Ownership and umask

Ownership, umask and Default Permissions

Only root may give a file away; an owner may change its group to any group they belong to. chown deploy:www-data file sets both, chgrp only the group, chown --reference=a.php b.php copies a neighbor.

Programs request mode 666 for files and 777 for directories, and the process's inherited umask removes bits. 022 yields 644/755, 002 yields 664/775 for a group that shares files, 027 yields 640/750, and 077 yields 600/700. The umask never affects a chmod you issue yourself.

Reading a umask and proving what it doesShell
umask
( umask 027; touch f27; mkdir d27; stat -c '%a %n' f27 d27 )   # try it in a subshell
sudo su - "$USER" -c umask           # a full login session for the same user
Output
0022
640 f27
750 d27
0002

Your terminal's mask proves nothing about a daemon: with USERGROUPS_ENAB yes, Ubuntu 225 's pam_umask turns 022 into 002 at login for a user whose primary group bears their own name. PHP-FPM inherits the service's mask, 0022 by default (systemctl show php8.5-fpm -p UMask); set UMask=0027 in a unit override (systemd Services). Start backup scripts with umask 077, or the dump is readable by every account.