check / check (push) Successful in 1m32s
`secret mv --force x x` deleted the secret: a move within one vault removes an existing destination before renaming the source onto it. The same happened for `work:x work:`, `work:x work` and `work:x ""`, where an empty destination defaults to the source name. moveSecretWithinVault now rejects a move whose two names are the same before touching anything. A move within a named vault works in that vault directly instead of selecting it, so the current vault never changes; the vault must be one of the existing vaults. The test runs each rejected move on a copy of two in-memory vaults and requires the exact error and an unchanged state directory. Model: opus-5-5