tar, one command per page
Twenty-nine commands for the tape archiver: the three letters c, t and x and why -f eats the next word, archiving and compression as two separate steps, the z j J zstd picker, auto-detection on extract, listing before you trust a tarball, -C and --strip-components and --one-top-level against the nested-directory dance and the tarbomb, the leading-slash warning, appending updating deleting comparing, --exclude and --wildcards, keeping old files safe, extracting one named file, the dash filename over pipes and ssh, ownership and permissions of what lands on disk, and the classic mistakes tally.
A diagram, the mechanism, and one command to try today. That's a page.
tar, one command per page
Twenty-nine commands for the tape archiver: the three letters c, t and x and why -f eats the next word, archiving and compression as two separate steps, the z j J zstd picker, auto-detection on extract, listing before you trust a tarball, -C and --strip-components and --one-top-level against the nested-directory dance and the tarbomb, the leading-slash warning, appending updating deleting comparing, --exclude and --wildcards, keeping old files safe, extracting one named file, the dash filename over pipes and ssh, ownership and permissions of what lands on disk, and the classic mistakes tally.
Set in Space Grotesk, Inter and JetBrains Mono (SIL Open Font License).
General information only. Every command, flag and behaviour in this book is as the GNU tar manual (version 1.35.90, gnu.org) and the man7.org tar(1) page state it, fetched and read during this build; no facts are sourced from forum threads. Behaviour can differ on non-GNU tar implementations (notably BusyBox and BSD tar); the book says GNU tar when it matters.
Your purchase is for personal use only. You do not have redistribution rights: please do not share, resell, or republish this book or its pages.
© 2026 Steve Hodgkiss. All rights reserved. Personal use only; no redistribution rights.
Edition 1.0 · stevehodgkiss.net
Contents
The core
The heart of tar: the c t x letters, why -f takes the next word, creating your first archive, listing before trusting it, extracting, and verbosity on both sides.
- 01Two steps, not one
- 02The three letters
- 03Why -f eats a word
- 04Look first, then open
- 05The extract letter
Per the GNU tar manual (gnu.org, version 1.35.90), tutorial chapter on creating archives and the chapter on compressed archives: tar bundles many files into one archive stream; compression is a separate filter over that stream. The compression options -z --gzip, -j --bzip2, -J --xz and --zstd filter the archive through the named compressor. Compressed archives cannot be modified: you cannot update, delete or append members.
Two steps, not one
tar does one job: it wraps many files into one stream. gzip, bzip2, xz and zstd do the second job: they squeeze that stream. A .tar.gz is both jobs stapled together, and knowing they are separate explains almost every quirk.
The letters -z -j -J just pick the squeezer. And because the squeezer runs over the whole stream, you cannot update or delete inside a compressed archive. Unwrap first, edit, re-squeeze.
Two tools, one filename. That's the whole idea.
Today, run tar cf plain.tar on a small directory, then gzip it separately. Notice nothing breaks: the steps really are separate.
Per the GNU tar manual (gnu.org, 1.35.90), operations chapter: the three principal operations are --create (-c), --list (-t) and --extract (-x). Only one operation per invocation; the manual's synopsis chapter states tar requires exactly one of them.
The three letters
Everything starts with one letter. c creates an archive, t lists what's inside, x extracts it. One operation per command: you never pack and peek in the same breath.
The classic confusion, remembering which letter, dissolves when you read them as verbs: create, lisT, eXtract. The rest of the command line just modifies whichever verb you picked.
c writes, t reads, x writes back out. Pick the verb first, everything else follows.
Type the three commands on a scratch directory today: tar cf, then tar tf, then tar xf. Three letters, one loop.
Per the GNU tar manual (gnu.org, 1.35.90), the file option chapter: -f archive-name specifies the archive file; without it tar examines the TAPE environment variable and falls back to a default device, a leftover from tape drives. The argument to -f is the next word on the command line.
Why -f eats a word
-f means: the next word is the archive. That's why it's -cf backup.tar and not -c backup.tar. Forget -f and tar reaches for a tape drive, or the TAPE variable, a leftover from when archives literally lived on tape.
