惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Fortinet All Blogs
爱范儿
爱范儿
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
B
Blog
WordPress大学
WordPress大学
Jina AI
Jina AI
GbyAI
GbyAI
aimingoo的专栏
aimingoo的专栏
N
Netflix TechBlog - Medium
腾讯CDC
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
阮一峰的网络日志
阮一峰的网络日志
The GitHub Blog
The GitHub Blog
V
Visual Studio Blog
Google DeepMind News
Google DeepMind News
月光博客
月光博客
博客园 - Franky
Y
Y Combinator Blog
MyScale Blog
MyScale Blog
大猫的无限游戏
大猫的无限游戏
Martin Fowler
Martin Fowler
雷峰网
雷峰网
小众软件
小众软件
H
Hackread – Cybersecurity News, Data Breaches, AI and More

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
Why umask 022 creates 755 folders and 644 files
authur · 2026-05-18 · via DEV Community

authur

If you have ever wondered why umask 022 creates directories like 755 but files like 644, the short answer is:

directories start from 777
regular files usually start from 666
umask subtracts permissions from those defaults

Enter fullscreen mode Exit fullscreen mode

So 022 does not mean "set permissions to 022". It means "remove these permission bits from the default mode".

The common example

For directories:

777 - 022 = 755

Enter fullscreen mode Exit fullscreen mode

For regular files:

666 - 022 = 644

Enter fullscreen mode Exit fullscreen mode

That is why a newly created folder often becomes:

drwxr-xr-x

Enter fullscreen mode Exit fullscreen mode

And a newly created file often becomes:

-rw-r--r--

Enter fullscreen mode Exit fullscreen mode

Why files do not start from 777

Directories need the execute bit so users can enter and traverse them.

Regular files usually do not start as executable. That is why the default starting point for many newly created files is 666, not 777.

So this is expected:

umask 022 -> folders 755
umask 022 -> files 644

Enter fullscreen mode Exit fullscreen mode

More examples

umask 002 -> folders 775, files 664
umask 027 -> folders 750, files 640
umask 077 -> folders 700, files 600

Enter fullscreen mode Exit fullscreen mode

002 is common when a shared group needs write access.

027 is stricter: group can read and enter directories, but others get no access.

077 is private: only the owner gets access.

chmod vs umask

A lot of confusion comes from mixing up chmod and umask.

chmod changes permissions on existing files or directories.

umask controls the default permissions for new files and directories.

So if a file already exists, changing your umask will not change that file. You would use chmod for that.

If new files are being created with the wrong permissions, then checking the current umask makes sense.

Quick checklist

When debugging a permissions problem, check these in order:

  1. What user is creating the file?
  2. What group owns the parent directory?
  3. What is the current umask?
  4. Is the filesystem a normal Linux filesystem, or something mounted with options like uid, gid, umask, fmask, or dmask?
  5. Are you trying to fix an existing file, or the defaults for future files?

That last question usually tells you whether you need chmod or umask.

I made a small browser-local calculator for this because I kept checking the same examples repeatedly:

https://webutilslab.com/umask-calculator/?ref=devto

It runs in the browser and is mostly useful for quickly verifying cases like 022, 027, and 077.