//go:build unix package main import "syscall" // setUmask makes the process's default permissions match what the data // directory is documented to use: group-writable, world-readable. The token // file overrides this explicitly, since it is the one thing that is secret. func setUmask() { syscall.Umask(0o002) }