Read

Module 5 · Users, groups and permissions

umask and default permissions

Why new files are 644 and new directories 755, how the umask subtracts bits, and how to change it for one command or a whole session.

What you will learn

  • Compute the mode of a new file or directory from the umask.
  • Read and set the umask of the current shell, in octal and symbolic form.
  • Use a subshell to apply a umask to a single command.

Where do 644 and 755 come from?

Programs that create files ask the kernel for a generous mode: 666 for a plain file (everyone may read and write), 777 for a directory. The kernel then removes whatever bits are set in the process's umask before creating the entry. The default umask is 022: remove write from group and others. 666 minus 022 gives 644; 777 minus 022 gives 755. That single number is why every file you have touched in this course came out -rw-r--r-- and every mkdir gave drwxr-xr-x.

"Minus" is a convenient lie: it is really a bitwise *clear*, so the mask can only take permissions away, never add them. That is why a new file never comes out executable whatever the umask: the request was 666, with no x to begin with. Programs must chmod +x explicitly, and compilers do.

umaskNew fileNew directoryMeaning
022644 -rw-r--r--755 drwxr-xr-xDefault: others may read, only you write
002664 -rw-rw-r--775 drwxrwxr-xTeam work: the group may write too
027640 -rw-r-----750 drwxr-x---Group reads, others see nothing
077600 -rw-------700 drwx------Paranoid: everything private

Reading and setting it

~% umask
0022
~% umask -S
u=rwx,g=rx,o=rx
~% umask 077
~% touch private.txt; mkdir private.d
~% ls -ld private.*
drwx------    2 root     root             0 Oct  4 19:25 private.d
-rw-------    1 root     root             0 Oct  4 19:25 private.txt
~% umask 022

umask is a shell builtin, not a program, because the mask is a property of each process and children inherit it. Called alone it prints the current value with a leading zero; -S shows the same thing as the permissions that *survive*, which many people find easier to read. Called with a number it sets the mask for this shell and every command you start from it afterwards. It does not touch existing files.

Just for one command

Because the mask is inherited downwards but never upwards, a subshell is the clean way to apply it once: (umask 077; touch secret.txt) creates the file with mode 600 and leaves your interactive shell's umask untouched when the parentheses close. The same trick works for cd and for variables. To make a umask permanent you put the umask line in a startup file such as /etc/profile, which lesson 70 covers.

Commands in this lesson

CommandWhat it does
umaskShow the current mask in octal.
umask -SShow it as the permissions that survive.
umask 077New files 600, new directories 700, from now on in this shell.
umask 002Let the group write to new files and directories.
(umask 077; touch FILE)Apply a mask to one command only.
grep Umask /proc/$/statusThe kernel's view of this shell's mask.

Quiz

  1. With umask `027`, what mode does a new regular file get?

    • `640`
    • `750`
    • `627`
  2. Can a umask make new files executable?

    • Yes, with `umask 000`
    • No: it can only remove bits, and files are requested as 666
    • Only for root
  3. Why is `umask` a shell builtin rather than a program in /bin?

    • For speed
    • Because the mask belongs to each process; an external program could only change its own
    • Because it needs root
  4. What does `(umask 077; touch a.txt)` leave your shell's umask at?

    • `077`
    • Unchanged: the change happened in a subshell
    • `000`

Practice

  1. Save your shell's current umask, in its numeric form, into `/root/lab/l49/umask.txt`.

  2. Create `/root/lab/l49/private.txt` so that it is born with mode `-rw-------`, by setting the right umask rather than using chmod afterwards.

  3. Create the directory `/root/lab/l49/team` so that it is born as `drwxr-x---` (group may enter, others may not), using the umask.

Open this lesson in the app to do the tasks in a real Linux machine and have them checked.