check / check (push) Successful in 1m4s
Entry() now returns the exit code and only main calls os.Exit, so the deferred memguard.Purge() in Entry() runs on success and on error; before, os.Exit(1) skipped every deferred Destroy(). SIGINT and SIGTERM go through memguard's handler, which wipes every buffer and exits with status 1. The passphrase prompt turns terminal echo off until its read returns, and the handler exits before that, so on Ctrl-C the handler first restores the terminal settings saved at startup. It leaves the terminal alone on SIGTERM, which can reach a background process, and changing the terminal from the background would stop the process. Model: opus-5-5