Wire deferred settings rows: destructive actions, auto-lock relock, orphan editors
Surface a batch of settings-model options that were deferred by
isSettingImplemented, each with a working on-device handler (no dead rows),
and wire the auto-lock timer to the FSM.
Destructive actions (catalog §9.4): add ResetSettings (restore every device
preference to its default, keep the vault) and FactoryReset (wipe vault +
preferences + BLE bonds + onboarding -> first-run). A new settings_reset module
holds the single source of truth for which NVS entries are preferences
(kPreferenceKeys) — deliberately excluding vault/onboarding/security/identity
state so Reset Settings keeps the vault usable. Both reuse the hold-to-confirm
popup and restart so every subsystem re-reads its default.
Auto-lock relock (catalog §9.3): wire the auto_lock idle timer to the FSM. The
HomeStateHandler now relocks the vault (radios off + key zeroize -> PIN_ENTRY)
once idle passes autoLockMs, distinct from and below the deep-sleep ceiling.
decideRelock (pure, host-tested) splits the two §9.3 cases: lock face visible
when the screen is still on, silent relock (relockSilent -> PinStateHandler
keeps the panel dark) when the screen already powered off. Gated off keyboard
boards and capture builds; does not regress deep-sleep-locks-on-idle.
Orphan editors: add the AudioFeedback and ShakeToLock toggles and the
ShakeSensitivity stepper to the button-nav tree, reusing the existing
speaker/IMU backends (audio_fb / shake_lock / shake_thr NVS keys).
Also add a scoped NOLINT for a pre-existing cppcoreguidelines-owning-memory
finding on the QR scratch placement-new singleton (unrelated to this change;
keeps the clang-tidy gate green).
Native tests: decideRelock policy (6 cases), Reset-Settings preference scope
(7 cases), and the newly listed rows in the nav-logic suite.
Claude-Session: https://claude.ai/code/session_01P6BNTpbgrvnZXSJnNuj8ZJ