verify.py reaches these through a dynamic import and nothing exercised
them, so a signature check that accepted everything would have looked
exactly like one that worked.
Console dumps are personal data and cannot be committed, but the
verifiers only read structure and signatures: the fixtures are built
from the layouts in unique_data.cpp and otp.cpp, signing with a key the
test owns and passing the matching public key in through the keys file.
That covers the region-change detection in SecureInfo_A, the embedded
LFCS in movable.sed, and the OTP path down to the sect233r1 certificate
including the pre-v5 expiry endianness.
crypto_verify goes from 9 to 89 percent. Disabling the OTP hash check
and the movable.sed magic check each fails a test.