repo clone: resolve /gh/ shorthand via pull-gated placement lookup
Commit

Why
entire repo clone /gh/<owner>/<repo> resolved owner/repo to a cluster
host via the mirror list (repo#list), which omits the public_viewer
wildcard. A public mirror the caller held no grant on was invisible to
discovery, so the shorthand failed with "no mirror found" even though
cloning the full entire:// URL (repo#pull) worked. Discovery and
authorization disagreed.
What
Point the clone path's discovery at the new pull-gated GET /api/v1/mirrors/placements (resolveMirrorPlacements): regenerate the ogen client from the spec, add resolvePullablePlacements() in repo_clone.go, and call it instead of listMirrorsForRepo. Now discovery uses the same authority (repo#pull) as the clone itself, so anything clonable-by-URL — public or private-with-grant — resolves by shorthand.
The three routing callers (api passthrough, experts cell-target, activity/recap) keep using the affiliation-scoped listMirrorsForRepo: enumeration should stay repo#list so public repos don't flood listings. Only targeted clone-by-name uses pull. Results map into coreapi.Mirror so the cluster picker (selectCloneTarget) is unchanged.
Tests
repo_clone_test.go: TestResolvePullablePlacements_MapsPlacements asserts the endpoint, query, and field mapping. Existing picker/list tests unchanged and passing.
Paired server change (entiredb): link added after creation.
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com