Remove the Entire DB credential-store integration · Entire

Review the code changes

Review the code changes against the base branch 'main'. The merge base commit for this comparison is 368750cee35f31935640a34ad199e889fc60f1a8. Run git diff 368750cee35f31935640a34ad199e889fc60f1a8 to inspect the changes relative to main. Provide prioritized, actionable findings.

Findings

{"findings":[{"title":"[P2] Treat unexpected EOF as a transport error","body":"When the response body returns `io.ErrUnexpectedEOF` after buffering fewer than 8 bytes, such as a truncated HTTP response immediately after the ACK/NAK section, `bufio.Reader.Peek` returns that error and clears it. This branch treats it as benign and returns nil, so `fetchToStoreV1`/`fetchPackV1` proceed with the original transport error lost and callers later see only partial data or plain EOF; `io.ErrUnexpectedEOF` should surface like the other non-EOF transport errors.","confidence_score":0.85,"priority":2,"code_location":{"absolute_file_path":"/Users/soph/Work/entire/devenv/git-sync/internal/gitproto/fetch.go","line_range":{"start":590,"end":590}}}],"overall_correctness":"patch is incorrect","overall_explanation":"The patch improves handling of some Peek errors, but it still explicitly suppresses `io.ErrUnexpectedEOF`, which is a real premature-stream error and can be consumed by `Peek` before downstream code can report it.","overall_confidence_score":0.85}

Code Changes

Remove the Entire DB credential-store integration

git-sync carried a bespoke Entire credential path: auth.Resolve fell back to an active-user lookup in ~/.config/entire/hosts.json plus a file/keyring token store and OAuth refresh-token handling (client_id=entire-cli). Nothing in the product produces that layout anymore — the mirror-pipeline worker (the only library consumer that talks to entiredb) supplies credentials directly at the transport layer (GitHub installation tokens + per-request entire-core repo-scoped bearers), and client-side entire:// auth is owned by the separate git-remote-entire helper using the newer contexts.json model. So the lookup only ever read a store no current producer writes.

Drop entiredb.go and tokenstore.go and the LookupEntireDBCredential fallback; auth.Resolve now resolves explicit token/bearer credentials only and otherwise returns nil so the git credential helper is consulted on a 401, exactly as for any other remote. This also drops the github.com/zalando/go-keyring dependency and, with the file token store gone, removes the syscall.Flock usage that broke the Windows build (so the package now cross-compiles for windows cleanly).

Supersedes the entiredb token-refresh fix (#90) and the tokenstore Windows flock fix (#92), both of which were polishing this now-deleted code.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com

Entire-Checkpoint: de15fe82f1f3+18/-1384

More details can be found in the commit message.