How Unrar Handles Password Protected Files
When the unrar utility processes a RAR archive featuring
unencrypted headers containing individually password-protected files, it
allows users to inspect the archive's contents freely but restricts the
extraction of the protected payloads. This article outlines how
unrar behaves during listing and extraction commands, how
it handles interactive versus automated environments, and how errors are
reported when an encrypted file is encountered.
Archive Structure: Encrypted Payloads vs. Encrypted Headers
RAR archives support two levels of encryption: encrypting both the file data and the file headers, or encrypting only the file data while leaving the headers visible. When headers are left unprotected, metadata such as filenames, file sizes, timestamps, and compression ratios remain in plaintext, while the actual file contents inside the compressed stream are encrypted.
Listing Archive Contents
Because the directory table and file headers are not encrypted, running listing commands does not require a password:
unrar l archive.rar
unrar v archive.rarThe command displays all filenames and metadata immediately without
prompting for credentials. In the detailed view (unrar v),
files that require a password typically display a flag indicating
encryption (often marked with an asterisk * or a
P attribute, depending on the tool version).
Extraction Behavior
When invoking extraction commands (unrar e or
unrar x), the behavior depends on whether credentials are
provided beforehand and the execution environment:
1. Interactive Mode
If no password is provided via the command line, unrar
extracts any preceding unencrypted files normally. The moment it reaches
an encrypted file, execution pauses and prints a prompt:
Enter password (will not be echoed):
- Correct Password: The file decrypts and extracts to the destination path.
- Incorrect Password:
unrarattempts decryption, detects a checksum mismatch, and outputs an error such asChecksum error in file_name (wrong password?). - Cancellation: Pressing
Ctrl+Cterminates the extraction process entirely.
2. Non-Interactive / Scripted Environments
In automated scripts, cron jobs, or headless servers where standard
input (stdin) is not connected to a terminal:
- If no password flag is supplied, the process may hang waiting for input or abort immediately upon reaching the encrypted file.
- Using the
-p-switch tellsunrarnot to prompt for a password under any circumstance. When encountering an encrypted file, it automatically skips the file or terminates with a password error without halting script execution. - Supplying the password inline via
-p<password>allows seamless extraction without an interactive prompt.
Partial Extraction and Error Status
If an archive contains a mixture of protected and unprotected files,
unrar processes the items sequentially:
- Files placed before the protected file in the archive are extracted without issues.
- Files placed after the protected file will continue to be extracted if the user enters the correct password or if the tool is configured to skip errors.
- If a password fails or is omitted,
unrarreturns a non-zero exit code upon termination (typically exit code3for a CRC error/corrupt data caused by an invalid password, or exit code1for general warnings), signaling failure to calling processes.