I don't think the GPL covers signing keys, just some mechanism for installation. Allowing addition of additional signing keys is a good way to do it, just like UEFI Secure Boot does things. There are also plenty of phone vendors who allow bootloader unlock after wiping the device DRM/etc keys too.
https://sfconservancy.org/blog/2021/mar/25/install-gplv2/ https://sfconservancy.org/blog/2021/jul/23/tivoization-and-t... https://events19.linuxfoundation.org/wp-content/uploads/2017...