how far down the chain does the protection go? if you swap the flash chips can you just boot or do the other chips expect a signature upstream?

AFAIK there are signatures that are checked at the SoC level. In other words, it's not a write lock that can be bypassed by flashing the chips directly.