Appendix: Determining Umask Values
This appendix describes Umask values and how to calculate them. Umasks are used to define access permissions in Hammerspace when local users are employed instead of Active Directory.
Unix Permissions - Octal Values
The following table shows the conversion of Unix permissions from their binary value to an octal value, which is needed to determine the desired Umask setting.
| Permissions | Octal Value | Binary Value | Description |
|---|---|---|---|
|
0 |
000 |
No permissions |
|
1 |
001 |
Execute |
|
2 |
010 |
Write |
|
3 |
011 |
Write and execute |
|
4 |
100 |
Read |
|
5 |
101 |
Read and execute |
|
6 |
110 |
Read and write |
|
7 |
111 |
Read, write, and execute |
To determine the Umask value, simply determine what must be subtracted from 7 to reach the desired permission set. For example, to grant only read permissions for new files/folders (octal value 4 above), use a Umask value of 3, since 7 - 3 = 4.
Creating an S3 Umask Value for a Local Identity Provider
A Hammerspace S3 server that uses the local identity provider relies on a Umask setting to determine the permissions for new files and folders that are created using the S3 protocol.
The default setting is 0002, which can be explained as follows:
-
The first value is 0, which sets the sticky bit to off. The sticky bit is a special file permission flag in Unix-like systems that, when set on a directory, prevents users (other than the owner or root) from deleting or moving files within that directory, even if they have write access.
-
The second value sets the permissions for the file owner; a 0 (7 - 0 = octal permission value of 7) means that the owner will have full access to all files and folders that they create (read/write for files, read/write/execute for folders).
-
The third value sets the permissions for the groups that the file owner is a member of; a 0 (7 - 0 = octal permission value of 7) means that members of those groups will have full access to all files and folders the owner creates (read/write for files, read/write/execute for folders).
-
The fourth value sets the permissions for all other users; a 2 (7 - 2 = octal permission value of 5, the Hammerspace default) means that all other users will have only read/execute permissions for folders and read permissions for files.
|