What is Umask in Linux?
In Linux and Unix-like operating systems, umask (user file-creation mode mask) is a environment setting that determines default permissions assigned to newly created files and directories.
Instead of adding permissions, umask acts as a filter that removes (masks) permissions from base initial values:
- Base default for Files:
666(rw-rw-rw-) — files are created without execution bits by default. - Base default for Directories:
777(rwxrwxrwx) — directories require execution bits to allow navigation.
How Umask Calculation Works
The effective permission is calculated by performing a bitwise NOT operation on the umask, then performing a bitwise AND with the base permission:
Effective Permission = Base Permission AND (NOT umask)
| Umask | Effective File Permission | Effective Directory Permission | Security Use Case |
|---|---|---|---|
022 | 644 (-rw-r--r--) | 755 (drwxr-xr-x) | Standard Linux default (Owner read/write, public read) |
027 | 640 (-rw-r-----) | 750 (drwxr-x---) | Shared team servers (Blocks public access) |
077 | 600 (-rw-------) | 700 (drwx------) | Strict privacy (Private to user account only) |
How to Set Umask in Linux
You can view or temporarily set umask in your terminal session:
umask# Set session umask to 027umask 027To make umask settings permanent across shell restarts, add umask 022 to your shell profile file (~/.bashrc, ~/.zshrc, or /etc/profile).