How Unrar Handles Alternate Data Streams on Linux
This article explains how the Linux version of the unrar
utility processes archives containing NTFS Alternate Data Streams (ADS).
While Windows systems use ADS to store metadata, resource forks, or
hidden data alongside primary file contents, Linux filesystems use
different architectural models, such as extended attributes. Below is an
overview of how unrar handles these secondary streams
during extraction on a Linux host, the technical reasons behind its
behavior, and how to access the underlying data if needed.
What Are Alternate Data Streams in RAR Archives?
Alternate Data Streams are a feature of the Windows New Technology
File System (NTFS). They allow an individual file to hold multiple
streams of data: the primary, unnamed data stream (the standard file
contents) and one or more named streams accessed via the
filename:streamname syntax.
When WinRAR or the Windows command-line RAR tool compresses files,
users can pass the -os switch to capture these secondary
streams inside the archive. This is commonly used to preserve
Windows-specific metadata, zone identifiers (web download markers), or
custom application data.
Default Behavior of Linux
unrar
When running the official RARLAB unrar binary (or the
open-source unrar-free utility) on Linux:
- Streams Are Skipped or Discarded: By default, Linux
unrarextracts only the primary unnamed data stream. It reads the archive headers, recognizes the standard file data, and ignores the stream data chunks assigned to alternate streams. - No xattr Conversion: Linux utilizes Extended
Attributes (
xattr) for file metadata, butunrardoes not translate NTFS streams into Linux extended attributes. - No Colon-Delimited File Creation: While Linux
filesystems (such as ext4, Btrfs, and XFS) permit colons
(
:) in filenames,unrardoes not attempt to create standalone files using thefilename:streamnameconvention to preserve the extra data.
Because of this behavior, extracting an archive on Linux that relies on secondary streams will quietly result in the loss of all stream data, while the main file contents remain intact.
Why Linux unrar
Discards ADS
- Filesystem Incompatibility: The Virtual File System (VFS) in the Linux kernel does not support the multi-stream file model of NTFS.
- Path Traversal and Security Risks: Automatically unpacking alternate streams into distinct Linux files using colons could overwrite existing files or introduce security vulnerabilities, especially if an archive contains streams designed to mimic system paths.
- Tool Design: RARLAB’s Unix version of
unraris compiled with cross-platform compatibility in mind. Its extraction engine maps standard POSIX file permissions and timestamps, but excludes Windows-exclusive subsystems like NTFS streams unless specifically targeting a Windows environment.
Security and Data Integrity Implications
- Data Loss: If an application relies on secondary streams (such as specific audio tagging tools, graphic design software, or legacy backup tools), extracting the archive on Linux will strip that information without throwing a fatal extraction error.
- Security Shielding: Malicious payloads hidden inside alternate data streams to bypass antivirus software on Windows are neutralized on Linux. Because the streams are not unpacked, the hidden data cannot be written to disk.
Methods to Access ADS Data on Linux
If you must extract and read the contents of Alternate Data Streams on a Linux machine, consider the following alternatives:
- Use 7-Zip (
7zorp7zip): Some versions of7zon Linux allow extracting alternate streams as separate files. Using the-snsswitch (store/restore NTFS streams) instructs the unpacker to extract streams as separate files using thefilename:streamnamenaming scheme. - Run WinRAR Under Wine: Running the official Windows
console or GUI version of WinRAR via Wine allows the utility to execute
its native Windows stream-handling logic. If extracted to an
NTFS-formatted drive mounted with
ntfs-3g, the streams can be written directly to the filesystem. - Third-Party Python Libraries: Forensic tools and
Python libraries such as
rarfilepermit programmatic inspection of RAR headers, allowing you to manually identify and dump raw byte streams embedded inside the archive.