So the folk mnemonic unfolds: c the verb, f the file, then the files. The order matters because f's argument is whatever follows it, immediately.
-f is not decoration. It's the difference between backup.tar and /dev/rmt0.
Run tar -cvf today with the words spaced out on paper first: verb, file, inputs. You'll never misplace the filename again.
Per the GNU tar manual (gnu.org, 1.35.90), list chapter and the extracting-from-untrusted-sources section: tar -tf archive.tar prints the stored member names; if you have forgotten the correct names, use tar --list to list them correctly; member names must be given exactly as --list prints them. The manual warns about archives from untrusted sources and advises precautions before extracting.
Look first, then open
tar -tf costs nothing and tells you everything: the layout, the top folder, whether stray files sit at the root. Extracting is the expensive direction, because it writes to your disk exactly where the names say.
A tarbomb is an archive whose members have no shared top folder, so it scatters across your working directory. Reading the listing first is the entire defence, and it's free.
t is a window. x is a door. Look through the window first.
Before your next extract, run tar -tf on the file and read every line. Ten seconds, zero surprises.
Per the GNU tar manual (gnu.org, 1.35.90), extract chapter: tar -xf archive.tar extracts members into the current working directory; directories are created as needed; member names are relative as stored. The chapter notes the practice directory will be created if it didn't already exist.
The extract letter
tar -xf writes members out relative to where you stand, not where the archive lives. Names stored relative come out relative: that's why the tarball seems to explode into your directory if you weren't looking.
Missing directories are created on arrival. Nothing is fetched from anywhere special; the archive is just a list of names and bytes, replayed here.
cd first, extract second. The command has no other idea of place.
Make an empty directory today, cd into it, extract there. Feel how place is entirely your job.
Per the GNU tar manual (gnu.org, 1.35.90), auto-compress section: --auto-compress (-a) on create selects the compression from the archive filename suffix; recognized suffixes include .tar.gz and .tgz for gzip, .tar.bz2, .tar.xz; the manual's suffix table lists taz and tgz among recognized short forms.
Reading the suffix
.tgz and .tar.gz are the same thing: the short form is a historical filename squeeze, the format identical. Same for .tbz2 and .txz. Read the suffix right to left: the last extension names the squeezer.
Create in the same spirit with -a: tar -caf backup.tgz sees the suffix and picks gzip for you. The filename becomes the instruction.
The suffix is documentation the tools already read. Name files honestly and -a does the rest.
Rename a copy of a .tar.gz to .tgz today and list it. Identical contents: proof the suffix was only ever a label.
Per the GNU tar manual (gnu.org, 1.35.90), modifying file and member names chapter: --strip-components=number strips the given number of leading directory components from member names on extraction; the manual's example extracts folk from music.tar with --strip-components=1.
The strip trick
Every tarball seems to have that one wrapper folder, project-1.2, that nests wrong. --strip-components=1 drops the first path segment from every member on the way out, so the contents land directly where you stand.
Count carefully: the number is how many leading parts to remove, applied to every member uniformly. A mixed-depth archive strips badly; check with t first.
One flag dissolves the wrapper folder. Look before you strip, because depth must be uniform.
Download any release tarball today and extract it twice: once plain, once with --strip-components=1 into a scratch dir. Compare trees.
Per the GNU tar manual (gnu.org, 1.35.90), extracting specific files chapter: name archive members exactly as --list prints them to extract them; tar --extract --file=archive member/path takes out just the named members; -O --to-stdout extracts to standard output instead of writing files.
The single file pull
You never have to unpack the whole thing. tar -xf archive.tar path/to/one-file lifts out exactly that member, using the name exactly as t printed it. No leading ./ fudging, no guessing.
Want it without even touching the disk? -O pours the member to stdout: pipe it into less, diff, or another command. The archive becomes a lookup, not an unpack.
List, copy the name, extract it. Three commands, one file, zero mess.
Pull one config file out of an old archive today with its exact member name. Then try it again with -O into less.