summaryrefslogtreecommitdiff
path: root/docs/smbdotconf/security/createmask.xml
blob: 7f9f93caaa914283e3e7ca0e180e4f991f0a2636 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
<samba:parameter name="create mask"
                 context="S"
				 type="string"
                 xmlns:samba="http://www.samba.org/samba/DTD/samba-doc">

<synonym>create mode</synonym>
<description>
    <para>When a file is created, the necessary permissions are 
    calculated according to the mapping from DOS modes to UNIX 
    permissions, and the resulting UNIX mode is then bit-wise 'AND'ed 
    with this parameter. This parameter may be thought of as a bit-wise 
    MASK for the UNIX modes of a file. Any bit <emphasis>not</emphasis> 
    set here will be removed from the modes set on a file when it is 
    created.</para>

    <para>The default value of this parameter removes the 
    'group' and 'other' write and execute bits from the UNIX modes.</para>

    <para>Following this Samba will bit-wise 'OR' the UNIX mode created 
    from this parameter with the value of the <smbconfoption name="force create mode"/>
    parameter which is set to 000 by default.</para>

    <para>This parameter does not affect directory modes. See the 
    parameter <smbconfoption name="directory mode"/> for details.</para>

    <para>Note that this parameter does not apply to permissions
    set by Windows NT/2000 ACL editors. If the administrator wishes to enforce
    a mask on access control lists also, they need to set the <smbconfoption name="security mask"/>.</para>
</description>

<related>force create mode</related>
<related>directory mode</related>
<related>inherit permissions</related>

<value type="default">0744</value>
<value type="example">0775</value>
</samba:parameter>