How Unrar Handles Alternate Data Streams on Linux

This article explains how the Linux version of the unrar utility processes archives containing NTFS Alternate Data Streams (ADS). While Windows systems use ADS to store metadata, resource forks, or hidden data alongside primary file contents, Linux filesystems use different architectural models, such as extended attributes. Below is an overview of how unrar handles these secondary streams during extraction on a Linux host, the technical reasons behind its behavior, and how to access the underlying data if needed.

What Are Alternate Data Streams in RAR Archives?

Alternate Data Streams are a feature of the Windows New Technology File System (NTFS). They allow an individual file to hold multiple streams of data: the primary, unnamed data stream (the standard file contents) and one or more named streams accessed via the filename:streamname syntax.

When WinRAR or the Windows command-line RAR tool compresses files, users can pass the -os switch to capture these secondary streams inside the archive. This is commonly used to preserve Windows-specific metadata, zone identifiers (web download markers), or custom application data.

Default Behavior of Linux unrar

When running the official RARLAB unrar binary (or the open-source unrar-free utility) on Linux:

  • Streams Are Skipped or Discarded: By default, Linux unrar extracts only the primary unnamed data stream. It reads the archive headers, recognizes the standard file data, and ignores the stream data chunks assigned to alternate streams.
  • No xattr Conversion: Linux utilizes Extended Attributes (xattr) for file metadata, but unrar does not translate NTFS streams into Linux extended attributes.
  • No Colon-Delimited File Creation: While Linux filesystems (such as ext4, Btrfs, and XFS) permit colons (:) in filenames, unrar does not attempt to create standalone files using the filename:streamname convention to preserve the extra data.

Because of this behavior, extracting an archive on Linux that relies on secondary streams will quietly result in the loss of all stream data, while the main file contents remain intact.

Why Linux unrar Discards ADS

  1. Filesystem Incompatibility: The Virtual File System (VFS) in the Linux kernel does not support the multi-stream file model of NTFS.
  2. Path Traversal and Security Risks: Automatically unpacking alternate streams into distinct Linux files using colons could overwrite existing files or introduce security vulnerabilities, especially if an archive contains streams designed to mimic system paths.
  3. Tool Design: RARLAB’s Unix version of unrar is compiled with cross-platform compatibility in mind. Its extraction engine maps standard POSIX file permissions and timestamps, but excludes Windows-exclusive subsystems like NTFS streams unless specifically targeting a Windows environment.

Security and Data Integrity Implications

  • Data Loss: If an application relies on secondary streams (such as specific audio tagging tools, graphic design software, or legacy backup tools), extracting the archive on Linux will strip that information without throwing a fatal extraction error.
  • Security Shielding: Malicious payloads hidden inside alternate data streams to bypass antivirus software on Windows are neutralized on Linux. Because the streams are not unpacked, the hidden data cannot be written to disk.

Methods to Access ADS Data on Linux

If you must extract and read the contents of Alternate Data Streams on a Linux machine, consider the following alternatives:

  • Use 7-Zip (7z or p7zip): Some versions of 7z on Linux allow extracting alternate streams as separate files. Using the -sns switch (store/restore NTFS streams) instructs the unpacker to extract streams as separate files using the filename:streamname naming scheme.
  • Run WinRAR Under Wine: Running the official Windows console or GUI version of WinRAR via Wine allows the utility to execute its native Windows stream-handling logic. If extracted to an NTFS-formatted drive mounted with ntfs-3g, the streams can be written directly to the filesystem.
  • Third-Party Python Libraries: Forensic tools and Python libraries such as rarfile permit programmatic inspection of RAR headers, allowing you to manually identify and dump raw byte streams embedded inside the archive.