sha256convert: keep converted repo on post-conversion failure; redact URL parse errors
Commit

Two fixes from PR review:
-
Cleanup lifecycle: disarm the target-dir cleanup once the conversion is complete (refs + HEAD written). Previously a failure in an optional post-step -- --write-mapping, origin notes, or --sign-mode tips -- left cleanupTarget armed and os.RemoveAll'd the whole converted repo, silently discarding a (possibly multi-hour) conversion over a path typo or a signing misconfig. This also contradicted the docs, which promise the repo survives a signing failure. Those steps now surface the error but leave the valid converted repo on disk, matching the --check path.
-
Credential redaction: openSource no longer propagates url.Parse's error verbatim (it embeds the raw URL, leaking https://user:token@host into output/logs/CI). It now surfaces only the underlying *url.Error.Err.
Add a gated regression test asserting the target survives an unwritable --write-mapping path and stays fsck-clean; verified it fails without the cleanup fix.
Docs: correct the stale determinism note (the notes ref uses a pinned SOURCE_DATE_EPOCH / Unix-epoch timestamp, not time.Now(), so the whole conversion is reproducible); document the real HEAD-selection fallback; note signed attestation tags are also excluded side outputs under --check.
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: adebb896690e