looks good enough;
new version outputs tsec_root_kek_%% package1_kek_%% and so on,
the part that matters is whenever new key generation is found either, also the debug message for not found doesn't matter that much
"NOFAT" error exists before...
Thanks to a tester the refactor of lockpick_rcm has reached a state of being able to (on its own) produce new key revisions, even if there has not been an update to lockpick_rcm...