Unrar vs WinRAR: Handling NTFS Alternate Data Streams
This article examines how the cross-platform command-line tool
unrar and the Windows GUI utility WinRAR process NTFS
Alternate Data Streams (ADS). While both tools share the underlying
RARLAB codebase, WinRAR provides native, integrated support for
preserving and restoring ADS within the Windows environment, whereas
unrar handles these streams differently depending on the
operating system, compilation options, and command-line parameters.
Understanding NTFS Alternate Data Streams
NTFS Alternate Data Streams allow files to contain multiple streams
of data under a single file descriptor. The default, unnamed stream
holds the primary file contents, while secondary named streams
(formatted as filename.ext:streamname) store additional
metadata, such as Windows Zone.Identifier ("Mark of the Web") tags,
document summary properties, or application-specific assets. Because ADS
is a specific feature of the NTFS file system, archival software must
explicitly support it to preserve these secondary streams during
compression and extraction.
WinRAR: Native Windows ADS Integration
WinRAR is designed primarily as a native Windows application with deep integration into NTFS file system capabilities:
- Archive Creation: When creating archives via
WinRAR, users can navigate to the Advanced tab and
check the "Save NTFS streams" option (corresponding to
the
-osswitch in the command line). This directs the archiver to bundle all secondary data streams alongside the base file data. - Extraction: When unpacking an archive containing ADS to an NTFS-formatted drive, WinRAR automatically restores these streams by default. If the destination is a non-NTFS partition (such as FAT32 or exFAT), WinRAR skips the streams and typically notifies the user that the target file system does not support the feature.
- Security Handling: Modern versions of WinRAR also interact deliberately with security-related streams. For example, if an archive carries a Zone.Identifier stream, WinRAR can apply or propagate this stream depending on security configurations and Windows Attachment Execution Service settings.
unrar: Command-Line and Cross-Platform Behavior
The handling of ADS by unrar depends primarily on the
platform on which the binary is compiled and executed:
- Windows Command-Line (
unrar.exe): On Windows,unrarshares the core logic of WinRAR. It can extract NTFS streams to an NTFS file system, but it typically requires the use of specific switches or matching configuration to ensure stream data is written properly. Using standard extraction commands without stream support enabled can result in only the primary stream being extracted. - Unix/Linux/macOS (
unrarsource build): On non-Windows systems, POSIX-compliant file systems (such as ext4, Btrfs, or APFS) do not natively implement NTFS-style Alternate Data Streams. Consequently:- By default, Unix ports of
unrarcompletely discard any NTFS ADS embedded within an archive. - The streams are ignored during extraction, and only the base, unnamed stream is written to the destination disk.
- Unlike macOS resource forks or Linux extended attributes (xattrs),
unrardoes not automatically translate NTFS secondary streams into native POSIX extended attributes without custom patches.
- By default, Unix ports of
Key Differences at a Glance
| Feature | WinRAR (Windows GUI/CLI) | unrar (Cross-Platform CLI) |
|---|---|---|
| Primary Platform | Microsoft Windows | Linux, macOS, Unix, Windows |
| ADS Extraction by Default | Yes (on NTFS targets) | Yes on Windows; No on non-Windows |
| Non-NTFS Destination | Skips ADS, warns user | Discards ADS silently or skips |
| Configuration Interface | GUI checkboxes and -os
switch |
Command-line switches only |
| Cross-Platform Parity | Restricted to Windows ecosystem | Stream metadata is dropped outside NTFS |
WinRAR offers an end-to-end mechanism for preserving NTFS secondary
streams directly inside Windows. In contrast, unrar
functions effectively for ADS only when running on a Windows environment
targeted at an NTFS volume, stripping these streams entirely when
deployed in standard Linux and Unix pipelines.