D038 - What the cryptographic entries are not, recorded so nobody re-runs the searches

0x400, 0x401 and 0x1002 resisted every local hypothesis. Refuted across the samples:

The same treatment was given to the two unexplained 32-byte fields in the PFS superblock, at 0xb8 and 0x380. Refuted: the superblock with the field zeroed, the whole superblock, the seed, the image after the superblock, the whole image, the prefix before the seed, the following block - under SHA-256, and under HMAC-SHA-256 keyed by the seed.

That is a wall of negatives and it is worth the space. Every one of them is a search somebody would otherwise repeat, and knowing that the content is not present in the package is what says the answer has to come from a source rather than from more staring.

The source is named and already cited here: data/pkg-keys.toml records that the fake keyset comes from LibOrbisPkg, an open-source packaging tool. A writer is exactly what unblocked the container (D012), and this repository already trusts that project for its keys.