you can install a custom firmware that will calculate and report the firmware fingerprint
that can’t really be done easily. the firmware carries the bootloader in compressed form, so you’d have to do some amount of disassembly, locate the right sequence, uncompress it …
This is the usual way: verify that your firmware build matches the downloaded image, then verify that the build process is putting in the right bootloader.
The bootloader image that you’re looking for is sitting in core/embed/models/T2T1/bootloaders/bootloader-T2T1.bin.