check / check (push) Failing after 3s
CreatePGPUnlocker resolved the GPG key's fingerprint, and the keychain unlocker got the long-term key, only after writing part of the unlocker, so a failure there left a directory with no metadata. Both now do every step that can fail before writing anything. All four unlocker types write their files through the new secret.WriteDir, which builds a new directory in a temporary directory, renames it into place when complete and removes it on a failure. A directory that already exists, as when an unlocker replaces one of the same name, is written in place and never removed. Model: opus-5-5