Add support for canokey for testing operations involving smart card
Request PIN entry twice when provisioning smart cards
fix: set xdg_runtime_dir required by keyfork
feat: optional boot with kvm or efi