How Unrar Handles Password Protected Files

When the unrar utility processes a RAR archive featuring unencrypted headers containing individually password-protected files, it allows users to inspect the archive's contents freely but restricts the extraction of the protected payloads. This article outlines how unrar behaves during listing and extraction commands, how it handles interactive versus automated environments, and how errors are reported when an encrypted file is encountered.

Archive Structure: Encrypted Payloads vs. Encrypted Headers

RAR archives support two levels of encryption: encrypting both the file data and the file headers, or encrypting only the file data while leaving the headers visible. When headers are left unprotected, metadata such as filenames, file sizes, timestamps, and compression ratios remain in plaintext, while the actual file contents inside the compressed stream are encrypted.

Listing Archive Contents

Because the directory table and file headers are not encrypted, running listing commands does not require a password:

unrar l archive.rar
unrar v archive.rar

The command displays all filenames and metadata immediately without prompting for credentials. In the detailed view (unrar v), files that require a password typically display a flag indicating encryption (often marked with an asterisk * or a P attribute, depending on the tool version).

Extraction Behavior

When invoking extraction commands (unrar e or unrar x), the behavior depends on whether credentials are provided beforehand and the execution environment:

1. Interactive Mode

If no password is provided via the command line, unrar extracts any preceding unencrypted files normally. The moment it reaches an encrypted file, execution pauses and prints a prompt:

Enter password (will not be echoed):
  • Correct Password: The file decrypts and extracts to the destination path.
  • Incorrect Password: unrar attempts decryption, detects a checksum mismatch, and outputs an error such as Checksum error in file_name (wrong password?).
  • Cancellation: Pressing Ctrl+C terminates the extraction process entirely.

2. Non-Interactive / Scripted Environments

In automated scripts, cron jobs, or headless servers where standard input (stdin) is not connected to a terminal:

  • If no password flag is supplied, the process may hang waiting for input or abort immediately upon reaching the encrypted file.
  • Using the -p- switch tells unrar not to prompt for a password under any circumstance. When encountering an encrypted file, it automatically skips the file or terminates with a password error without halting script execution.
  • Supplying the password inline via -p<password> allows seamless extraction without an interactive prompt.

Partial Extraction and Error Status

If an archive contains a mixture of protected and unprotected files, unrar processes the items sequentially:

  • Files placed before the protected file in the archive are extracted without issues.
  • Files placed after the protected file will continue to be extracted if the user enters the correct password or if the tool is configured to skip errors.
  • If a password fails or is omitted, unrar returns a non-zero exit code upon termination (typically exit code 3 for a CRC error/corrupt data caused by an invalid password, or exit code 1 for general warnings), signaling failure to calling processes.