Hmm... so blankflash fails, too? Wouldn't that have all the needed signatures? I mean, you may need to redo with stock firmware post-blank-flash, then let it activate the OEM unlock switch, then unlock it, then start the game all over again, but it saves the hardware? Not saying you are wrong or anything, I've never gotten even this far with EDL (acknowledging there is a functioning EDL mode) on a Moto before. No one else in the moto communities I've looked at ever discuss it; the OnePlus folks are well aware and routinely use it to unbrick stupidities (myself included, many times).
I may be entirely wrong, but I thought if you had a signed programmer (e.g. the ELF file) the actual firehose contents (e.g. what you flash) weren't signed or otherwise verified, and you could overwrite any of the partitions (including where the 'Allow OEM unlock' is stored)? I figure the worst was that verified boot would limit you to a properly signed bootloader until the OEM unlocking is completed- but we have the signed stock image, right? Just as a fastboot-mode flash vs EDL/Sahara mode image (I do, if you don't... just DM me).
I may be entirely wrong, but I thought if you had a signed programmer (e.g. the ELF file) the actual firehose contents (e.g. what you flash) weren't signed or otherwise verified, and you could overwrite any of the partitions (including where the 'Allow OEM unlock' is stored)? I figure the worst was that verified boot would limit you to a properly signed bootloader until the OEM unlocking is completed- but we have the signed stock image, right? Just as a fastboot-mode flash vs EDL/Sahara mode image (I do, if you don't... just DM me).