The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Create a tar archivetar -cf project.tar project/View examples
Archive relative namestar -C /srv/app -cf app.tar config publicView examples
Exclude generated filestar --exclude='*.log' --exclude='cache/' -cf app.tar \ app/View examples
List archive memberstar -tf project.tarView examples
Inspect stored metadatatar -tvf project.tarView examples
Extract an archivetar -xf project.tar -C destination/View examples
Extract one membertar -xf project.tar project/README.mdView examples
Remove a leading directorytar -xf release.tar -C destination/ --strip-components=1View examples
Ignore stored ownershiptar -xf backup.tar -C destination/ --no-same-ownerView examples
Create a gzip tarballtar -czf project.tar.gz project/View examples
Create an xz tarballtar -cJf project.tar.xz project/View examples
Select compression by suffixtar -caf project.tar.gz project/View examples
Extract compressed tartar -xf project.tar.gz -C destination/View examples
Compress and keep a filegzip -k report.csvView examples
Decompress to standard outputgzip -dc report.csv.gz | headView examples
Compress with xzxz -k report.csvView examples
Test gzip integritygzip -t project.tar.gzView examples
Test xz integrityxz -t project.tar.xzView examples
Verify a checksum filesha256sum --check project.tar.gz.sha256View examples
Review before extractionfile release.tar.gz && gzip -t release.tar.gz && tar -tf \ release.tar.gzView examples

Archiving combines files and metadata; compression reduces the resulting stream. List unfamiliar archives before extraction, choose an explicit destination, distrust embedded paths and ownership, and verify checksums from an authenticated source before treating an archive as genuine.

Step by step

Detailed examples

01

Store useful relative names and intentional content

tar records a tree of member names and metadata. Use -C to avoid archiving long host-specific source prefixes, and inspect exclusion patterns because they match stored names according to tar's rules. Do not archive a growing archive into itself, and remember an archive is not an independent backup until copied to appropriate separate storage.

Create a reproducible small project archive
mkdir -p project/config project/cache
printf '%s\n' 'mode=production' > project/config/app.conf
printf '%s\n' 'temporary' > project/cache/state.log
tar --exclude='cache/' -C project -cf project.tar config
Review what was stored
tar -tf project.tar
Output
config/
config/app.conf
Back to quick reference ↑
02

List before extracting unfamiliar content

tar -t reads the archive table of contents; -v adds metadata useful for spotting absolute-looking paths, unexpected parent traversal, device entries, ownership, or modes. Treat archive names and symlink targets as untrusted input. Listing reduces risk but does not replace using an updated extraction tool and an isolated destination.

Inspect member names and metadata
tar -tf project.tar
tar -tvf project.tar
Output
config/
config/app.conf
# Verbose output also includes type, mode, owner, size, and timestamp.
Back to quick reference ↑
03

Extract into a prepared destination

Create and inspect a destination, then pass it with -C rather than relying on the current directory. An exact member name extracts a subset. --strip-components is useful for release archives wrapped in one top-level directory, but can cause collisions after components are removed. Non-root extraction normally avoids restoring foreign owners; --no-same-owner makes that intent explicit.

Extract one reviewed archive into an empty directory
mkdir -p restored
tar -xf project.tar -C restored --no-same-owner
find restored -type f -print
Output
restored/config/app.conf
Back to quick reference ↑
04

Combine tar with an appropriate compressor

The z and J options filter an archive through gzip and xz respectively; -a asks GNU tar to infer compression from the output suffix. gzip is commonly fast and compatible, while xz often trades more CPU for smaller output. GNU tar can usually recognize compression when reading a seekable file, so -xf is sufficient for extraction.

Create and inspect two compressed archives
tar -czf project.tar.gz project/
tar -cJf project.tar.xz project/
tar -tf project.tar.gz | head
tar -tf project.tar.xz | head
Output
project/
project/config/
project/config/app.conf
project/cache/
project/cache/state.log
project/
project/config/
project/config/app.conf
project/cache/
project/cache/state.log
Back to quick reference ↑
05

Compress a single stream without wrapping it in tar

gzip and xz compress individual byte streams and normally replace a named input with a suffixed file. -k retains the original; -d decompresses and -c writes to standard output. Use tar first when directory structure, several files, permissions, or other metadata must travel together.

Keep originals and inspect decompressed output
printf '%s\n' alpha beta gamma > report.csv
gzip -k report.csv
gzip -dc report.csv.gz | head -n 2
xz -k report.csv
ls report.csv report.csv.gz report.csv.xz
Output
alpha
beta
report.csv
report.csv.gz
report.csv.xz
Back to quick reference ↑
06

Separate integrity checks from authenticity

gzip -t and xz -t detect corruption according to the compression format but do not establish who produced a file. sha256sum --check detects any byte change relative to a checksum list, but that list must arrive through a trusted channel or be authenticated by a signature. Verify before extraction and retain the exact failure output for diagnosis.

Create and verify a local checksum manifest
sha256sum project.tar.gz > project.tar.gz.sha256
sha256sum --check project.tar.gz.sha256
gzip -t project.tar.gz
Output
project.tar.gz: OK
Back to quick reference ↑
07

Use a review-first extraction workflow

Identify the file, test compression, list members, create a dedicated directory, extract without foreign ownership, and inspect the resulting tree. Never extract an untrusted archive as root merely to avoid permission errors. For hostile input, use a disposable sandbox with filesystem and privilege isolation appropriate to the threat model.

Review then extract
file release.tar.gz
gzip -t release.tar.gz
tar -tvf release.tar.gz | less
mkdir -p release-review
tar -xf release.tar.gz -C release-review --no-same-owner
find release-review -maxdepth 2 -print
Output
# Inspect each result before advancing to extraction.
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. GNU ProjectGNU tar Manualgnu.org
  2. Linux man-pages projecttar(1) — archiving utilityman7.org
  3. GNU ProjectGNU Gzip Manualgnu.org
  4. Tukaani ProjectXZ Utils Documentationtukaani.org

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback