fn restrict_to_owner(path: &Path)
Make a key file owner-readable only. Best effort — a filesystem without Unix permissions is not a reason to fail.