Linux umask Command: Control Default File Permissions
umask sets the permission bits to be removed when the current shell and its child processes create new files or directories. It does not change the permissions of existing files.
What is the umask command?
The typical creation request permissions are 666 for files and 777 for directories. When umask 022 is applied, files are usually created as 644, and directories as 755. This is not a simple numeric subtraction but a method of removing mask bits from the allowed bits. If a program requests a more restrictive mode, the actual result will also be more limited.
Basic syntax
umask [-S] [mask]
Installed implementations and options may vary depending on the distribution. Check the description for the current system with help umask.
Examples
Check the current mask
Displays the octal mask applied to the shell.
umask
Check symbolically
Displays the currently allowed permissions in a human-readable form using characters.
umask -S
Current Shell New File Permission Restriction
Adjusts the restriction that will be applied to newly created files and directories. It does not apply to existing files.
umask 027 umask
Removing the mask from default permissions
In a fresh working directory, setting umask 027 in the shell removes group-write and other-user permissions from the maximum default of 666 for new regular files. The maximum default for new directories is 777. Run this example where the file and directory do not yet exist: touch does not recalculate permissions on an existing file.
umask 027 umask touch demo.txt mkdir demo-dir stat -c '%a %n' demo.txt demo-dir
Example output (when there are no additional policies like ACLs in the filesystem):
0027 640 demo.txt 750 demo-dir
umask applies to the current shell and its child processes and does not change permissions of existing files. Actual permissions are also affected by the mode requested by the program and ACL/filesystem policies, so check important paths with stat.
Umask masks requested permission bits; it is not ordinary decimal subtraction. Changing the mask cannot add an execute bit to a regular file if the creating program did not request one. Login shells, service managers, and containers may also set different masks.
Main Options and Format
| Options/Format | Description |
|---|---|
022 |
A common example that restricts group write and other user write. |
027 |
Restricts group write and all permissions for other users. |
-S |
Displays the current settings in symbolic form. |
-p |
Displays it in a form that can be re-executed in Bash. |
Precautions when using
umask is a Bash shell built-in command, so even if executed in a separate child shell, it does not change the settings of the parent shell. Newly created files do not necessarily start at 666, and the mode requested by the application as well as ACL and file system policies also affect the result. To change the permissions of existing files, use chmod.
Frequently Asked Questions
If you run umask 022, will existing files become 644?
No. After that, it only applies to the permission restrictions of items created by this shell and child processes.
Official Documentation
The exact behavior of the option and differences between implementations can be found in the official documentation on umask.









