Search the docs

Appendix: Determining Umask Values

This appendix describes Umask values and how to calculate them. Umasks are used to define access permissions in Hammerspace when local users are employed instead of Active Directory.

Unix Permissions - Octal Values

The following table shows the conversion of Unix permissions from their binary value to an octal value, which is needed to determine the desired Umask setting.

Permissions Octal Value Binary Value Description

---

0

000

No permissions

--x

1

001

Execute

-w-

2

010

Write

-wx

3

011

Write and execute

r--

4

100

Read

r-x

5

101

Read and execute

rw-

6

110

Read and write

rwx

7

111

Read, write, and execute

To determine the Umask value, simply determine what must be subtracted from 7 to reach the desired permission set. For example, to grant only read permissions for new files/folders (octal value 4 above), use a Umask value of 3, since 7 - 3 = 4.

Creating an S3 Umask Value for a Local Identity Provider

A Hammerspace S3 server that uses the local identity provider relies on a Umask setting to determine the permissions for new files and folders that are created using the S3 protocol.

The default setting is 0002, which can be explained as follows:

  • The first value is 0, which sets the sticky bit to off. The sticky bit is a special file permission flag in Unix-like systems that, when set on a directory, prevents users (other than the owner or root) from deleting or moving files within that directory, even if they have write access.

  • The second value sets the permissions for the file owner; a 0 (7 - 0 = octal permission value of 7) means that the owner will have full access to all files and folders that they create (read/write for files, read/write/execute for folders).

  • The third value sets the permissions for the groups that the file owner is a member of; a 0 (7 - 0 = octal permission value of 7) means that members of those groups will have full access to all files and folders the owner creates (read/write for files, read/write/execute for folders).

  • The fourth value sets the permissions for all other users; a 2 (7 - 2 = octal permission value of 5, the Hammerspace default) means that all other users will have only read/execute permissions for folders and read permissions for files.

  • A Umask of 0 (octal permission value of 7) grants read/write/execute permissions to folders and read/write permissions to files; this is expected.

  • Hammerspace does not alter the existing permissions of any files or folders that were or are created by non-S3 clients.

  • Umask is only used with S3 servers that use a local identity provider, not those that use Active Directory.