... your bootloader for a signed hash of itself and verify that the signature of the hash ...
... an important facility: it lacks the facility to verify that what you think you're running ...