flashupdate: Implement BIOS key metrics writer for key rotation

Introduce the BIOS key metrics writer logic in flashupdate. This writes
telemetry data to `/run/bios_key/` containing four metrics:
- bios_key_validation_method: EMBEDDED_KEY or PAYLOAD_KEY
- bios_key_image_family: Decimal image family of the validating key
- bios_key_version: The config package version from Hoth key rotation record
- bios_key_validation_key_data: First 64 bits of the validating key's modulus (hex)

The metrics writer is hooked into:
1. isBiosKeyRotationSupport(): Writes EMBEDDED_KEY when key rotation is
   not supported or there are zero keys defined.
2. trustKeyInCr51Signature(): Writes PAYLOAD_KEY, image family, version
   (queried via libhoth_key_rotation_get_version), and validation key data
   (extracted from the validating key's modulus) when a key match happens.

Updated unit tests to align with this design and added mock coverage for
libhoth_key_rotation_get_version.

Google-Bug-Id: 459542518
Change-Id: Ibdf47909f85cf2ebd30fc9ed1bf02db3a543bc0d
Signed-off-by: Manan J. Mehta <mjmehta@google.com>
4 files changed