How Unrar Handles Partially Password Protected Archives
Extracting a multi-volume RAR archive containing a mix of
password-protected and unencrypted data requires understanding how the
unrar utility evaluates encryption blocks. When running
unrar, the tool reads archive segments sequentially,
extracting unprotected content immediately and pausing execution to
prompt for credentials only when it encounters an encrypted file payload
or an encrypted volume header.
Per-File Encryption vs. Header Encryption
In the RAR format, encryption can be applied either to individual file streams or to the entire archive header structure:
- File-Level Encryption: If encryption is applied
only to individual files,
unrarcan read the table of contents across all volumes. As extraction proceeds, any file that was packaged without a password extracts normally. The momentunrarreaches an encrypted file—even if it is located midway through a multi-volume sequence—the command-line interface halts and requests a password before continuing. - Header-Level Encryption: If a volume was created
with encrypted headers (using the
-hpswitch),unrarcannot read the filenames, file sizes, or metadata within that specific volume. Processing will immediately pause and demand a password the moment that volume is loaded, preventing any further reading until authentication is provided.
Spanned Files Across Multiple Volumes
When a single large file spans across multiple volumes (e.g.,
beginning in part1.rar and ending in
part2.rar), the encryption state applies to the entire file
stream:
- If the spanned file is encrypted,
unrarasks for the password at the start of that file's extraction. You cannot extract the segment located inpart1.rarwithout the password, even if other separate files in that volume are unencrypted. - If the spanned file is not encrypted, it unpacks across the boundaries of both volumes without a password prompt.
Non-Interactive and Automated Extraction
The default behavior of unrar is interactive, waiting
indefinitely for user input in the terminal when an encrypted volume or
file is encountered. In automated scripts, this behavior can be adjusted
using specific flags:
- Skipping Password Requests (
-p-): Passing the-p-flag tellsunrarnot to prompt for passwords. When it reaches an encrypted volume or file, it will skip it, output a permission/password error to standard error, and continue extracting the remaining unencrypted files. - Pre-supplying Credentials
(
-p<password>): Providing a password via the command line applies that password to all volumes. If only some files require this password,unraruses it when needed and silently unpacks the unencrypted files as normal.