the filesystem level without triggering an
infinite resolution loop during the creation phase.
Preventing Infinite Traversal Loops
The primary risk of circular symlinks occurs during post-extraction
processing, such as restoring file attributes, updating timestamps, or
recursively scanning extracted directories. The unrar
utility prevents traversal loops through the following techniques:
- Using
lstatInstead ofstat: When querying file statuses or applying metadata,unraruses operations that do not resolve target pointers. By inspecting the link itself rather than following it, the utility avoids entering a recursive loop. - Non-Recursive Target Processing: During decompression, files are extracted based on the explicit manifest stored in the archive headers. The extraction routine iterates linearly over the archive entries rather than traversing the local directory tree dynamically. As a result, the tool never "walks" through a newly created circular link.
Extraction Modes and the
-ol Switch
By default, modern Unix builds of unrar do not extract
symbolic links without specific parameters to protect users from
unexpected link behavior.
- Extracting as Real Links (
-ol): Supplying the-olswitch instructsunrarto recreate the symbolic links as links. In this mode, circular references are written to disk as requested, leaving the OS kernel to detect and return anELOOP(Too many levels of symbolic links) error only if an external program later attempts to traverse them. - Default/Fallback Behavior: Without
-ol,unrarignores symlink creation or writes an empty marker depending on configuration, neutralizing the circular reference entirely.
Path Sanitization and Directory Traversal Defenses
Recent iterations of unrar include strict path
sanitization to mitigate vulnerabilities (such as arbitrary file write
risks). The utility validates the relative paths of symlink targets to
ensure they cannot escape the intended extraction directory. If a
circular symlink chain attempts to escape the root extraction directory
through relative sequences like ../, the sanitizer flags or
skips the offending entry, preventing path traversal attacks alongside
potential cyclic link exploits.