pub fn initialize() -> Result<SelfTestReport>Expand description
Run the pre-operational self-tests and bring the module up.
Idempotent: calling it again once operational is a no-op that preserves the
current mode. If any known-answer test fails, the module latches into
State::Error and every subsequent call fails with
ErrorKind::ModuleErrorState.
The module comes up Mode::Unrestricted; call set_mode to enter
approved mode. That ordering is deliberate — entering approved mode is a
decision the operator makes explicitly, never a default the caller might not
have noticed.