Module 5 · Users, groups and permissions
umask and default permissions
Why new files are 644 and new directories 755, how the umask subtracts bits, and how to change it for one command or a whole session.
What you will learn
- Compute the mode of a new file or directory from the umask.
- Read and set the umask of the current shell, in octal and symbolic form.
- Use a subshell to apply a umask to a single command.
Where do 644 and 755 come from?
Programs that create files ask the kernel for a generous mode: 666 for a plain file (everyone may read and write), 777 for a directory. The kernel then removes whatever bits are set in the process's umask before creating the entry. The default umask is 022: remove write from group and others. 666 minus 022 gives 644; 777 minus 022 gives 755. That single number is why every file you have touched in this course came out -rw-r--r-- and every mkdir gave drwxr-xr-x.
"Minus" is a convenient lie: it is really a bitwise *clear*, so the mask can only take permissions away, never add them. That is why a new file never comes out executable whatever the umask: the request was 666, with no x to begin with. Programs must chmod +x explicitly, and compilers do.
| umask | New file | New directory | Meaning |
|---|---|---|---|
022 | 644 -rw-r--r-- | 755 drwxr-xr-x | Default: others may read, only you write |
002 | 664 -rw-rw-r-- | 775 drwxrwxr-x | Team work: the group may write too |
027 | 640 -rw-r----- | 750 drwxr-x--- | Group reads, others see nothing |
077 | 600 -rw------- | 700 drwx------ | Paranoid: everything private |
Reading and setting it
~% umask
0022
~% umask -S
u=rwx,g=rx,o=rx
~% umask 077
~% touch private.txt; mkdir private.d
~% ls -ld private.*
drwx------ 2 root root 0 Oct 4 19:25 private.d
-rw------- 1 root root 0 Oct 4 19:25 private.txt
~% umask 022
umask is a shell builtin, not a program, because the mask is a property of each process and children inherit it. Called alone it prints the current value with a leading zero; -S shows the same thing as the permissions that *survive*, which many people find easier to read. Called with a number it sets the mask for this shell and every command you start from it afterwards. It does not touch existing files.
Just for one command
Because the mask is inherited downwards but never upwards, a subshell is the clean way to apply it once: (umask 077; touch secret.txt) creates the file with mode 600 and leaves your interactive shell's umask untouched when the parentheses close. The same trick works for cd and for variables. To make a umask permanent you put the umask line in a startup file such as /etc/profile, which lesson 70 covers.
Commands in this lesson
| Command | What it does |
|---|---|
umask | Show the current mask in octal. |
umask -S | Show it as the permissions that survive. |
umask 077 | New files 600, new directories 700, from now on in this shell. |
umask 002 | Let the group write to new files and directories. |
(umask 077; touch FILE) | Apply a mask to one command only. |
grep Umask /proc/$/status | The kernel's view of this shell's mask. |
Quiz
With umask `027`, what mode does a new regular file get?
- `640`
- `750`
- `627`
Can a umask make new files executable?
- Yes, with `umask 000`
- No: it can only remove bits, and files are requested as 666
- Only for root
Why is `umask` a shell builtin rather than a program in /bin?
- For speed
- Because the mask belongs to each process; an external program could only change its own
- Because it needs root
What does `(umask 077; touch a.txt)` leave your shell's umask at?
- `077`
- Unchanged: the change happened in a subshell
- `000`
Practice
Save your shell's current umask, in its numeric form, into `/root/lab/l49/umask.txt`.
Create `/root/lab/l49/private.txt` so that it is born with mode `-rw-------`, by setting the right umask rather than using chmod afterwards.
Create the directory `/root/lab/l49/team` so that it is born as `drwxr-x---` (group may enter, others may not), using the umask.
Open this lesson in the app to do the tasks in a real Linux machine and have them checked.