How Unrar Handles Partially Password Protected Archives

Extracting a multi-volume RAR archive containing a mix of password-protected and unencrypted data requires understanding how the unrar utility evaluates encryption blocks. When running unrar, the tool reads archive segments sequentially, extracting unprotected content immediately and pausing execution to prompt for credentials only when it encounters an encrypted file payload or an encrypted volume header.

Per-File Encryption vs. Header Encryption

In the RAR format, encryption can be applied either to individual file streams or to the entire archive header structure:

  • File-Level Encryption: If encryption is applied only to individual files, unrar can read the table of contents across all volumes. As extraction proceeds, any file that was packaged without a password extracts normally. The moment unrar reaches an encrypted file—even if it is located midway through a multi-volume sequence—the command-line interface halts and requests a password before continuing.
  • Header-Level Encryption: If a volume was created with encrypted headers (using the -hp switch), unrar cannot read the filenames, file sizes, or metadata within that specific volume. Processing will immediately pause and demand a password the moment that volume is loaded, preventing any further reading until authentication is provided.

Spanned Files Across Multiple Volumes

When a single large file spans across multiple volumes (e.g., beginning in part1.rar and ending in part2.rar), the encryption state applies to the entire file stream:

  • If the spanned file is encrypted, unrar asks for the password at the start of that file's extraction. You cannot extract the segment located in part1.rar without the password, even if other separate files in that volume are unencrypted.
  • If the spanned file is not encrypted, it unpacks across the boundaries of both volumes without a password prompt.

Non-Interactive and Automated Extraction

The default behavior of unrar is interactive, waiting indefinitely for user input in the terminal when an encrypted volume or file is encountered. In automated scripts, this behavior can be adjusted using specific flags:

  • Skipping Password Requests (-p-): Passing the -p- flag tells unrar not to prompt for passwords. When it reaches an encrypted volume or file, it will skip it, output a permission/password error to standard error, and continue extracting the remaining unencrypted files.
  • Pre-supplying Credentials (-p<password>): Providing a password via the command line applies that password to all volumes. If only some files require this password, unrar uses it when needed and silently unpacks the unencrypted files as normal.