How unrar Handles Symbolic Links on Linux

This article explains how the unrar utility processes, extracts, and manages symbolic links (symlinks) within RAR archives on Linux systems. It covers default extraction behaviors, relevant command-line flags, security measures designed to prevent path traversal attacks, and the differences between standard RARLAB implementations and alternative packages.

When an archive containing symbolic links is extracted on a Linux system, the standard RARLAB unrar binary identifies symlink headers created by Unix-compatible archiving tools. By default, unrar recreates these symbolic links using standard POSIX symlink() system calls, pointing to the original relative or absolute targets recorded inside the archive.

If the target filesystem does not support symbolic links (such as FAT32) or if the user lacks the necessary write permissions, unrar outputs a warning and skips link creation without aborting the rest of the extraction process.

Relevant Command-Line Switches

unrar provides specific switches to alter how symlinks are handled:

  • -ol (Process symbolic links as links): Forces the utility to create actual filesystem symlinks rather than extracting them as regular files containing the target path string. In modern versions of RARLAB unrar, this behavior is enabled by default.
  • -ow (Process file security information): Restores owner and group information along with file attributes, which can apply to symbolic links if executed with root privileges.

Security and Path Traversal Safeguards

Historically, malicious archives used symbolic links pointing to critical system locations (such as /etc or parent directories via ../../) to overwrite protected files during extraction. Modern versions of unrar implement strict sanitization rules:

  1. Absolute Path Stripping: Targets with absolute paths (e.g., /usr/bin) are routinely stripped of their leading slashes or rejected to prevent arbitrary system modification.
  2. Directory Traversal Prevention: Links containing consecutive ../ sequences that attempt to resolve outside the extraction root directory are either sanitized, truncated, or dropped.
  3. Overwriting Protections: unrar refuses to follow an existing extracted symlink to overwrite target files located elsewhere on the host filesystem.

Proprietary unrar vs. unrar-free

Linux repositories typically offer two variants of the extraction tool:

  • unrar (non-free / RARLAB): Directly derived from the official RAR source code. It fully supports RAR4 and RAR5 formats, including proper recreation of symbolic links, hard links, and Unix permissions.
  • unrar-free: An open-source, reverse-engineered implementation. This package has limited format support (mostly older RAR versions) and frequently lacks proper handling for symbolic links, often ignoring link metadata entirely or extracting the link path as a standard text file.