id: 1710e6cda5634209833822a828a9740b
parent_id: 
item_type: 1
item_id: 7d630d2e08274bb4880c341ea2bbc6e8
item_updated_time: 1786726778897
title_diff: "[{\"diffs\":[[1,\"Production & Re-install Implementation Plan (IMPLEMENTED)\"]],\"start1\":0,\"start2\":0,\"length1\":0,\"length2\":57}]"
body_diff: "[{\"diffs\":[[1,\"# ✅ IMPLEMENTED (2026-08-05) — historical plan, kept for reference\\\n\\\nAll tasks below were implemented and HW-verified (production flows, applet reset on\\\nHW, validation, retry). Current architecture is documented in the crate docs and\\\nthe audit note; see \\\"Project Status\\\" for the current snapshot.\\\n\\\n---\\\n\\\n# Plan (original)\\\n\\\n## Overview\\\nWire up 3 GUI workflows that already have most of their logic implemented in existing code:\\\n1. **HW Re-install**: applet_reset (DELETE+INSTALL) + provision + lifecycle + validate\\\n2. **HW Production**: provision + lifecycle + validate + KLMS report\\\n3. **Mock Production**: same as HW but with mock transport\\\n\\\n## Tasks\\\n\\\n### 1. Enable factory transition in provisioner\\\n- Change HW provisioner to use `skip_lifecycle_transition: false` (currently true)\\\n- The provisioner already has lifecycle + post-perso code paths\\\n- Need to ensure it works end-to-end\\\n\\\n### 2. Add post-provisioning validation to provisioner\\\n- After lifecycle transition: cert readback (GET DATA), FESN/SPID readback, ECDSA signature verification\\\n- This logic exists in `factory_transition.rs` — needs to be ported into `kf-provision` (or exposed)\\\n- Or: keep it in kf-dev-station and call it from the production workflow\\\n\\\n### 3. Make applet_reset work on HW\\\n- Currently mock-only (uses mock_transport/mock_keys)\\\n- Need: connect to PICC reader, select ISD, SCP03 auth, DELETE instance, INSTALL instance\\\n- Already has the core APDU logic, just needs real transport\\\n\\\n### 4. Wire up GUI tabs\\\n- **Re-install HW**: container dir + reader → applet reset → provision → validate\\\n- **HW Production**: container dir + reader → provision → lifecycle → validate → report  \\\n- **Mock Production**: container dir + UID → mock provision → mock validate\\\n\\\n### 5. Fix existing issues\\\n- 6A 80 on CMS cert fragment (first fob that works)\\\n- 69 85 on second fob (different card OS)\\\n\\\n## File Changes\\\n\\\n### kf-provision changes:\\\n- Make `ProvisionerConfig` expose lifecycle/validate flags\\\n- Add `post_perso_commands` to `ProvisioningSource` trait (from `ProvisioningInput`)\\\n- Or: add a `ProvisioningOutput` with validation data\\\n\\\n### kf-dev-station changes:\\\n- Make `applet_reset.rs::run()` work with real `SmartcardTransport` + real keys\\\n- Wire production flow to use real provisioner with lifecycle enabled\\\n- Add mock validation (mirrors factory_transition with mock transport)\"]],\"start1\":0,\"start2\":0,\"length1\":0,\"length2\":2346}]"
metadata_diff: {"new":{"id":"7d630d2e08274bb4880c341ea2bbc6e8","parent_id":"beb251c3b3f9490285e6cb68942a5145","latitude":"0.00000000","longitude":"0.00000000","altitude":"0.0000","author":"","source_url":"","is_todo":0,"todo_due":0,"todo_completed":0,"source":"joplin-desktop","source_application":"net.cozic.joplin-desktop","application_data":"","order":1786363129075,"markup_language":1,"is_shared":0,"share_id":"","conflict_original_id":"","master_key_id":"","user_data":"","deleted_time":0},"deleted":[]}
encryption_cipher_text: 
encryption_applied: 0
updated_time: 2026-08-14T17:00:01.028Z
created_time: 2026-08-14T17:00:01.028Z
is_locked: 0
type_: 13