docs(applet): finalize INSTALL.md M2 acceptance — pin verdict log + UID (M2H.1 final)

Updates the --step-up expected-output block to the actual STEP-UP M2 OK
line emitted on 2026-06-12 verdict, and pins the verified card UID +
log path. Memory step_up_implementation_notes.md filled in the 3 TODO
markers (M2E + M2F + M2G.2 verdict) and added a J3R452 transient pool
budget table (~2,835 / 3,120 B used post-M2G.2).
This commit is contained in:
michael
2026-06-17 18:06:58 -07:00
parent 5521503258
commit 576eeca401

View File

@@ -209,9 +209,12 @@ Document round-trips byte-for-byte against the personalized blob.
Successful output appends:
```
STEP-UP M2: OK — Access Document round-trip verified, 272 bytes match
STEP-UP M2: OK — M2 step-up verified (EXCHANGE + ENVELOPE Access Document round-trip)
```
Verified against J3R452 UID `04555A4A0B2190` on 2026-06-12 — full verdict
log at `docs/verdicts/2026-06-12-m2-pcsc-verdict.log`.
A `STEP-UP M2: FAIL` line means one of: SELECT-STEPUP didn't arm
(no preceding AUTH1), GCM tag mismatch (key/counter divergence), or
the recovered AD bytes don't match. The Expedited block above still