check / check (push) Waiting to run
`secret mv --force x x` deleted the secret: a move within one vault removes an existing destination before renaming the source onto it. The same happened for `work:x work:`, `work:x work` and `work:x ""`, and for `work:x work/:x`, which named one vault two ways and so was taken for a move between vaults. A move whose two names are the same is now rejected before anything changes. Every vault named with `vault:` must be one of the existing vaults by exact name, checked before choosing between the two kinds of move. A move within a named vault no longer makes it the current vault. The test runs each rejected move on a copy of two in-memory vaults and requires the exact error and an unchanged state directory. Model: opus-5-5