I appreciate what you're saying. Commercial realities are very different to theoretical ideals, and of course you have to draw the boundary of trust somewhere to get anything done.
I don't think anyone is saying it's an app developers responsibility to ensure the user's bootloader is securely implemented.
There is a lot of space between verify everything and trust nothing, and I don't think it's unreasonable to question whether that trust boundary is in the right place.
I also think that the code compiled to produce the binary you ship is a perfectly reasonable place to put that boundary, would you disagree?
I'm sure that within the mobile dev world it is normal, accepted practice to include lots of unseen code. I don't begrudge anyone involve for taking the money and doing what's expected.
But I still think it's a mad way to run a business or community project, and it's worth considering how we got here and whether it really has to be this way.