Skip to content

Treat the Discovery Object as optional in the PIV state - #22

Merged
mmlado merged 1 commit into
mainfrom
fix/discovery-optional-state
Oct 7, 2026
Merged

mmlado merged 1 commit into
mainfrom
fix/discovery-optional-state

Conversation

@mmlado

@mmlado mmlado commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

Derive the mandatory PIV object set from the object registry (CHUID and CCC). Discovery is optional and no built-in profile creates it, so it must not block PivPersonalized. It is still probed and listed in objects_present.

factory piv preperso status reports finalize_allowed under the gate the finalize command applies (applet selectable, not SECURED) and adds load_config_allowed for a blank applet. The human output separates the two lines.

Read-only detection of SECURED is unchanged (Finalized (SECURED): no/undetermined).

Tests: tests/unit/test_state_discovery_optional.py, tests/unit/test_preperso_status_gate.py.

🤖 Generated with Claude Code

Derive the mandatory object set from the PIV object registry (CHUID and
CCC). Discovery is optional in PIV and no built-in profile creates it, so
a complete card never reached PivPersonalized.

Report finalize in `preperso status` under the rule the finalize command
applies (applet selectable, not SECURED) and add `load_config_allowed`
for the blank-applet case.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@mmlado mmlado self-assigned this Oct 7, 2026
@mmlado
mmlado merged commit a5c531e into main Oct 7, 2026
12 checks passed
@mmlado
mmlado deleted the fix/discovery-optional-state branch October 7, 2026 17:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant