Per Coverity. Back-patch to 9.0 (all supported versions).
Michael Paquier, reviewed (in earlier versions) by Heikki Linnakangas.
}
else
{
+ int old_umask;
+
tm = pg_malloc0(sizeof(TAR_MEMBER));
+ /*
+ * POSIX does not require, but permits, tmpfile() to restrict file
+ * permissions. Given an OS crash after we write data, the filesystem
+ * might retain the data but forget tmpfile()'s unlink(). If so, the
+ * file mode protects confidentiality of the data written.
+ */
+ old_umask = umask(S_IRWXG | S_IRWXO);
+
#ifndef WIN32
tm->tmpFH = tmpfile();
#else
if (tm->tmpFH == NULL)
exit_horribly(modulename, "could not generate temporary file name: %s\n", strerror(errno));
+ umask(old_umask);
+
#ifdef HAVE_LIBZ
if (AH->compression != 0)