Self-cleaning temp dir

mktemp gives an unpredictable name (no symlink attacks, no collisions); the EXIT trap removes it on normal exit and set -e failure.

tmp=$(mktemp -d) && trap 'rm -rf "$tmp"' EXIT
trap 'exit 130' INT TERM # dash/ash skip EXIT on signals without this

Two gotchas: dash and busybox ash don’t run the EXIT trap on Ctrl-C (bash does), hence the second line. And a shell has only one EXIT trap, so a later trap ... EXIT silently replaces this one; merge cleanups into a single handler.

esc