hamrpassValidate is the single source of truth for whether a key is acceptable and what the UI says about it. Shared by the inline /hamrpass handler and the arg popover hint. ok=false with an empty trimmed key is the "show status block" signal. Non-printable/non-ASCII runes are rejected up front: h
(raw string)
no outgoing calls