Linux umask Command: Control Default File Permissions

umask sets the permission bits to be removed when the current shell and its child processes create new files or directories. It does not change the permissions of existing files.

What is the umask command?

The typical creation request permissions are 666 for files and 777 for directories. When umask 022 is applied, files are usually created as 644, and directories as 755. This is not a simple numeric subtraction but a method of removing mask bits from the allowed bits. If a program requests a more restrictive mode, the actual result will also be more limited.

Basic syntax

umask [-S] [mask]

Installed implementations and options may vary depending on the distribution. Check the description for the current system with help umask.

Examples

Check the current mask

Displays the octal mask applied to the shell.

umask

Check symbolically

Displays the currently allowed permissions in a human-readable form using characters.

umask -S

Current Shell New File Permission Restriction

Adjusts the restriction that will be applied to newly created files and directories. It does not apply to existing files.

umask 027
umask

Removing the mask from default permissions

In a fresh working directory, setting umask 027 in the shell removes group-write and other-user permissions from the maximum default of 666 for new regular files. The maximum default for new directories is 777. Run this example where the file and directory do not yet exist: touch does not recalculate permissions on an existing file.

umask 027
umask
touch demo.txt
mkdir demo-dir
stat -c '%a %n' demo.txt demo-dir

Example output (when there are no additional policies like ACLs in the filesystem):

0027
640 demo.txt
750 demo-dir

umask applies to the current shell and its child processes and does not change permissions of existing files. Actual permissions are also affected by the mode requested by the program and ACL/filesystem policies, so check important paths with stat.

Umask masks requested permission bits; it is not ordinary decimal subtraction. Changing the mask cannot add an execute bit to a regular file if the creating program did not request one. Login shells, service managers, and containers may also set different masks.

Main Options and Format

Options/Format Description
022 A common example that restricts group write and other user write.
027 Restricts group write and all permissions for other users.
-S Displays the current settings in symbolic form.
-p Displays it in a form that can be re-executed in Bash.

Precautions when using

umask is a Bash shell built-in command, so even if executed in a separate child shell, it does not change the settings of the parent shell. Newly created files do not necessarily start at 666, and the mode requested by the application as well as ACL and file system policies also affect the result. To change the permissions of existing files, use chmod.

Frequently Asked Questions

If you run umask 022, will existing files become 644?

No. After that, it only applies to the permission restrictions of items created by this shell and child processes.

Official Documentation

The exact behavior of the option and differences between implementations can be found in the official documentation on umask.

More in This Category
Linux more Command: View Text One Screen at a Time

Linux more Command: View Text One Screen at a Time

Learn how to use Linux more to read text one screen at a time, move and search interactively, start at a line or pattern, and choose between more and less.

Linux locate Command: Search Indexed File Paths Quickly

Linux locate Command: Search Indexed File Paths Quickly

Learn how Linux locate searches a filename database, how updatedb affects freshness, how to limit and filter matches, and when find is the better tool.

Linux pkill Command: Signal Processes by Name

Linux pkill Command: Signal Processes by Name

Learn how to signal Processes by Name with the Linux pkill command, including practical examples, key options, and important precautions.

Linux Tutorial / Understand Users, Groups, and File Ownership

Linux Tutorial / Understand Users, Groups, and File Ownership

Understand UIDs, GIDs, primary and supplementary groups, and file ownership, then inspect them safely with id, groups, getent, ls, and stat.

Linux whatis Command: Show One-Line Command Descriptions

Linux whatis Command: Show One-Line Command Descriptions

Learn how to use the Linux whatis command to display concise descriptions of commands and manual pages, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux resolvectl Command: Inspect systemd DNS Resolution

Linux resolvectl Command: Inspect systemd DNS Resolution

Learn how to inspect systemd DNS Resolution with the Linux resolvectl command, including practical examples, key options, and important precautions.

Linux Administration Memo: Essential Commands and System Checks

Linux Administration Memo: Essential Commands and System Checks

A compact Linux administration reference for checking system information, processes, storage, networking, users, permissions, services, and logs.

Linux Tutorial / Install and Update Packages with APT and DNF

Linux Tutorial / Install and Update Packages with APT and DNF

Compare APT on Debian or Ubuntu with DNF on Rocky Linux for searching, installing, updating, and removing packages, including repository and transaction checks.

Linux Tutorial / Read Files with cat, less, more, head, and tail

Linux Tutorial / Read Files with cat, less, more, head, and tail

Learn when to use cat, less, more, head, and tail to read Linux files, with a small reproducible example and guidance for long files and logs.

Linux mount Command: Inspect and Mount Filesystems

Linux mount Command: Inspect and Mount Filesystems

Learn how to inspect and Mount Filesystems with the Linux mount command, including practical examples, key options, and important precautions.