How Unrar Extracts Hidden and System Files

This article explains how the unrar utility processes archives containing hidden and system files, detailing its attribute preservation mechanisms, cross-platform behavior, and relevant command-line flags. When unpacking an archive, unrar reads the metadata attached to each entry, determining whether to restore OS-specific flags like the Windows "Hidden" and "System" attributes or POSIX hidden file formats. Understanding this process ensures you can safely extract or ignore sensitive and concealed files across different environments.

File Attribute Preservation

The RAR file format stores extended file metadata alongside the compressed data. When files are archived on a Windows system, their standard DOS/NTFS attributes—such as Read-Only, Archive, Hidden, and System—are saved into the archive header.

By default, when unrar unpacks an archive on a Windows system, it applies these preserved attributes directly to the extracted files. If a file was marked as both hidden and a system file in the archive, it will retain both statuses in the destination directory, making it invisible in standard file managers unless configured to show protected operating system files.

Cross-Platform Handling: Windows vs. Linux/macOS

Operating systems treat "hidden" and "system" statuses differently, and unrar adapts according to the host platform:

  • On Windows: unrar maps the internal attribute flags directly to the Windows file system API. Files with the hidden or system bit set will immediately receive those attributes upon extraction.
  • On Unix-like Systems (Linux, macOS): Unix systems do not natively use "hidden" or "system" metadata flags. Instead, files are considered hidden if their filename begins with a dot (.filename). If an archive contains a file that was named with a leading dot, unrar extracts it as-is, and it becomes hidden in Unix environments. However, if a file only has the Windows "Hidden" or "System" attribute flag set without a leading dot, unrar extracts it as a visible file on Linux/macOS, though it may attempt to store these flags in extended attributes (xattr) if configured to do so.

Command-Line Switches for Attribute Control

You can control how unrar processes attributes and system-level permissions using specific command-line switches:

  • -ai (Ignore file attributes): Instructs unrar not to apply the stored file attributes (including Hidden, System, and Read-Only) to the extracted files. The extracted files inherit the default attributes of the target folder.
  • -ow (Restore file owner and group): Restores security information, including user and group ownership on platforms that support it (requires administrative/root privileges).
  • -os (Save and restore NTFS streams): Directs unrar to restore alternate data streams and extended file properties associated with Windows NTFS file systems.

Security and Overwrite Protections

Because hidden and system files can theoretically be used to replace critical operating system components, unrar includes built-in safeguards:

  1. Directory Traversal Protection: unrar automatically strips absolute paths (such as C:\Windows\ or /etc/) and relative path traversal sequences (such as ../) to prevent an archive from silently planting hidden system files into sensitive system directories.
  2. Overwrite Confirmations: By default, unrar prompts the user before overwriting existing files, preventing an incoming hidden system file from silently replacing an existing document or configuration file, unless overridden by flags such as -o+ (overwrite without prompt) or -o- (do not overwrite).