How Unrar Extracts Circular Symlink Archives

This article explains how the unrar utility handles archive extractions containing circular symbolic link references without causing infinite loops, filesystem corruption, or system crashes. It covers the mechanics of symbolic link creation in Unix-like environments, path resolution safeguards, and the specific security measures modern versions of unrar use to isolate cyclic link structures.

When unrar extracts a symbolic link, it treats the link as a metadata record rather than following the path to its target. Under POSIX-compliant systems, unrar reads the link target stored in the RAR header and invokes the standard symlink() system call. Because symlink() merely records the target path string in the filesystem without dereferencing it, creating a circular reference (such as Link A pointing to Link B, which points back to Link A) succeeds instantly at the filesystem level without triggering an infinite resolution loop during the creation phase.

Preventing Infinite Traversal Loops

The primary risk of circular symlinks occurs during post-extraction processing, such as restoring file attributes, updating timestamps, or recursively scanning extracted directories. The unrar utility prevents traversal loops through the following techniques:

  • Using lstat Instead of stat: When querying file statuses or applying metadata, unrar uses operations that do not resolve target pointers. By inspecting the link itself rather than following it, the utility avoids entering a recursive loop.
  • Non-Recursive Target Processing: During decompression, files are extracted based on the explicit manifest stored in the archive headers. The extraction routine iterates linearly over the archive entries rather than traversing the local directory tree dynamically. As a result, the tool never "walks" through a newly created circular link.

Extraction Modes and the -ol Switch

By default, modern Unix builds of unrar do not extract symbolic links without specific parameters to protect users from unexpected link behavior.

  • Extracting as Real Links (-ol): Supplying the -ol switch instructs unrar to recreate the symbolic links as links. In this mode, circular references are written to disk as requested, leaving the OS kernel to detect and return an ELOOP (Too many levels of symbolic links) error only if an external program later attempts to traverse them.
  • Default/Fallback Behavior: Without -ol, unrar ignores symlink creation or writes an empty marker depending on configuration, neutralizing the circular reference entirely.

Path Sanitization and Directory Traversal Defenses

Recent iterations of unrar include strict path sanitization to mitigate vulnerabilities (such as arbitrary file write risks). The utility validates the relative paths of symlink targets to ensure they cannot escape the intended extraction directory. If a circular symlink chain attempts to escape the root extraction directory through relative sequences like ../, the sanitizer flags or skips the offending entry, preventing path traversal attacks alongside potential cyclic link exploits.