How Unrar Handles Locked RAR Archives
This article explains how the unrar utility detects,
interprets, and processes archives marked with a locked status. While
the locked attribute permanently prevents changes to an archive’s
contents, unrar is specifically designed for decompression
rather than creation or modification. Understanding how the utility
reads header flags, executes extraction commands, and displays archive
metadata clarifies why extraction succeeds even when alteration is
blocked.
The Purpose of the Locked Flag in RAR Archives
The locked attribute is a security measure applied during or after
archive creation using the -k switch in the full
rar utility or WinRAR. Its sole purpose is to prevent
accidental or intentional changes, such as adding, deleting, updating,
or renaming files within the archive.
At the file structure level, this lock is stored as a specific bit flag inside the main archive header:
- In RAR 4.x formats, the archive header contains a flags field where
the bit mask
0x0004designates a locked archive. - In RAR 5.x formats, the lock property is defined within the main archive header block metadata.
How unrar Processes the Lock During Decompression
The unrar command-line program is a standalone
extraction tool compiled strictly with read and unpack routines; it
contains no code to write, modify, or append archive data. Because of
this architectural separation, unrar treats locked archives
with the following behavior:
- Header Parsing: When opening an archive,
unrarreads the main archive block to verify its integrity, check for encryption, and identify global flags. It reads the lock bit to determine the archive's state. - Standard Extraction Execution: Commands such as
unrar x(extract with full paths) andunrar e(extract to current directory) execute without restriction. The locked flag does not restrict read access, decompression algorithms, or checksum verification (CRC32 or BLAKE2sp). As long as the archive is not corrupted and any required decryption passwords are provided, unpacking proceeds normally. - Information and Listing: When using commands such
as
unrar l(list) orunrar v(verbose list), the utility parses the lock flag and prints the status to the terminal output (typically displayed asLockorArchive is lockedin the summary block).
Difference Between unrar and the Full rar Tool
The impact of the locked state is only observable when attempting
write operations. Because unrar inherently lacks commands
like a (add), d (delete), u
(update), or c (comment), it cannot trigger lock-related
errors.
If a user attempts modification using the standard rar
binary rather than unrar, the process aborts
immediately:
# Attempting to delete a file using the standard rar utility
rar d locked_archive.rar file.txtOutput:
Cannot modify locked archive
In contrast, running extraction via unrar:
# Extracting files remains unaffected
unrar x locked_archive.rarThe operation completes successfully because the locked flag restricts write operations on the archive container, not read or unpacking operations on the compressed streams inside it.