XZ to LZMA Converter
FileFlip converts XZ to LZMA entirely inside your browser, using libarchive compiled to WebAssembly. The file is never uploaded to a server: it is read off your disk, converted on your own machine, and saved back by the browser. That means no file-size limit, no queue and no account.
How do I convert an XZ file to LZMA?#
- Drop your XZ file onto the converter at the top of this page, or click it to pick one from your computer. You can add as many as you like.
- Leave the target set to LZMA and the conversion starts on its own. FileFlip downloads 1.0 MB of WebAssembly the first time and nothing after that, then runs libarchive on your own machine.
- Save the LZMA file. Your browser writes it straight to your downloads folder, because there was never a server holding it.
Does converting XZ to LZMA lose quality?#
No. Converting XZ to LZMA does not touch the files inside the archive. Each member is read out and written back byte for byte, so only the wrapper around them changes and nothing is recompressed.
Is it safe to convert XZ files online?#
Yes, because nothing is uploaded. FileFlip converts XZ files inside the browser tab you already have open, using WebAssembly builds of the same engines a desktop converter would install. Your file is read from your own disk into the page's memory, and no request carrying it is ever made.
You do not have to take that on trust. Open your browser's network panel, run a conversion, and you will see the engine come down and your file go nowhere. There is no upload, no server-side copy, no retention window, and no account tied to what you converted.
How FileFlip works lists every engine, its version and its download size, and shows how to check for yourself that nothing leaves your machine.
What XZ to LZMA actually does to the file#
Converting XZ to LZMA runs on libarchive, downloads 1.0 MB of WebAssembly the first time and nothing after that, copies the archived files through unchanged, keeps file contents.
| Engine | libarchive |
|---|---|
| Conversion path | 2 steps: XZ → the unpacked files → LZMA |
| Downloaded to your browser | 1.0 MB, once, then cached by your browser |
| Quality | Lossless, contents copied unchanged |
| You get back | One file |
| Where it runs | In a background worker, so the page stays responsive |
What survives the conversion
| What is in the file | This conversion | Why |
|---|---|---|
| File contents | Kept | Carried through into the converted file. |
| File timestamps | Sometimes | Survives for some files and not others. |
| File permissions | Sometimes | Survives for some files and not others. |
Worth knowing before you start:
- the output is a PAX tar archive inside the compressor, not a single compressed stream
- every entry is extracted into memory before anything is written, so a very large archive can exhaust it
What is an XZ file?#
An XZ file is a single stream compressed with LZMA2 inside a container that adds framing, size fields and a CRC or SHA-256 integrity check, specified by the Tukaani project's xz format starting in 2009.
Use XZ when the smallest practical archive size matters more than how long compression takes, which is why Linux distributions compress their packages and kernel source with it.
Convert XZ to GZ when the archive needs to decompress on something old or constrained enough that gzip's lighter decoder matters.
What is an LZMA file?#
An LZMA file is a single stream of data compressed with the raw LZMA algorithm inside its original, minimal container, the format that came before both the 7z and xz formats now built on the same compressor.
An LZMA file mostly turns up when opening something old rather than something worth creating new; xz supersedes it for anything being compressed today.
Convert an LZMA file to xz when it needs an integrity check or has to be re-shared, since xz is the actively maintained format built on the same compressor.
XZ to LZMA questions people ask#
Is xz the same as LZMA?
xz is a container format built around LZMA2, an improved version of the older LZMA algorithm, adding a proper file header, block structure and a CRC or SHA-256 integrity check that raw LZMA files never had. The Tukaani Project's .xz format specification was first released in 2009.
Why is xz compression so slow?
xz's LZMA2 algorithm searches harder for redundancy than gzip's DEFLATE or bzip2's Burrows-Wheeler transform, which is exactly what gives it a better compression ratio, but that search takes real CPU time and memory, especially at higher presets. Decompression doesn't carry this cost and stays fast.
Was the xz format itself compromised in the 2024 backdoor?
No. The 2024 incident, CVE-2024-3094, planted malicious code in the XZ Utils build scripts and the liblzma library in versions 5.6.0 and 5.6.1, not in the .xz file format itself. Files compressed as .xz were never the vector; the risk was in that specific compromised version of the software that reads and writes them.
Why do Linux distributions use .xz for packages?
xz compresses tighter than gzip or bzip2 on most data while still decompressing quickly, which matters because package managers decompress far more often than they compress. That ratio-versus-decompression-speed balance is why Debian, Fedora and the Linux kernel have shipped source and package archives as .xz for years.