28f2ea86e2
Fixes the two live E2E blockers @ctaylor86 found on PR #77189 (macOS 26.3.1, OpenSSL 3.6.3): - retry the PKCS#12 export with -legacy when security import rejects the OpenSSL 3 default format ('MAC verification failed during PKCS12 import') - trust the self-signed root for the codeSign policy (security add-trusted-cert -r trustRoot -p codeSign) — an imported-but-untrusted cert is invisible to find-identity -v and unusable by codesign - gate success on find-identity -v -p codesigning (postcondition), and use the same -v probe for idempotency so an untrusted leftover cert is repaired instead of reported as done Tests rewritten as stateful fakes (valid only after import+trust), plus new coverage for the -legacy retry, trust failure, postcondition gate, and the untrusted-cert repair path; sabotage-verified (reverting to the name-in-output probe fails 4 tests). Docs: manual fallback now includes the Trust step.