Address a very theoretical possible security issue in mandos-client.
If there were to run some sort of "cleaner" process for /run/tmp (or /tmp), and mandos-client were to run for long enough for that cleaner process to remove the temporary directory for GPGME, there was a possibility that another unprivileged process could trick the (also unprivileged) mandos-client process to remove other files or symlinks which the unprivileged mandos-client process was allowed to remove. This is not currently known to have been exploitable, since there are no known initramfs environments running such cleaner processes.
* plugins.d/mandos-client.c (main): Use O_NOFOLLOW when opening tempdir for cleaning.