Corrects entity_auth_data CBOR structure based on 243 captured requests:
- scheme name is "MGK_APPID" (not "FAIRPLAY_MGK_APPID")
- apphmac is device_id_token UTF-8 bytes, not a computed HMAC
- devicetoken is base64.b64decode(device_id_token) raw bytes
- integer key 3 for ESN (not string key); no device_key_data or esn_prefix
- identity (key 33.8) is full ESN without "_3" suffix
- signature = HMAC-SHA256(sign_key_0, key_request_data_bytes) only
iOSAppbootParams simplified: removes device_key_data, apphmac, devicetoken,
renewable, capabilities, esn_prefix. Adds optional device_id_token for
subsequent sessions. CBOR building moved inline into iOSMslClient.
New tools/test_appboot_e2e.py performs the full chain: TFIT emulation ->
Phase 3 KDF -> DH keygen -> CBOR build -> POST appboot.netflix.com ->
response parse. Handles both CBOR success and JSON MSL error responses.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>