### Review of Code Changes

Review the code changes against the base branch 'main'. The merge base commit for this comparison is 368750cee35f31935640a34ad199e889fc60f1a8. Run `git diff 368750cee35f31935640a34ad199e889fc60f1a8` to inspect the changes relative to main. Provide prioritized, actionable findings.

#### Findings

- **Title:** [P2] Implement real locking for Windows file token writes  
  **Body:** When `ENTIRE_TOKEN_STORE=file` is used on Windows, `flockExclusive` only opens the lock file and does not exclude another process. `writeFileToken` relies on this lock for its read-modify-write and also writes to a fixed `path + ".tmp"` before renaming, so two concurrent logins or credential refreshes can overwrite each other's temp file, lose one credential, or return a rename error. Please use a real Windows interprocess lock, or otherwise make concurrent writes safe.  
  **Confidence Score:** 0.87  
  **Priority:** 2  
  **Code Location:**   
  - **Absolute File Path:** `/Users/soph/Work/entire/devenv/git-sync/internal/auth/tokenstore_lock_windows.go`  
  - **Line Range:** 20-20

#### Overall Correctness
- **Overall Correctness:** patch is incorrect  
- **Overall Explanation:** The patch fixes Windows compilation, but the Windows lock implementation is a no-op while the token store write path still depends on mutual exclusion for correctness under concurrent file-store writes.  
- **Overall Confidence Score:** 0.87

#### Additional Notes
- Remove the Entire DB credential-store integration.  
  git-sync carried a bespoke Entire credential path: auth.Resolve fell back to an active-user lookup in ~/.config/entire/hosts.json plus a file/keyring token store and OAuth refresh-token handling (client_id=entire-cli).  Nothing in the product produces that layout anymore — the mirror-pipeline worker supplies credentials directly at the transport layer (GitHub installation tokens + per-request entire-core repo-scoped bearers), and client-side entire:// auth is owned by the separate git-remote-entire helper using the newer contexts.json model.  
  
  Drop `entiredb.go` and `tokenstore.go` and the `LookupEntireDBCredential` fallback; `auth.Resolve` now resolves explicit token/bearer credentials only and otherwise returns nil so the git credential helper is consulted on a 401. This also drops the `github.com/zalando/go-keyring` dependency and removes the `syscall.Flock` usage that broke the Windows build, ensuring that the package now cross-compiles for Windows cleanly.  
  
  Supersedes the entiredb token-refresh fix (#90) and the tokenstore Windows flock fix (#92), both of which were polishing this now-deleted code.
