In rsync, what does the `-a` (archive) option expand to, what does it deliberately not preserve, and which part of it silently does nothing unless the transfer runs with superuser rights?
answer
- seven letters, not a mode
- the one letter that changes performance
- hard links are not in the set
- chown is a privileged operation
- names versus numbers across hosts
basics
~20 srsync's -a is shorthand for -rlptgoD: recurse, copy symlinks as symlinks, preserve permissions, times, group, owner, and device and special files. It does not cover hard links (-H), ACLs (-A), extended attributes (-X) or sparse files (-S), and preserving owner requires superuser rights on the receiving side.
solid answer
~50 s`-a` is not a mode, it is an abbreviation for `-rlptgoD`: recurse into directories, recreate symlinks as symlinks, preserve permissions, modification times, group, owner, and device and special files. What people get wrong is what it leaves out — hard links are only preserved with `-H`, ACLs with `-A`, extended attributes with `-X`, and sparse files are only kept sparse with `-S`. It also does not imply `-x` (`--one-file-system`), so an archive-mode copy of `/` will happily descend into every mount below it. And `-o` is aspirational unless the receiving side is running with the privilege to chown: as an ordinary user the files simply come out owned by you, with no error. `-g` has the same shape — you can only set groups you are entitled to set. On a cross-host copy where the user and group databases differ, add `--numeric-ids` so rsync matches by ID rather than by name.
go deeper
Know that -a is the everyday option for copying a tree, that it stands for a group of preservation flags, and that it recurses. Being able to expand it as -rlptgoD already puts you ahead at this level.
Explain each letter, and more importantly what is missing: -H, -A, -X, -S and -x. Point out that -t is what keeps repeat runs cheap, because the quick check compares size and mtime.
Show that you have been burned: ownership failing silently without privilege, --numeric-ids for restores onto rebuilt hosts, --fake-super for unprivileged backups, and subtracting with --no-o --no-g for deploys where the service account should own the files.
Decide the fidelity contract. State what your backups are required to restore — content only, or ownership, ACLs and labels — and therefore whether backup agents get privilege on the destination, since that decision sets the recovery guarantee for the whole estate.
## What `-a` really is `-a` is pure shorthand. rsync expands it to `-rlptgoD`, and every one of those letters is separately available: | letter | long form | meaning | |---|---|---| | `-r` | `--recursive` | descend into directories | | `-l` | `--links` | copy symlinks as symlinks | | `-p` | `--perms` | preserve permission bits | | `-t` | `--times` | preserve modification times | | `-g` | `--group` | preserve group | | `-o` | `--owner` | preserve owner | | `-D` | `--devices --specials` | recreate device nodes, fifos and sockets | Because it is shorthand, you can subtract from it: `-a --no-o --no-g` is archive mode without ownership, which is the usual form when pushing content as an unprivileged deploy user. `-a --no-p` drops permission preservation, and so on. ## The `-t` letter is the load-bearing one Of the seven, `-t` is the one that changes rsync's *performance* rather than just the resulting metadata. rsync's default file-selection rule — the quick check — skips a file when its size and modification time match on both sides. If times are not preserved, every destination file gets a fresh mtime as it lands, so on the next run every file looks different and the entire tree transfers again. This is why `rsync -r` on a schedule feels broken and `rsync -a` does not. ## What archive mode does not cover This is the part interviewers are really asking about, because "`-a` preserves everything" is the common wrong belief. - **Hard links (`-H`, `--hard-links`).** Without it, two directory entries pointing at one inode arrive as two independent files, and the destination is larger than the source. `-H` is not in `-a` because it costs memory and bookkeeping proportional to the tree. - **ACLs (`-A`, `--acls`).** Extra access entries beyond the classic mode bits are dropped unless you ask for them; `-A` implies `-p`. The destination filesystem must also support them. - **Extended attributes (`-X`, `--xattrs`).** Anything stored as an xattr is not carried by `-a`. On systems that keep security labels in xattrs, that matters — and copying labels between hosts is often not what you want anyway. - **Sparse files (`-S`, `--sparse`).** Without it, a file with large holes is written out solid at the destination, which can turn a nominally small image into a full-size one. - **`--one-file-system` (`-x`).** Archive mode recurses across mount points. Copying `/` with `-a` and no `-x` will descend into every mounted filesystem underneath, including network mounts. - **Atime** is not preserved by `-a` at all — `-U`/`--atimes` exists in rsync 3.2+, but access times are rarely worth preserving and reading the source updates them anyway unless the filesystem is mounted `noatime`. ## Ownership needs privilege, and fails quietly `-o` asks the receiving side to `chown` each file to the source's owner. Changing a file's owner to somebody else is a privileged operation, so an unprivileged receiver simply cannot do it. rsync does not abort — the files land owned by the transferring user, and the run reports success. The same logic applies to `-g` for groups you are not a member of, and to setuid/setgid bits under `-p`. Three things follow: 1. If ownership matters, the receiving side must be privileged. `--rsync-path='sudo rsync'` is the usual mechanism when logging in as an ordinary account, paired with a narrow sudo rule. 2. Across hosts, add **`--numeric-ids`**. By default rsync maps owners and groups by *name*, looking the name up on the receiver. If the two hosts assign different numeric IDs to the same name, or the name does not exist there, the result is silently different from the source. `--numeric-ids` transfers the raw IDs instead, which is what you want for a backup you may restore onto a rebuilt host. 3. `--fake-super` is the escape hatch for backing up a tree as an unprivileged user: rsync stores the ownership and other privileged metadata in extended attributes on the destination and reconstitutes it on the way back. ## A practical default set For a backup where fidelity is the point: `-aHAX --numeric-ids` (plus `-S` if the tree holds sparse images), run with privilege on the receiving side. For a deploy where you only want the content: `-a --no-o --no-g --delete`, so the files land owned by the service account and the destination is pruned to match. Say which one you are doing before you pick the flags — the two goals want genuinely different commands.
- You run `rsync -a` as an ordinary user and the destination files come out owned by you. Was there an error?No, and that is the trap. `-o` asks the receiver to chown files to the source's owner, which an unprivileged process cannot do, so rsync silently keeps your ownership and exits successfully. If ownership matters, the receiving side must be privileged — commonly via `--rsync-path='sudo rsync'` — or use `--fake-super` to stash the metadata in extended attributes for a later privileged restore.
- Why is `--numeric-ids` recommended for cross-host backups?Without it rsync maps ownership by name: it sends the owner's name and the receiver looks up the corresponding local ID. If the hosts disagree about which UID a name has, or the account does not exist there, files land owned by the wrong principal with no warning. `--numeric-ids` transfers raw IDs, which is what a restore onto a rebuilt machine needs.
- What breaks if you use `-r` instead of `-a` on a scheduled job?`-r` gives you recursion and nothing else, so modification times are not preserved. rsync's default quick check compares size and mtime, and every file lands with a fresh mtime — so the next run considers every file changed and re-transfers the whole tree. Permissions and symlinks are also lost. `-a` (or at least adding `-t`) is what makes repeat runs cheap.
saying these in an interview costs you the question
- Claims -a preserves hard links and ACLs
- Thinks -a implies --one-file-system
- Expects an error when ownership cannot be set
- Uses -r on a scheduled sync and wonders why it is slow
- Assumes owner names mean the same UID on every host