## Bottom line

Addressed the requested PR review comment (and the adjacent one) on `cmd/entire/cli/repo_mirror.go`.

**What changed:**

- **`repo_mirror_test.go`** — Added `TestRepoMirrorList_ShowAvailableRouting`, a command-level test that executes `repo mirror list` end-to-end against an httptest fake control-plane and locks in:
  
  - `--show-available` → routes to `GET /api/v1/mirrors/available`, renders the `ACCESS`/`STATUS` columns (not `CLONE URL`), and prints the "Listing repos you could mirror" banner.
  - default → routes to `GET /api/v1/mirrors` with the clone-URL view + "Listing mirrors on" banner.
  - `--owner` flows into the query on **both** paths.
  - `--cluster`/`--provider` apply to `/mirrors` but are correctly **ignored** by `--show-available`.
- **`corecmd.go`** — Added a small `activeCoreClient` package seam (production = `coreapi.New`) so `runCore` can be pointed at a test server without the auth/context/TLS stack. (The original review comment, r3449752471.)
- **`repo_mirror.go`** — Fixed the `availableMirrorColumns` doc comment to use the real `entire repo mirror create`/`list` command names instead of `mirror create`/`mirror list`. (The adjacent comment, r3449752460.)

**Heads-up — repo footgun I hit:** `mise run lint` runs `golangci-lint --fix`, and a stale lint cache made `nolintlint` think the `//nolint:ireturn` directives in `checkpoint/open.go` and `strategy/manual_commit.go` were unused, auto-stripping them from those two unrelated files. I restored the directives (they now match HEAD) and confirmed it was a cache artifact — `golangci-lint cache clean` then a full run reports **0 issues**. If you `mise run lint` with a stale cache it may strip them again; clear the cache first.

Tests pass; lint is clean. Not committed — yours to push.

## Bottom line

One open high-severity finding on trail #631 — a real data race in my test helper. Fixed and pushed.

**The finding:** `serveMirrorList` wrote `recordedRequest` from the HTTP handler goroutine and read it from the test goroutine with no happens-before edge — `-race` would fail it. (Same gotcha the existing `TestBearerOnlySource_NoCookieOnTheWire` documents.)

**The fix (`8292221f9`):** Deliver the recorded request over a buffered channel; the test receives from it after the command runs, which is the synchronization edge. Verified with `go test -race` — all 5 subtests pass clean. Lint/gofmt clean.

**To close it out:** the finding (`019eedf8-…`) is still open — run when ready:

```
entire trail finding resolve 019eedf8-fa11-7624-ad26-c1a6e61fa851 --trail 631
```
