check / check (push) Failing after 3s
A Secure Enclave unlocker add gets the long-term key before it creates the Secure Enclave key, so a wrong passphrase creates none, and deletes the key if encrypting with it or writing the unlocker then fails. A keychain unlocker add writes all of the unlocker's files before it stores the keychain item, and deletes the item if moving the unlocker into place then fails. A failure to delete is reported along with the original error. These files build only on macOS: the code is type-checked and linted from Linux by script/lint-darwin; the new tests run only on a Mac. Model: opus-5-5