check / check (push) Waiting to run
CreatePGPUnlocker got the vault's long-term key from the keychain unlocker's helper, which on every platform but macOS is a stub that always fails. It now calls the vault's GetOrDeriveLongTermKey, as adding a passphrase unlocker does: from the mnemonic, checked against the vault, or else from the current unlocker. That method joins VaultInterface. The test GPG key gains an encryption subkey, and a new test adds a PGP unlocker with the long-term key from the mnemonic and from a passphrase unlocker, then reads a secret through it. Model: opus-5-5