secret init and secret vault create read the mnemonic with the new
secret.ReadMnemonic, whose every error wraps the new
secret.ErrMnemonicNotRead. It shares the terminal read with ReadPassphrase,
whose errors still wrap ErrPassphraseNotRead. Without a terminal the error
names the environment variable that gives the value instead:
SB_SECRET_MNEMONIC for the mnemonic, SB_UNLOCK_PASSPHRASE for the
passphrase. A test pins the message of init without a terminal.
Model: opus-5-5
When a vault cannot be opened through its current unlocker, the error now
ends by naming the vault, saying that it still opens with its mnemonic,
and that 'secret unlocker add passphrase' run with SB_SECRET_MNEMONIC set
gives it a new unlocker, after 'secret vault select' when it is not the
current vault. Only when the vault metadata records the key the mnemonic
derives, and not when the passphrase could not be read. 'secret encrypt'
and 'secret decrypt' read the key secret through vault.GetSecret, and
Secret.GetValue with its helpers is removed. An unreadable 'current'
file's error names 'secret version list' and 'secret version promote'.
Causes stay wrapped.
Model: opus-5-5