SIGN IN SIGN UP

[client] Stage install script downloads in a private temp directory (#7534)

The install script downloaded both the macOS .pkg and the release tarballs
into /tmp under fixed, predictable names, then passed those same paths to the
privileged install steps (`installer -pkg`, `mv` into the install dir).

/tmp is shared, so those fixed names can collide with entries created there
beforehand, and the privileged steps consume whatever the path resolves to.

Stage every download in a directory from `mktemp -d` instead: unpredictable
name, mode 0700, owned by the caller, created atomically. Extraction now
targets that directory (`tar -C`, `unzip -d`) rather than relying on `cd /tmp`,
and an EXIT trap removes it, so a failed run no longer leaves the archive and
the unpacked LICENSE/README behind in /tmp either.
R
Riccardo Manfrin committed
58b5263c1a507f4f30de8e1920d4786a0363bbfa
Parent: f29249e
Committed by GitHub <noreply@github.com> on 9/15/2026, 8:30:33 AM