PR #3474 second review: previous revision ran `umask 077` only BEFORE
sourcing the rc, so a typical `.bashrc`/`.zshrc` that calls
`umask 022` reopened the world-read window between the spawned shell's
first `>|` and the JS post-spawn chmod. Snapshot file (with inlined
env-var values) lived at 0644 for the full body of the script.
Two-layer fix:
- JS caller now pre-creates the snapshot file at 0600 with
`fs.writeFileSync(path, "", { mode: 0o600 })` before spawning. The
shell's `>|` (truncate) and `>>` (append) preserve the existing
inode mode, so the file is 0600 from byte zero regardless of the
spawned shell's umask state.
- Script also re-applies `umask 077` after the rc source so any
other file the script might create (none today, defensive) stays
private even when the rc resets umask.
New e2e regression test seeds a `.bashrc` containing `umask 022` and
asserts the resulting snapshot mode `& 0o077 === 0`.