fix: handle HFS+ mount failure in container flash helper
Add graceful fallback when kernel hfsplus mount is blocked by container
security policy. ESP partition 2 has BOOTX64.EFI as Mac boot fallback.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>