The attestation dossier only fired on a successfully produced chain, so
the StrongBox/BHIM failures left nothing on the per-UID plane and had to
be reconstructed from marshalled .bin dumps offline. Add three records,
all debug- and target-gated like the existing dossier:
- keybox-pick: which keybox signs the forge (requested algo, exact match
vs EC fail-safe, signer subject) -- makes an EC-only-keybox RSA
fallback visible instead of silent.
- forge-fail: emit the failure reason on the per-UID plane when a forge
throws (e.g. ATTESTATION_KEYS_NOT_PROVISIONED), paired with dispatch.
- auth-shape: the emitted authorization list (count, ordered tags,
per-auth securityLevel) -- the surface the duck generate-mode parcel
fingerprint stride-walks, readable without offline decode.