So, upstream just closed the issue I created with 'Works as Designed' blaming the default umask for the bug and that specifying file permissions for files created by mongodb is not something mongodb should do.
https://jira.mongodb.org/browse/SERVER-25335#comment-1342085 The bug is locked, what do I do now?