mktemp gives an unpredictable name (no symlink attacks, no collisions);
the EXIT trap removes it on normal exit and set -e failure.
tmp=$(mktemp -d) && trap 'rm -rf "$tmp"' EXITtrap 'exit 130' INT TERM # dash/ash skip EXIT on signals without thisTwo gotchas: dash and busybox ash don’t run the EXIT trap on Ctrl-C
(bash does), hence the second line. And a shell has only one EXIT trap,
so a later trap ... EXIT silently replaces this one; merge cleanups into
a single handler.