umask Explained

umask Explained

umask quietly decides the permissions every new file and directory gets the moment it is created, before you ever run chmod on it yourself. Most people never touch it, and most people also never quite understand why their new files consistently show up as 644 and new directories as 755. This is why.

What umask actually does

umask
# 0022

umask does not directly set permissions. It sets a mask, a value that gets subtracted from a maximum default permission, to determine what a newly created file or directory actually receives.

Maximum default for new FILES:       666  (rw-rw-rw-)
Maximum default for new DIRECTORIES: 777  (rwxrwxrwx)

umask value:                          022

New file result:       666 - 022 = 644  (rw-r--r--)
New directory result:  777 - 022 = 755  (rwxr-xr-x)

The subtraction is not simple arithmetic; it is a bitwise operation that removes exactly the bits set in the umask value from the maximum. In practice, thinking of it as “removes these permissions” for whichever bits are set in the mask is close enough for everyday use.

Why files never get execute permission from umask alone

umask 000
touch newfile.txt
ls -l newfile.txt
# -rw-rw-rw- 1 colton colton 0 Jul  9 newfile.txt
# (no execute bit anywhere, even with umask completely disabled)

This is a deliberate and important safety detail: the maximum starting point for files is 666, which never includes execute permission at all, regardless of what the umask value is set to. Since umask can only subtract from that starting maximum and never add permissions beyond it, a newly created file can never become executable purely as a side effect of umask, no matter how permissive the value. Execute permission on a file always has to be added deliberately afterward with chmod +x.

Directories are different, since their maximum starting point (777) does include execute, which is why new directories commonly end up executable (browsable) by default while new files do not.

Checking your current umask

umask
# 0022

umask -S
# u=rwx,g=rx,o=rx

Plain umask shows the raw numeric mask. umask -S (symbolic) shows the resulting effective permission pattern directly, which many people find easier to reason about at a glance than the subtraction math.

Common umask values

umask 022    # the typical default: files 644, directories 755
umask 027    # stricter: files 640, directories 750, nothing for "other"
umask 077    # very strict: files 600, directories 700, owner only
umask 002    # more permissive for group: files 664, directories 775

022 is the standard default on most distributions, striking a balance where new files are readable by everyone but writable only by the owner. 027 and 077 are common tightenings used on servers handling sensitive data, where the assumption that every other user on the system should at least be able to read a newly created file is considered too permissive. 002 is sometimes used on systems where collaborative group work is the norm and the group should have the same write access as the owner.

Changing umask for the current session only

umask 027
touch testfile.txt
ls -l testfile.txt
# -rw-r----- 1 colton colton 0 Jul  9 testfile.txt

Running umask directly in a terminal changes the value only for that shell session. Opening a new terminal, or logging in again, reverts to whatever the default is configured to be elsewhere.

Making a umask change permanent

# Per-user: add to your shell startup file
echo "umask 027" >> ~/.bashrc

# System-wide: affects every user's default
sudo nano /etc/profile
# or, on some distributions, the default is set in:
sudo nano /etc/login.defs

For a change that should apply every time you open a new terminal, add the umask command to your shell’s startup file, ~/.bashrc for bash on most distributions. For a change that should apply to every user on the system by default, the setting typically belongs in a system-wide file like /etc/profile or /etc/login.defs, depending on the distribution.

umask in practice: why this matters for shared directories

umask 002
mkdir shared_project
touch shared_project/notes.txt
ls -l shared_project/notes.txt
# -rw-rw-r-- 1 colton developers 0 Jul  9 notes.txt
# (group has write access automatically, thanks to umask 002)

Setting a more permissive umask specifically around group write access is a common technique for shared team directories, so that every new file any team member creates is automatically group-writable from the moment it is created, without anyone needing to remember to run chmod g+w manually every single time.

Frequently Asked Questions

What does umask do?

umask sets a default mask that determines what permissions new files and directories get automatically, without you needing to run chmod manually every time. It works by subtracting (technically, masking out) permission bits from the maximum default that a new file or directory would otherwise receive.

Why do new files typically get 644 permissions and new directories get 755, if I never ran chmod?

The system starts with a maximum default of 666 (rw-rw-rw-) for new files and 777 (rwxrwxrwx) for new directories, then subtracts whatever the current umask value specifies. A common umask of 022 subtracts write permission for group and other, turning the file default of 666 into 644, and the directory default of 777 into 755. This is why those two specific numbers show up so consistently across new files and directories without anyone running chmod manually.

Why do new files never get execute permission by default even if umask is 000?

The maximum starting point for files is 666, which never includes execute permission in the first place, regardless of what umask subtracts. This is a deliberate safety default: umask can only remove permissions from that starting point, never add ones that were not part of the maximum to begin with, so a freshly created file cannot become executable purely through umask, no matter how permissive the umask value is set.

How do I check my current umask value?

Run umask with no arguments, which prints the current value, typically something like 0022. Running umask -S instead prints a symbolic, more human-readable form directly showing which permissions are being masked out for each of the owner, group, and other categories.

How do I change umask permanently instead of just for the current session?

Add a umask command to your shell’s startup file, typically ~/.bashrc or ~/.profile for a per-user change, or /etc/profile or /etc/login.defs for a system-wide default affecting every user. A line like umask 027 in .bashrc sets that value every time a new shell session starts for that user.

What is a common stricter umask value and why would someone use it?

umask 027 is a common stricter alternative to the default 022. It results in new files being created as 640 (rw-r-----) and new directories as 750 (rwxr-x---), removing all access for anyone outside the owner and owning group entirely. This is common on servers handling sensitive data, where the default of letting every user on the system at least read new files is considered too permissive.