check / check (push) Successful in 39s
The passphrase protecting the keychain unlocker's age key was a plain string passed through encoding/json, leaving copies in ordinary memory when an unlocker was created and each time one was used. It is now generated into a locked buffer, and KeychainData, moved to keychaindata.go, which is not darwin-only so its tests run on Linux, writes and reads the keychain JSON itself: encode copies the parts straight into a locked buffer, and decodeKeychainData takes the passphrase from a json.RawMessage that it wipes. The JSON field names are unchanged. keychainunlocker.go only calls this code and stores the item from the locked buffer without a string copy. Model: opus-5-5