de1368fd2d
PR #3474 review: the new export pass writes referenced env-var values into a snapshot file under `os.tmpdir()/omp-shell-snapshots`. On Linux where `os.tmpdir()` is `/tmp` and the umask is the default 022, the file ended up world-readable (0644) until postmortem cleanup. A user rcfile defining `deploy(){ curl -H "Authorization: $GITHUB_TOKEN" ...; }` would have its token written verbatim to that file. Three-layer mitigation: - `umask 077` at the top of the snapshot script so the file is 0600 from the first byte (the shell creates it via redirection, not JS). - JS caller now passes `mode: 0o700` to `mkdirSync` and chmods the dir + file defensively after the script exits, covering pre-existing dirs and exotic shells where the umask call might not take. - Helper denylist gained the common secret-shaped name patterns (`*TOKEN*`, `*SECRET*`, `*API_KEY*`, `*PASSWORD*`, `*PASSWD*`, `*PRIVATE_KEY*`, `*ACCESS_KEY*`, `*CREDENTIAL*`, `*SESSION_KEY*`) so even when the file is locked down, we don't materialise tokens onto disk in the first place. Tests cover both: a new helper-level test asserts none of the secret names (or their values) appear in the export stream, and the e2e test now stats the snapshot file + dir and asserts `mode & 0o077 === 0`.