Nothing to try yet
A signed-cache subsystem with write, remove and shadow-check paths exists, but its list of trusted signing roots is empty.
A signed-cache subsystem now exists, with its own logging prefix, an accepted-iat lock, a shadow check, and write/remove paths, computing a frozen list of trusted signing roots. In this build the literal roots array is empty (roots: []), so whatever verification it is meant to gate currently has nothing to verify against.