From the review of #2112 (closes #1947):
- configure_gcp_test.go RemovalFailureReported doesn't assert !m.deleteCalled. A mutation that moves the remote-delete check after local removal (deleting a successfully stored key when the unlink fails) passes every test. Add assert.False(t, m.deleteCalled).
- A panic inside the upload skips the remote delete (the named err is still nil). Recover, or set err in a deferred recover.
- A second Ctrl-C during the 60s remote delete is swallowed (stop() is deferred).
- Pre-existing: an interrupt during the CreateKey RPC can exit with the key already minted in GCP.
From the review of #2112 (closes #1947):